{"id":41030,"date":"2023-01-11T10:37:50","date_gmt":"2023-10-27T13:48:32","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/"},"modified":"2024-04-29T09:28:05","modified_gmt":"2024-04-29T01:28:05","slug":"%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/","title":{"rendered":"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743"},"content":{"rendered":"<h1>\u672c\u6587\u7684\u6982\u8ff0<\/h1>\n<p>ELK\uff08Elasticsearch + Logstash + Kibana\uff09\u88ab\u5e7f\u6cdb\u8ba4\u53ef\u4f5c\u4e3a\u65e5\u5fd7\u6536\u96c6\u548c\u5206\u6790\u7684\u57fa\u7840\u67b6\u6784\uff0c\u5176\u4e2d\u4ee5Elasticsearch + Kibana\u8d1f\u8d23\u65e5\u5fd7\u7684\u7ba1\u7406\u548c\u53ef\u89c6\u5316\u3002\u7136\u800c\uff0c\u76ee\u524dKibana\u5e76\u672a\u5b9e\u73b0\u8bf8\u5982\u8ba4\u8bc1\u3001\u6388\u6743\u548c\u5b89\u5168\u9632\u62a4\u7b49\u529f\u80fd\uff0c\u8fd9\u5728\u6b63\u5f0f\u8fd0\u8425\u65f6\u4f1a\u9762\u4e34\u4e00\u4e9b\u95ee\u9898\u3002\u6ca1\u6709\u8ba4\u8bc1\u548c\u6388\u6743\u7684\u60c5\u51b5\u4e0b\uff0c\u6bd4\u5982\u7ba1\u7406\u5458\u5728Kibana\u4e0a\u521b\u5efa\u4e86\u53ef\u89c6\u5316\u56fe\u8868\u548c\u4eea\u8868\u76d8\uff0c\u4efb\u4f55\u6709Kibana\u8bbf\u95ee\u6743\u9650\u7684\u4eba\u90fd\u53ef\u4ee5\u4fee\u6539\u8fd9\u4e9b\u5185\u5bb9\u3002\u56e0\u6b64\uff0c\u6211\u4eec\u51b3\u5b9a\u5c1d\u8bd5\u4f7f\u7528Elasticsearch\u7684\u4ed8\u8d39\u5b89\u5168\u63d2\u4ef6&#8221;Shield&#8221;\u6765\u5b9e\u73b0Kibana\u7684\u8ba4\u8bc1\u548c\u6388\u6743\uff0c\u5e76\u6839\u636e\u7528\u6237\u7684\u6743\u9650\u5c06\u53ef\u89c6\u5316\u56fe\u8868\u548c\u4eea\u8868\u76d8\u8bbe\u4e3a\u53ea\u8bfb\u6a21\u5f0f\u3002<\/p>\n<p>\u203bKibana\u7684\u8eab\u4efd\u9a8c\u8bc1\u529f\u80fd\u6700\u521d\u8ba1\u5212\u57284.2\u7248\u672c\u4e2d\u5f15\u5165\uff0c\u4f46\u76ee\u524d\u8ba1\u5212\u57284.4\u7248\u672c\u4e2d\u5f15\u5165\u3002<br \/>\nhttps:\/\/github.com\/elastic\/kibana\/issues\/3904<\/p>\n<h1>\u73af\u5883\u4fe1\u606f<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">OS\uff1aCentOS6.5 on VirtualBox + Vagrant<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Logstash 2.1.1<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Elasticsearch 2.1.0<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Kibana 4.3.0<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Java 1.8.65<\/ul>\n<h1>\u5b98\u65b9\u7f51\u7ad9<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Elasticsearch<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">https:\/\/www.elastic.co\/products\/elasticsearch<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Logstash<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">https:\/\/www.elastic.co\/products\/logstash<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Kibana<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">https:\/\/www.elastic.co\/products\/kibana<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Shield<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">https:\/\/www.elastic.co\/products\/shield<\/ul>\n<h1>\u4e8b\u524d\u51c6\u5907<\/h1>\n<h2>\u5b89\u88c5ELK<\/h2>\n<h3>\u65e5\u5fd7\u805a\u5408\u5de5\u5177<\/h3>\n<pre class=\"post-pre\"><code>wget <span class=\"nt\">-P<\/span> \/usr\/local\/src\/ https:\/\/download.elastic.co\/logstash\/logstash\/packages\/centos\/logstash-2.1.1-1.noarch.rpm\r\nrpm <span class=\"nt\">-ivh<\/span> \/usr\/local\/src\/logstash-2.1.1-1.noarch.rpm\r\n<\/code><\/pre>\n<h3>\u5f39\u6027\u641c\u7d22<\/h3>\n<pre class=\"post-pre\"><code>wget <span class=\"nt\">-P<\/span> \/usr\/local\/src\/ https:\/\/download.elasticsearch.org\/elasticsearch\/release\/org\/elasticsearch\/distribution\/rpm\/elasticsearch\/2.1.0\/elasticsearch-2.1.0.rpm\r\nrpm <span class=\"nt\">-ivh<\/span> \/usr\/local\/src\/elasticsearch-2.1.0.rpm\r\n<\/code><\/pre>\n<h3>Elasticsearch\u53ef\u89c6\u5316\u5de5\u5177Kibana<\/h3>\n<pre class=\"post-pre\"><code>wget <span class=\"nt\">-P<\/span> \/usr\/local\/src\/ https:\/\/download.elastic.co\/kibana\/kibana\/kibana-4.3.0-linux-x64.tar.gz\r\n<span class=\"nb\">tar <\/span>xzvf \/usr\/local\/src\/kibana-4.3.0-linux-x64.tar.gz <span class=\"nt\">-C<\/span> \/opt\r\n<\/code><\/pre>\n<p>\u4e3a\u4e86\u542f\u52a8ELK\uff0c\u5047\u8bbeJava\u5df2\u7ecf\u5b89\u88c5\u3002<\/p>\n<h2>ELK\u5408\u4f5c<\/h2>\n<p>\u4f7f\u7528Logstash\u7684input-twitter-plugin\u5c06\u65f6\u95f4\u7ebf\u5bfc\u5165\u5230Elasticsearch\u4e2d\uff0c\u5e76\u5728Kibana\u4e2d\u8fdb\u884c\u53ef\u89c6\u5316\u3002<br \/>\n\u5c3d\u7ba1\u8fd9\u4e0d\u662f\u91cd\u70b9\uff0c\u4f46\u8003\u8651\u5230\u5373\u5c06\u5230\u6765\u7684\u5723\u8bde\u8282\uff0c\u6211\u4eec\u5c06\u5c1d\u8bd5\u6536\u96c6\u4e0e\u201cXmas\u201d\u5173\u952e\u8bcd\u76f8\u5173\u7684\u65f6\u95f4\u7ebf\u3002<\/p>\n<h3>Logstash\u7684\u914d\u7f6e<\/h3>\n<pre class=\"post-pre\"><code><span class=\"n\">input<\/span> {\r\n    <span class=\"n\">twitter<\/span> {\r\n        <span class=\"n\">consumer_key<\/span> =&gt; <span class=\"s2\">\"&lt;consumer_key&gt;\"<\/span>\r\n        <span class=\"n\">consumer_secret<\/span> =&gt; <span class=\"s2\">\"&lt;consumer_secret&gt;\"<\/span>\r\n        <span class=\"n\">oauth_token<\/span> =&gt; <span class=\"s2\">\"&lt;oauth_token&gt;\"<\/span>\r\n        <span class=\"n\">oauth_token_secret<\/span> =&gt; <span class=\"s2\">\"&lt;oauth_token_secret&gt;\"<\/span>\r\n        <span class=\"n\">keywords<\/span> =&gt; [<span class=\"s2\">\"Xmas\"<\/span>]\r\n        <span class=\"n\">full_tweet<\/span> =&gt; <span class=\"n\">true<\/span>\r\n        <span class=\"n\">ignore_retweets<\/span> =&gt; <span class=\"n\">true<\/span>\r\n    }\r\n}\r\n<span class=\"n\">output<\/span> {\r\n    <span class=\"n\">elasticsearch<\/span> {\r\n    }\r\n    <span class=\"n\">stdout<\/span> {\r\n        <span class=\"n\">codec<\/span> =&gt; <span class=\"n\">rubydebug<\/span>\r\n    }\r\n}\r\n<\/code><\/pre>\n<p>\u8bf7\u4f7f\u7528\u5728Twitter Apps\u4e2d\u6ce8\u518c\u7684\u5e94\u7528\u7a0b\u5e8f\u7684consumer_key\uff0cconsumer_secret\uff0coauth_token\u548coauth_token_secret\u3002<br \/>\n\u53c2\u8003\uff1ahttp:\/\/dev.classmethod.jp\/cloud\/aws\/twitter-visualize-using-elastic\/<\/p>\n<h3>\u542f\u52a8Elasticsearch<\/h3>\n<pre class=\"post-pre\"><code>service elasticsearch start\r\n<\/code><\/pre>\n<h3>\u542f\u52a8Kibana<\/h3>\n<pre class=\"post-pre\"><code>\/opt\/kibana-4.3.0-linux-x64\/bin\/kibana &amp;\r\n<\/code><\/pre>\n<h3>\u542f\u52a8Logstash<\/h3>\n<pre class=\"post-pre\"><code>service