{"id":34523,"date":"2022-11-20T20:55:39","date_gmt":"2023-01-17T21:46:50","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/"},"modified":"2024-04-29T01:41:10","modified_gmt":"2024-04-28T17:41:10","slug":"%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","title":{"rendered":"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316"},"content":{"rendered":"<h1>\u9996\u5148<\/h1>\n<p>\u6700\u8fd1\u6709\u4e00\u4e9b\u6d88\u606f\uff0c\u6765\u81ea\u682a\u5f0f\u4f1a\u793e\u30e9\u30c3\u30af\u516c\u53f8\uff0c\u5173\u4e8e\u4f7f\u7528DNS\u534f\u8bae\u7684\u75c5\u6bd2\u7684\u8b66\u544a\u3002<\/p>\n<p>\u25a0\u9060\u9694\u64cd\u4f5c\u30a6\u30a4\u30eb\u30b9\u306e\u5236\u5fa1\u306bDNS\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3059\u308b\u4e8b\u6848\u3078\u306e\u6ce8\u610f\u559a\u8d77<br \/>\nhttp:\/\/www.lac.co.jp\/security\/alert\/2016\/02\/01_alert_01.html<\/p>\n<p>\u8a18\u4e8b\u4e2d\u306b\u305d\u306e\u30a6\u30a3\u30eb\u30b9\u3078\u306e\u5bfe\u5fdc\u6cd5\u306b\u3064\u3044\u3066\u8a18\u8f09\u304c\u3042\u308a\u3001\u305d\u306e1\u3064\u306b\u300c\u5185\u90e8DNS\u306e\u30a2\u30af\u30bb\u30b9\u30ed\u30b0\u304b\u3089\u4e0d\u6b63\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u767a\u898b\u3059\u308b\uff08\u30ed\u30b0\u3092\u53d6\u5f97\u3059\u308b\uff09\u300d\u304c\u3042\u3052\u3089\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\n\u672c\u4e8b\u6848\u4ee5\u5916\u3067\u3082\u3001\u591a\u304f\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u306f\u540d\u524d\u89e3\u6c7a\u3092\u884c\u3044C\uff06C\u30b5\u30fc\u30d0\u3068\u3084\u308a\u53d6\u308a\u3092\u884c\u3046\u305f\u3081\u3001DNS\u901a\u4fe1\u306e\u30ed\u30b0\u3092\u53d6\u5f97\u3059\u308b\u3053\u3068\u306f\u3001\u8abf\u67fb\u306b\u304a\u3044\u3066\u91cd\u8981\u306a\u60c5\u5831\u306b\u306a\u308b\u3068\u8003\u3048\u307e\u3059\u3002<\/p>\n<p>\u5373\u4f7f\u8bf4\u662f\u83b7\u53d6DNS\u901a\u4fe1\u7684\u65e5\u5fd7\uff0c\u5982\u679c\u4ec5\u4ec5\u4f7f\u7528\u7b80\u5355\u7684\u6570\u636e\u5305\u6355\u83b7\uff0c\u4f1a\u6709\u4e00\u4e9b\u95ee\u9898\uff0c\u6bd4\u5982\u67e5\u770b\u56f0\u96be\uff08\u8ffd\u6eaf\u4fe1\u606f\u65f6\u4f1a\u82b1\u8d39\u65f6\u95f4\uff09\u7b49\u3002<\/p>\n<p>\u6211\u60f3\u4f7f\u7528\u4ee5\u4e0b\u7684\u5f00\u6e90\u4ea7\u54c1\u6765\u521b\u5efa\u4e00\u4e2a\u6613\u4e8e\u6d4f\u89c8\u7684\u7cfb\u7edf\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Packetbeat<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Elasticsearch<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Kibana<\/ul>\n<h1>\u4ea7\u54c1\u8bf4\u660e<\/h1>\n<p>&#8220;Packetbeat&#8221;\u662f\u7531elastic\u516c\u53f8\u63d0\u4f9b\u7684\u4e00\u79cd\u5305\u76d1\u63a7\u5de5\u5177\u3002<br \/>\n\u5b83\u662f&#8221;Beats&#8221;\u4ea7\u54c1\u7cfb\u5217\u4e2d\u7684\u4e00\u5458\uff0c\u5176\u4ed6\u8fd8\u6709&#8221;Filebeat&#8221;\u3001&#8221;Metricbeat&#8221;\u3001&#8221;Topbeat&#8221;\u548c&#8221;Winlogbeat&#8221;\u3002<\/p>\n<p>&#8220;Elasticsearch&#8221;\u3001&#8221;Kibana&#8221;\u3082elastic\u793e\u306e\u30d7\u30ed\u30c0\u30af\u30c8\u3067\u3001&#8221;Elasticsearch&#8221;\u306f\u5168\u6587\u691c\u7d22\u30a8\u30f3\u30b8\u30f3\u3001&#8221;Kibana&#8221;\u306f\u30ed\u30b0\u53ef\u8996\u5316\u30c4\u30fc\u30eb\u3067\u3059\u3002<\/p>\n<p>https:\/\/www.elastic.co\/zh-cn\/products\/elasticsearch<br \/>\nhttps:\/\/www.elastic.co\/zh-cn\/products\/kibana<\/p>\n<h1>\u6784\u6210<\/h1>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/13-0.png\" alt=\"Packetbeat_\u69cb\u6210.png\" \/><\/div>\n<p>\u84dd\u8272\u7bad\u5934\uff1aDNS\u67e5\u8be2\u3001\u54cd\u5e94\u901a\u4fe1<br \/>\n\u7ea2\u8272\u7bad\u5934\uff1aPacketbeat\u5c06\u65e5\u5fd7\u4f20\u8f93\u5230Elasticsearch\u901a\u4fe1<br \/>\n\u7eff\u8272\u7bad\u5934\uff1a\u5ba2\u6237\u7aefPC\u8bbf\u95eeKibana\uff08WebUI\uff09\u901a\u4fe1<\/p>\n<p>\u25cfDNS \u670d\u52a1\u5668<br \/>\nCentOS 7.2<br \/>\nPacketbeat \u7248\u672c 1.2.3<\/p>\n<p>\u25cf Elasticsearch\/Kibana \u670d\u52a1\u5668<br \/>\nCentOS 7.2 \u64cd\u4f5c\u7cfb\u7edf<br \/>\nElasticsearch \u7248\u672c 2.3.5<br \/>\nKibana \u7248\u672c 2.5.4<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/17-0.png\" alt=\"Packetbeat_\u69cb\u6210_\u30df\u30e9\u30fc\u30dd\u30fc\u30c8.png\" \/><\/div>\n<h1>\u5b89\u88c5<\/h1>\n<pre class=\"post-pre\"><code>\u30fb \u4eca\u56de\u306f\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u52d5\u4f5c\u3055\u305b\u308b\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u308b\u305f\u3081\u3001\u7d30\u304b\u306a\u30d1\u30e9\u30e1\u30fc\u30bf\u306e\u8abf\u6574\u306f\u5272\u611b\u3057\u3066\u3044\u307e\u3059\u3002\r\n\u30fb Firewalld\u306f\u505c\u6b62\u3055\u305b\u3066\u3044\u308b\u60f3\u5b9a\u3067\u3059\u3002\uff08systemctl stop firewalld\uff09\r\n<\/code><\/pre>\n<h2>\u7f51\u7edc\u5c01\u5305\u8ffd\u8e2a\u5668<\/h2>\n<p>\u5728\u201cDNS \u670d\u52a1\u5668\u201d\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>yum <span class=\"nb\">install <\/span>libpcap\r\ncurl <span class=\"nt\">-L<\/span> <span class=\"nt\">-O<\/span> https:\/\/download.elastic.co\/beats\/packetbeat\/packetbeat-1.2.3-x86_64.rpm\r\n<span class=\"nb\">sudo <\/span>rpm <span class=\"nt\">-vi<\/span> packetbeat-1.2.3-x86_64.rpm\r\n<\/code><\/pre>\n<p>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u5b8c\u4e86\u5f8c\u3001\u4ee5\u4e0b\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u7de8\u96c6\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code>\/etc\/packetbeat\/packetbeat.yml\r\n<\/code><\/pre>\n<p>Protocols\u30bb\u30af\u30b7\u30e7\u30f3\u3067\u3001\u201d ports: [53]\u201d\u304c\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u3055\u308c\u3066\u3044\u306a\u3044\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<br \/>\n\u4eca\u56de\u306fDNS\u4ee5\u5916\u306e\u30ed\u30b0\u306f\u53d6\u5f97\u3057\u306a\u3044\u306e\u3067\u3001\u305d\u306e\u4ed6\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u884c\u306f\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u3057\u307e\u3059\u3002<br \/>\n\u203bports: [80, 8080, 8000, 5000, 8002]\u7b49<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<span class=\"c1\">############################# Protocols #######################################<\/span>\r\n<span class=\"na\">protocols<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">dns<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for DNS traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the DNS protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"na\">ports<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"nv\">53<\/span><span class=\"pi\">]<\/span>\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n  <span class=\"s\">http<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for HTTP traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the HTTP protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [80, 8080, 8000, 5000, 8002]<\/span>\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n  <span class=\"s\">memcache<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for memcache traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the Memcache protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [11211]<\/span>\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n  <span