logstash start\r\n<\/code><\/pre>\n<h3>\u786e\u8ba4\u65e5\u5fd7\u8054\u52a8<\/h3>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/28-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 3.10.25.png\" \/><\/div>\n<h1>\u5b89\u5168\u8bbe\u7f6e<\/h1>\n<p>\u5f53\u51c6\u5907\u5de5\u4f5c\u5df2\u5b8c\u6210\uff0c\u73b0\u5728\u8981\u5f00\u59cb\u5b9e\u73b0\u5bf9Kibana\u7684\u8eab\u4efd\u9a8c\u8bc1\u548c\u6388\u6743\u3002<\/p>\n<h2>\u76fe\u724c\u5b89\u88c5<\/h2>\n<p>\u9996\u5148\uff0c\u5b89\u88c5Elasticsearch\u7684\u5b89\u5168\u63d2\u4ef6\u201cShield\u201d\u3002\u8be5\u63d2\u4ef6\u662f\u4e00\u4e2a\u4ed8\u8d39\u8ba2\u9605\u670d\u52a1\uff0c\u5e76\u63d0\u4f9b30\u5929\u7684\u8bd5\u7528\u8bb8\u53ef\u8bc1\uff0c\u60a8\u53ef\u4ee5\u4f7f\u7528\u5b83\u6765\u8bd5\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code>\/usr\/share\/elasticsearch\/bin\/plugin <span class=\"nb\">install <\/span>elasticsearch\/license\/latest\r\n\/usr\/share\/elasticsearch\/bin\/plugin <span class=\"nb\">install <\/span>elasticsearch\/shield\/latest\r\n<\/code><\/pre>\n<h2>\u9274\u5b9a\uff08Authentication\uff09<\/h2>\n<h3>\u5728Shield\u4e2d\u7684\u8ba4\u8bc1\u7406\u5ff5<\/h3>\n<p>Shield\u5728\u53d7\u5230\u7528\u6237\u8d44\u683c\u4fe1\u606f\u5e76\u8fdb\u884c\u9a8c\u8bc1\u7684\u8ba4\u8bc1\u673a\u5236\u4e2d\u5b9a\u4e49\u4e86\u201c\u9886\u57df\u201d\uff0c\u5e76\u652f\u6301\u56db\u79cd\u7c7b\u578b\u7684\u201c\u9886\u57df\u201d\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">esusers<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Shield\u306b\u7d44\u307f\u8fbc\u307e\u308c\u305f\u30cd\u30a4\u30c6\u30a3\u30d6\u306e\u8a8d\u8a3c\u30b7\u30b9\u30c6\u30e0\u3068\u306a\u308a\u307e\u3059\u3002\uff08\u30c7\u30d5\u30a9\u30eb\u30c8\uff09<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30d5\u30a1\u30a4\u30eb\u30d9\u30fc\u30b9\u306e\u30ec\u30eb\u30e0\u3068\u306a\u308a\u3001\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u304b\u3089\u30e6\u30fc\u30b6\u306e\u8ffd\u52a0\u30fb\u524a\u9664\u7b49\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">LDAP<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5916\u90e8\u306eLDAP\u30b5\u30fc\u30d0\u3067\u30e6\u30fc\u30b6\u3092\u8a8d\u8a3c\u3059\u308b\u30ec\u30eb\u30e0\u3068\u306a\u308a\u307e\u3059\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Active Directory<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5916\u90e8\u306eActive Directory\u30b5\u30fc\u30d0\u3067\u30e6\u30fc\u30b6\u3092\u8a8d\u8a3c\u3059\u308b\u30ec\u30eb\u30e0\u3068\u306a\u308a\u307e\u3059\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">PKI<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u516c\u958b\u9375\u3092\u5229\u7528\u3057\u3066\u8a8d\u8a3c\u3092\u884c\u3046\u30ec\u30eb\u30e0\u3068\u306a\u308a\u307e\u3059\u3002<\/ul>\n<p>\u6211\u60f3\u4f7f\u7528\u9ed8\u8ba4\u7684esusers\u9886\u57df\u6765\u5904\u7406\u672c\u6b21\u4e8b\u52a1\u3002<\/p>\n<h3>\u6dfb\u52a0\u7528\u6237<\/h3>\n<p>\u5728esusers\u9886\u57df\u4e2d\uff0c\u60a8\u53ef\u4ee5\u901a\u8fc7esusers\u547d\u4ee4\u6dfb\u52a0\u7528\u6237\uff0c\u4f46\u5728\u6dfb\u52a0\u7528\u6237\u4e4b\u524d\uff0c\u6211\u5e0c\u671b\u5148\u63d0\u53ca\u6388\u6743\u3002<\/p>\n<h2>\u6388\u6743