class=\"s\">mysql<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for MySQL traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the MySQL protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [3306]<\/span>\r\n\r\n  <span class=\"na\">pgsql<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for Pgsql traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the Pgsql protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [5432]<\/span>\r\n\r\n  <span class=\"na\">redis<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for Redis traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the Redis protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [6379]<\/span>\r\n\r\n  <span class=\"na\">thrift<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for Thrift-RPC traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the Thrift-RPC protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [9090]<\/span>\r\n\r\n  <span class=\"na\">mongodb<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Configure the ports where to listen for MongoDB traffic. You can disable<\/span>\r\n    <span class=\"c1\"># the MongoDB protocol by commenting out the list of ports.<\/span>\r\n    <span class=\"c1\">#ports: [27017]<\/span>\r\n<\/code><\/pre>\n<p>\u7136\u540e\uff0c\u5728Output\u90e8\u5206\u8fdb\u884c\u8bbe\u7f6e\u4ee5\u6307\u5b9a\u4fe1\u606f\u53d1\u9001\u5230\u76ee\u6807\u5730\uff08Elasticsearch\uff09\u3002<br \/>\n\u4f5c\u4e3a\u53d1\u9001\u76ee\u6807\uff0c\u586b\u5199Elasticsearch\/Kibana\u670d\u52a1\u5668\u7684IP\u5730\u5740\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<span class=\"c1\">############################# Output ##########################################<\/span>\r\n\r\n<span class=\"c1\"># Configure what outputs to use when sending the data collected by the beat.<\/span>\r\n<span class=\"c1\"># Multiple outputs may be used.<\/span>\r\n<span class=\"na\">output<\/span><span class=\"pi\">:<\/span>\r\n\r\n  <span class=\"c1\">### Elasticsearch as output<\/span>\r\n  <span class=\"na\">elasticsearch<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"c1\"># Array of hosts to connect to.<\/span>\r\n    <span class=\"c1\"># Scheme and port can be left out and will be set to the default (http and 9200)<\/span>\r\n    <span class=\"c1\"># In case you specify and additional path, the scheme is required: http:\/\/localhost:9200\/path<\/span>\r\n    <span class=\"c1\"># IPv6 addresses should always be defined as: https:\/\/[2001:db8::1]:9200<\/span>\r\n    <span class=\"c1\">#hosts: [\"localhost:9200\"]<\/span>\r\n    <span class=\"na\">hosts<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"s2\">\"<\/span><span class=\"s\">192.168.1.18:9200\"<\/span><span class=\"pi\">]<\/span>\r\n\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<\/code><\/pre>\n<p>\u8bbe\u7f6e\u5b8c\u6210\u540e\uff0c\u542f\u52a8&#8221;Packetbeat&#8221;\u3002<\/p>\n<pre class=\"post-pre\"><code>sudo systemctl start packetbeat\r\n<\/code><\/pre>\n<h2>Elasticsearch \u5f39\u6027\u641c\u7d22<\/h2>\n<p>\u5728&#8221;Elasticsearch\/Kibana\u670d\u52a1\u5668&#8221;\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>yum <span class=\"nb\">install<\/span> <span class=\"nt\">-y<\/span> java\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo cat<\/span> <span class=\"o\">&lt;&lt;<\/span><span class=\"no\">EOF<\/span><span class=\"sh\">&gt; \/etc\/yum.repos.d\/elasticsearch.repo\r\n[elasticsearch-2.x]\r\nname=Elasticsearch repository for 2.x packages\r\nbaseurl=http:\/\/packages.elastic.co\/elasticsearch\/2.x\/centos\r\ngpgcheck=1\r\ngpgkey=http:\/\/packages.elastic.co\/GPG-KEY-elasticsearch\r\nenabled=1\r\n<\/span><span