\uff08Authorization\uff09<\/h2>\n<h3>Shield\u5728\u8bb8\u53ef\u65b9\u9762\u7684\u7406\u5ff5<\/h3>\n<p>Shiled\u5229\u7528\u4e86\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u63a7\u5236\uff08RBAC\uff09\u6a21\u578b\u6765\u5b9e\u73b0\u5bf9\u6bcf\u4e2a\u7528\u6237\u7684\u6743\u9650\u7ba1\u7406\u3002\u7b80\u5355\u6765\u8bf4\uff0c\u6bcf\u4e2a\u89d2\u8272\u90fd\u6709\u4e00\u7ec4\u6743\u9650\u5b9a\u4e49\uff0c\u800c\u6bcf\u4e2a\u7528\u6237\u5219\u4e0e\u4e00\u7ec4\u89d2\u8272\u76f8\u7ed1\u5b9a\u3002<\/p>\n<h3>\u5b9a\u4e49\u5377<\/h3>\n<p>Shild\u7684\u89d2\u8272\u7531roles.yml\u6587\u4ef6\u5b9a\u4e49\u3002<br \/>\n\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5df2\u5b9a\u4e49\u4e86\u51e0\u4e2a\u89d2\u8272\uff0c\u5982\u7ba1\u7406\u5458\u89d2\u8272admin\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c1\"># All cluster rights<\/span>\r\n<span class=\"c1\"># All operations on all indices<\/span>\r\n<span class=\"na\">admin<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">cluster<\/span><span class=\"pi\">:<\/span> <span class=\"s\">all<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">all<\/span>\r\n\r\n<span class=\"c1\"># Monitoring cluster privileges<\/span>\r\n<span class=\"c1\"># All operations on all indices<\/span>\r\n<span class=\"na\">power_user<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">cluster<\/span><span class=\"pi\">:<\/span> <span class=\"s\">monitor<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">all<\/span>\r\n\r\n<span class=\"c1\"># Only read operations on indices<\/span>\r\n<span class=\"na\">user<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">read<\/span>\r\n\r\n<span class=\"c1\"># Only read operations on indices named events_*<\/span>\r\n<span class=\"na\">events_user<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">events_*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">read<\/span>\r\n<\/code><\/pre>\n<p>Shield\u5c06Elasticsearch\u7684\u6743\u9650\u5206\u4e3a\u4e24\u4e2a\u4e3b\u8981\u7c7b\u578b\uff1acluster\uff08\u7fa4\u96c6\uff09\u548cindices\uff08\u7d22\u5f15\uff09\u3002<br \/>\ncluster\u5b9a\u4e49\u4e86\u5bf9Elasticsearch\u7fa4\u96c6\u7684\u7ba1\u7406\u548c\u76d1\u63a7\u64cd\u4f5c\u7684\u6743\u9650\u3002<br \/>\nindices\u5b9a\u4e49\u4e86\u5bf9\u7fa4\u96c6\u4e2d\u7279\u5b9a\u7d22\u5f15\u7684\u7ba1\u7406\u548c\u76d1\u63a7\u64cd\u4f5c\u7684\u6743\u9650\u3002<\/p>\n<p>\u53ef\u4ee5\u4e3a\u6bcf\u4e2acluster\u548c\u7d22\u5f15\u8bbe\u7f6eall\u3001monitor\u3001read\u3001write\u7b49\u9884\u5b9a\u4e49\u6743\u9650\uff0c\u4e5f\u53ef\u4ee5\u66f4\u7ec6\u7c92\u5ea6\u5730\u6307\u5b9a\u7279\u5b9a\u89d2\u8272\u7684\u7279\u5b9a\u64cd\u4f5c\uff0c\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">user01<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">indices:admin\/create, indices:admin\/exists<\/span>\r\n<\/code><\/pre>\n<h3>\u589e\u52a0\u5377<\/h3>\n<p>\u5c3d\u7ba1\u524d\u9762\u7684\u51c6\u5907\u5de5\u4f5c\u6709\u70b9\u957f\uff0c\u4f46\u8fd9\u6b21\u6211\u4eec\u5c06\u5728Kibana\u4e2d\u4f7f\u7528\u4ee5\u4e0b\u4e09\u79cd\u89d2\u8272\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">kibana4_server\uff1aKibana\u30b5\u30fc\u30d0\u7528\u306e\u30ed\u30fc\u30eb<