class=\"no\">EOF\r\n<\/span><\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>yum <span class=\"nb\">install <\/span>elasticsearch-2.3.5\r\n<\/code><\/pre>\n<p>\u5b89\u88c5\u5b8c\u6210\u540e\uff0c\u5c06\u7f16\u8f91\u4ee5\u4e0b\u8bbe\u7f6e\u6587\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code>\/etc\/elasticsearch\/elasticsearch.yml\r\n<\/code><\/pre>\n<p>\u5728\u7f51\u7edc\u90e8\u5206\uff0c\u5c06&#8221;Elasticsearch\/Kibana Server&#8221;\u7684IP\u5730\u5740\u586b\u5199\u5230&#8221;network.host&#8221;\u9009\u9879\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<span class=\"c1\"># ---------------------------------- Network -----------------------------------<\/span>\r\n<span class=\"c1\">#<\/span>\r\n<span class=\"c1\"># Set the bind address to a specific IP (IPv4 or IPv6):<\/span>\r\n<span class=\"c1\">#<\/span>\r\n<span class=\"s\">network.host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">192.168.1.18<\/span>\r\n<span class=\"c1\">#<\/span>\r\n<span class=\"c1\"># Set a custom port for HTTP:<\/span>\r\n<span class=\"c1\">#<\/span>\r\n<span class=\"c1\"># http.port: 9200<\/span>\r\n<span class=\"c1\">#<\/span>\r\n<span class=\"c1\"># For more information, see the documentation at:<\/span>\r\n<span class=\"c1\"># &lt;http:\/\/www.elastic.co\/guide\/en\/elasticsearch\/reference\/current\/modules-network.html&gt;<\/span>\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<\/code><\/pre>\n<p>\u914d\u7f6e\u5b8c\u6210\u540e\uff0c\u542f\u52a8&#8221;Elasticsearch&#8221;\u3002<\/p>\n<pre class=\"post-pre\"><code>sudo systemctl start elasticsearch\r\n<\/code><\/pre>\n<h2>Kibana \u53ef\u89c6\u5316\u5de5\u5177<\/h2>\n<p>\u5728&#8221;Elasticsearch\/Kibana\u670d\u52a1\u5668&#8221;\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo cat<\/span> <span class=\"o\">&lt;&lt;<\/span><span class=\"no\">EOF<\/span><span class=\"sh\">&gt; \/etc\/yum.repos.d\/kibana.repo\r\n[kibana-4.5]\r\nname=Kibana repository for 4.5.x packages\r\nbaseurl=http:\/\/packages.elastic.co\/kibana\/4.5\/centos\r\ngpgcheck=1\r\ngpgkey=http:\/\/packages.elastic.co\/GPG-KEY-elasticsearch\r\nenabled=1\r\n<\/span><span class=\"no\">EOF\r\n<\/span><\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>yum <span class=\"nb\">install <\/span>kibana-4.5.4\r\n<\/code><\/pre>\n<p>\u5b89\u88c5\u5b8c\u6210\u540e\uff0c\u9700\u8981\u7f16\u8f91\u4ee5\u4e0b\u914d\u7f6e\u6587\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">\/opt\/kibana\/config\/kibana.yml<\/span>\r\n<\/code><\/pre>\n<p>\u5c06&#8221;Elasticsearch\/Kibana Server&#8221; \u7684 IP \u5730\u5740\u586b\u5199\u5230 &#8220;elasticsearch.url&#8221; \u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<span class=\"c1\"># The Elasticsearch instance to use for all your queries.<\/span>\r\n<span class=\"s\">elasticsearch.url<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">http:\/\/192.168.1.18:9200\"<\/span>\r\n\r\n<span class=\"c1\"># preserve_elasticsearch_host true will send the hostname specified in `elasticsearch`. If you set it to false,<\/span>\r\n<span class=\"c1\"># then the host you use to connect to *this* Kibana instance will be sent.