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">kibana4\uff1aKibana\u7ba1\u7406\u30ed\u30fc\u30eb\uff08Visualization\u3001Dashboard\u306e\u8aad\u53d6\u30fb\u4f5c\u6210\u30fb\u66f4\u65b0\u30fb\u524a\u9664\u53ef\uff09<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">kibana4_monitor\uff1aKibana\u76e3\u8996\u30ed\u30fc\u30eb\uff08Visualization\u3001Dashboard\u306f\u8aad\u53d6\u306e\u307f\u53ef\uff09<\/ul>\n<p>\u7f16\u8f91roles.yml\u6587\u4ef6\u5e76\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff0c\u4f7f\u7528kibana4_server\u89d2\u8272\u548ckibana4\u89d2\u8272\u7684\u9ed8\u8ba4\u5b9a\u4e49\uff0c\u521b\u5efa\u4e00\u4e2a\u65b0\u7684kibana4_monitoring\u89d2\u8272\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c1\"># The required permissions for the kibana 4 monitor<\/span>\r\n<span class=\"na\">kibana4_monitoring<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">cluster<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">cluster:monitor\/nodes\/info<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">cluster:monitor\/health<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">logstash-*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/get<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/mappings\/fields\/get<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/validate\/query<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/search<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/msearch<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/field_stats<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">.kibana'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/exists<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/get<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/mapping\/put<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/mappings\/fields\/get<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/refresh<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:admin\/validate\/query<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/mget<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/search<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/msearch<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">indices:data\/read\/field_stats<\/span>\r\n<\/code><\/pre>\n<p>\u4e0eKibana 4\u89d2\u8272\u7684\u5b9a\u4e49\u8fdb\u884c\u6bd4\u8f83\u540e\uff0c\u6211\u4eec\u53ef\u4ee5\u53d1\u73b0.kibana\u7d22\u5f15\u7684\u6570\u636e\u5199\u5165\u6743\u9650\u88ab\u6392\u9664\u5728\u5916\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"c1\"># The required permissions for kibana 4 users.<\/span>\r\n<span class=\"na\">kibana4<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">cluster<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">cluster:monitor\/nodes\/info<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"s\">cluster:monitor\/health<\/span>\r\n  <span class=\"na\">indices<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">*'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">indices:admin\/mappings\/fields\/get, indices:admin\/validate\/query, indices:data\/read\/search, indices:data\/read\/msearch, indices:admin\/get<\/span>\r\n    <span