<\/span>\r\n<span class=\"c1\"># elasticsearch.preserveHost: true<\/span>\r\n<span class=\"s\">&lt;\u7565&gt;<\/span>\r\n<\/code><\/pre>\n<p>\u5728\u8bbe\u7f6e\u5b8c\u6210\u540e\uff0c\u6211\u4eec\u5c06\u542f\u52a8&#8221;Kibana&#8221;\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">sudo <\/span>systemctl start kibana\r\n<\/code><\/pre>\n<h1>Elasticsearch\u6a21\u677f\u7684\u5b9a\u4e49<\/h1>\n<p>\u4e3a\u4e86\u5904\u7406Packetbeat\u5728Elasticsearch\u4e2d\u83b7\u53d6\u5230\u7684\u4fe1\u606f\uff0c\u6211\u4eec\u9700\u8981\u5b9a\u4e49\u4e00\u4e2a\u6a21\u677f\u3002<\/p>\n<p>\u5728\u201cDNS\u670d\u52a1\u5668\u201d\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-XPUT<\/span> <span class=\"s1\">'http:\/\/192.168.1.18:9200\/_template\/packetbeat'<\/span> <span class=\"nt\">-d<\/span>@\/etc\/packetbeat\/packetbeat.template.json\r\n\r\n<span class=\"o\">{<\/span><span class=\"s2\">\"acknowledged\"<\/span>:true<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<p>\u786e\u8ba4\u6267\u884c\u547d\u4ee4\u540e\u7684\u7ed3\u679c\u4e3a\u201d{&#8220;acknowledged&#8221;:true}\u201d\u3002<\/p>\n<h1>Kibana\u4eea\u8868\u677f\u5b9a\u4e49<\/h1>\n<p>\u4f7f\u7528Kibana\u5b9a\u4e49\u7528\u4e8e\u65e5\u5fd7\u53ef\u89c6\u5316\u7684\u4eea\u8868\u677f\u3002<\/p>\n<p>\u5728&#8221;Elasticsearch\/Kibana Server&#8221;\u4e0a\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u3002<\/p>\n<p>\u203b\u5b89\u88c5Elastic\u516c\u53f8\u63d0\u4f9b\u7684\u4eea\u8868\u677f\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-L<\/span> <span class=\"nt\">-O<\/span> http:\/\/download.elastic.co\/beats\/dashboards\/beats-dashboards-1.2.3.zip\r\nunzip beats-dashboards-1.2.3.zip\r\n<span class=\"nb\">cd <\/span>beats-dashboards-1.2.3\/\r\n.\/load.sh\r\n<\/code><\/pre>\n<p>\u9664\u4e86Packetbeat\u4e4b\u5916\uff0c\u8fd8\u4f1a\u5b89\u88c5\u5176\u4ed6Beats\u7cfb\u5217\u7684\u4eea\u8868\u76d8\u3002<\/p>\n<h1>\u8bbf\u95eeKibana<\/h1>\n<p>\u6211\u8981\u4f7f\u7528Kibana\u8fdb\u884c\u8bbf\u95ee\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">http:\/\/192.168.1.18:5601\/\r\n<\/span><\/code><\/pre>\n<p>\u8bf7\u6253\u5f00\u4ee5\u4e0b\u754c\u9762\uff0c\u5e76\u4ece\u5de6\u4fa7\u83dc\u5355\u4e2d\u9009\u62e9&#8221;packetbeat-*&#8221;\uff0c\u5728\u53f3\u4fa7\u83dc\u5355\u4e2d\u627e\u5230\u8be5\u754c\u9762\u5e76\u70b9\u51fb\u661f\u5f62\u56fe\u6807\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/67-0.jpeg\" alt=\"Kibana_2.5.4.jpg\" \/><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/68-0.jpeg\" alt=\"Kibana_2.5.4..jpg\" \/><\/div>\n<p>\u63a5\u4e0b\u6765\uff0c\u70b9\u51fb\u4e0a\u65b9\u83dc\u5355\u680f\u7684\u201cDashbord\u201d\uff0c\u7136\u540e\u70b9\u51fb\u663e\u793a\u5c4f\u5e55\u53f3\u4e0a\u65b9\u7684\u6587\u4ef6\u5939\u56fe\u6807\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/70-0.jpeg\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8_081516_072415_PM.jpg\" \/><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/71-0.jpeg\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8_081516_072505_PM.jpg\" \/><\/div>\n<p>Dashbord\u306e\u9078\u629e\u30e1\u30cb\u30e5\u30fc\u304c\u8868\u793a\u3055\u308c\u308b\u306e\u3067\u3001\u201dPacketbeat Dashboard\u201d\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/73-1.jpeg\" alt=\"Kibana_2.5.4.jpg\" \/><\/div>\n<h1>\u521b\u5efa\u4e13\u7528\u4e8eDNS\u7684\u4eea\u8868\u677f<\/h1>\n<p>\u7531\u4e8e\u201cPacketbeat Dashboard\u201d\u5e76\u4e0d\u662f\u4e13\u7528\u4e8eDNS\u7684\u4eea\u8868\u677f\uff0c\u56e0\u6b64\u6211\u4eec\u9700\u8981\u521b\u5efa\u4e00\u4e2a\u4e13\u7528\u7684\u4eea\u8868\u677f\u3002<\/p>\n<p>\u6211\u60f3\u5728\u4e0b\u4e00\u7bc7\u6587\u7ae0\u4e2d\u5199\u4e0b\u7eed\u7bc7\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u6700\u8fd1\u6709\u4e00\u4e9b\u6d88\u606f\uff0c\u6765\u81ea\u682a\u5f0f\u4f1a\u793e\u30e9\u30c3\u30af\u516c\u53f8\uff0c\u5173\u4e8e\u4f7f\u7528DNS\u534f\u8bae\u7684\u75c5\u6bd2\u7684\u8b66\u544a\u3002 \u25a0\u9060\u9694\u64cd\u4f5c\u30a6\u30a4\u30eb\u30b9\u306e\u5236\u5fa1\u306bDN [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-34523","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528packetbeatelasticsearchkibana\u5c06dns\u65e5\u5fd7\u53ef\u89c6\u5316\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u6700\u8fd1\u6709\u4e00\u4e9b\u6d88\u606f\uff0c\u6765\u81ea\u682a\u5f0f\u4f1a\u793e\u30e9\u30c3\u30af\u516c\u53f8\uff0c\u5173\u4e8e\u4f7f\u7528DNS\u534f\u8bae\u7684\u75c5\u6bd2\u7684\u8b66\u544a\u3002 \u25a0\u9060\u9694\u64cd\u4f5c\u30a6\u30a4\u30eb\u30b9\u306e\u5236\u5fa1\u306bDN [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528packetbeatelasticsearchkibana\u5c06dns\u65e5\u5fd7\u53ef\u89c6\u5316\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-17T21:46:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-28T17:41:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/13-0.png\" \/>\n<meta name=\"author\" content=\"\u65b0, \u97f5\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u65b0, \u97f5\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\",\"name\":\"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-01-17T21:46:50+00:00\",\"dateModified\":\"2024-04-28T17:41:10+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9\",\"name\":\"\u65b0, \u97f5\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g\",\"caption\":\"\u65b0, \u97f5\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528packetbeatelasticsearchkibana\u5c06dns\u65e5\u5fd7\u53ef\u89c6\u5316\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316","og_description":"\u9996\u5148 \u6700\u8fd1\u6709\u4e00\u4e9b\u6d88\u606f\uff0c\u6765\u81ea\u682a\u5f0f\u4f1a\u793e\u30e9\u30c3\u30af\u516c\u53f8\uff0c\u5173\u4e8e\u4f7f\u7528DNS\u534f\u8bae\u7684\u75c5\u6bd2\u7684\u8b66\u544a\u3002 \u25a0\u9060\u9694\u64cd\u4f5c\u30a6\u30a4\u30eb\u30b9\u306e\u5236\u5fa1\u306bDN [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528packetbeatelasticsearchkibana\u5c06dns\u65e5\u5fd7\u53ef\u89c6\u5316\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-01-17T21:46:50+00:00","article_modified_time":"2024-04-28T17:41:10+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d1dcd37434c4406c14548\/13-0.png"}],"author":"\u65b0, \u97f5","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u65b0, \u97f5","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"3 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/","name":"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-01-17T21:46:50+00:00","dateModified":"2024-04-28T17:41:10+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528Packetbeat+Elasticsearch+Kibana\u5c06DNS\u65e5\u5fd7\u53ef\u89c6\u5316"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/4ba4019495123db3038fd0809e6959c9","name":"\u65b0, \u97f5","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d484b6c6e4ae82e8a9efea989e1d2af46d9b6ef128101e63b18f559fca0ae627?s=96&d=mm&r=g","caption":"\u65b0, \u97f5"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunxin\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8packetbeatelasticsearchkibana%e5%b0%86dns%e6%97%a5%e5%bf%97%e5%8f%af%e8%a7%86%e5%8c%96%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/34523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=34523"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/34523\/revisions"}],"predecessor-version":[{"id":72398,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/34523\/revisions\/72398"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=34523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=34523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=34523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}