class=\"s1\">'<\/span><span class=\"s\">.kibana'<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">privileges<\/span><span class=\"pi\">:<\/span> <span class=\"s\">indices:admin\/exists, indices:admin\/mapping\/put, indices:admin\/mappings\/fields\/get, indices:admin\/refresh, indices:admin\/validate\/query, indices:data\/read\/get, indices:data\/read\/mget, indices:data\/read\/search, indices:data\/write\/delete, indices:data\/write\/index, indices:data\/write\/update<\/span>\r\n<\/code><\/pre>\n<h3>\u5404\u79cd\u7528\u6237\u521b\u5efa\uff1a<\/h3>\n<p>\u521b\u5efa\u4e0e\u4e0a\u8ff0\u521b\u5efa\u7684\u89d2\u8272\u76f8\u5173\u8054\u7684\u7528\u6237\u3002<br \/>\n\u5728esusers\u547d\u4ee4\u4e2d\uff0c\u4f7f\u7528useradd\u9009\u9879\u6307\u5b9a&#8221;\u8981\u521b\u5efa\u7684\u7528\u6237\u540d&#8221;\uff0c\u5e76\u4f7f\u7528-r\u9009\u9879\u6307\u5b9a&#8221;\u8981\u5173\u8054\u7684\u89d2\u8272\u540d&#8221;\u3002<br \/>\n\u6267\u884c\u547d\u4ee4\u540e\uff0c\u5c06\u8981\u6c42\u8f93\u5165\u5bc6\u7801\u3002<\/p>\n<pre class=\"post-pre\"><code># Kibana\u30b5\u30fc\u30d0\u7528\u30e6\u30fc\u30b6\r\n\/usr\/share\/elasticsearch\/bin\/shield\/esusers useradd kibana4_server -r kibana4_server\r\n# Kibana\u7ba1\u7406\u7528\u30e6\u30fc\u30b6\r\n\/usr\/share\/elasticsearch\/bin\/shield\/esusers useradd kibana4 -r kibana4\r\n# Kibana\u76e3\u8996\u7528\u30e6\u30fc\u30b6\r\n\/usr\/share\/elasticsearch\/bin\/shield\/esusers useradd kibana4_monitor -r kibana4_monitoring\r\n<\/code><\/pre>\n<h2>Kibana\u8bbe\u7f6e<\/h2>\n<p>\u7f16\u8f91Kibana\u7684\u914d\u7f6e\u6587\u4ef6\uff08\/config\/kibana.yml\uff09\uff0c\u5e76\u6dfb\u52a0Kibana\u670d\u52a1\u5668\u7528\u6237\u7684\u5b9a\u4e49\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">elasticsearch.username<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">kibana4_server\"<\/span>\r\n<span class=\"s\">elasticsearch.password<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">password\"<\/span>\r\n<\/code><\/pre>\n<p>\u5b8c\u6210\u4e0a\u8ff0\u8bbe\u7f6e\u540e\uff0c\u91cd\u65b0\u542f\u52a8Elasticsearch\u548cKibana\uff0c\u5e76\u4eceKibana\u754c\u9762\u4e0a\u8fdb\u884c\u786e\u8ba4\u3002<\/p>\n<h1>\u786e\u8ba4<\/h1>\n<h2>\u4ee5Kibana\u7ba1\u7406\u7528\u6237\u7684\u8eab\u4efd\u767b\u5f55\u3002<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/66-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.35.23.png\" \/><\/div>\n<h2>\u521b\u5efa\u6570\u636e\u53ef\u89c6\u5316\u548c\u4eea\u8868\u677f<\/h2>\n<p>\u6211\u4f1a\u5728Dashboard\u4e0a\u521b\u5efa\u4e00\u4e2a\u9002\u5f53\u7684\u53ef\u89c6\u5316\uff0c\u5e76\u5c06\u5176\u4fdd\u5b58\u4e3a\u201cdashboard_twitter\u201d\u3002\u4f5c\u4e3a\u7ba1\u7406\u5458\uff0c\u6211\u53ef\u4ee5\u6beb\u65e0\u95ee\u9898\u5730\u4fdd\u5b58\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/69-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.37.01.png\" \/><\/div>\n<h2>\u4f7f\u7528Kibana\u76d1 audit \u8bf7\u767b\u5f55 \u4f60 \u7528\u6237 \u3002<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/71-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.29.05.png\" \/><\/div>\n<h2>\u6570\u636e\u53ef\u89c6\u5316\u3001\u4eea\u8868\u677f\u52a0\u8f7d<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/73-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.37.01.png\" \/><\/div>\n<h2>\u53ef\u89c6\u5316\u3001\u4eea\u8868\u677f\u7684\u7f16\u8f91\u548c\u4fdd\u5b58<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/75-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.32.17.png\" \/><\/div>\n<h2>\u6743\u9650\u9519\u8bef<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/77-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2015-12-13 2.32.39.png\" \/><\/div>\n<h1>\u6574\u7406<\/h1>\n<p>\u8bf7\u95ee\u60a8\u89c9\u5f97\u600e\u4e48\u6837\u5462\uff1f<br \/>\n\u5728\u5546\u4e1a\u9886\u57df\u4f7f\u7528ELK\uff0c\u6211\u8ba4\u4e3a\u8981\u8003\u8651\u7684\u5b89\u5168\u6027\u662f\u65e0\u6cd5\u56de\u907f\u7684\u3002<br \/>\n\u867d\u7136\u4f1a\u6709\u6536\u8d39\u7684\u63d2\u4ef6\uff0c\u4f46\u6211\u8ba4\u4e3a\u5b83\u4eec\u5177\u6709\u5f88\u5927\u7684\u4f7f\u7528\u4ef7\u503c\u3002<br \/>\n\u9664\u4e86\u6211\u4eec\u4eca\u5929\u4ecb\u7ecd\u7684&#8221;\u8ba4\u8bc1&#8221;\u548c&#8221;\u6388\u6743&#8221;\u4e4b\u5916\uff0c\u201cShield\u201d\u8fd8\u652f\u6301\u201c\u5ba1\u8ba1\u65e5\u5fd7\u8f93\u51fa\u201d\u3001\u201c\u52a0\u5bc6\u901a\u4fe1\u201d\u548c\u201cIP\u8fc7\u6ee4\u201d\u7b49\u529f\u80fd\u3002\u5982\u679c\u6709\u673a\u4f1a\uff0c\u6211\u60f3\u8bd5\u8bd5\u3002<\/p>\n<p>\u53e6\u5916\uff0c\u5982\u679c\u8fd8\u6709\u9664\u4eca\u5929\u4ecb\u7ecd\u7684\u65b9\u6cd5\u4e4b\u5916\u7684\u6700\u4f73\u5b9e\u8df5\uff0c\u8bf7\u5411\u6211\u4eec\u6307\u6559\u3002<\/p>\n<h1>\u53ea\u9700\u4e00\u4e2a\u9009\u62e9\uff0c\u5728\u4e2d\u6587\u4e2d\u89e3\u91ca\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/h1>\n<p>\u9664\u4e86\u5b98\u65b9\u7f51\u7ad9\u4e4b\u5916\u7684\u53c2\u8003\u6765\u6e90<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">http:\/\/blog.johtani.info\/blog\/2015\/02\/27\/you-know-for-security-shield-goes-ga-ja\/<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">http:\/\/dev.classmethod.jp\/cloud\/aws\/using-elasticsearch-plugin-shield\/<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">http:\/\/dev.classmethod.jp\/cloud\/aws\/twitter-visualize-using-elastic\/<\/ul>\n<div>\u4e25\u683c\u6765\u8bf4\uff0c\u9ed8\u8ba4\u8bbe\u7f6e\u4e2d\u6dfb\u52a0\u4e86indices:data\/read\/field_stats\u3002\u5728\u672c\u6587\u4e2d\u6ca1\u6709\u8be6\u7ec6\u4ecb\u7ecd\uff0c\u4f46\u662f\u5728\u8bbe\u7f6e\u4e86Shield\u4e4b\u540e\uff0c\u4e3a\u4e86\u5c06Logstash\u4e0eElasticsearch\u8fdb\u884c\u534f\u4f5c\uff0c\u9700\u8981\u8bbe\u7f6eLogstash\u7528\u6237\uff08\u901a\u8fc7esusers\u547d\u4ee4\u6dfb\u52a0logstash\u7528\u6237\uff0c\u6dfb\u52a0\u7528\u6237\u8bbe\u7f6e\u5230elasticsearch-output-plugin\uff09\u3002<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u672c\u6587\u7684\u6982\u8ff0 ELK\uff08Elasticsearch + Logstash + Kibana\uff09\u88ab\u5e7f\u6cdb\u8ba4\u53ef\u4f5c\u4e3a\u65e5\u5fd7\u6536\u96c6 [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-41030","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch\u7684\u63d2\u4ef6shield\u4f7felk\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728kibana\u4e0a\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743\" \/>\n<meta property=\"og:description\" content=\"\u672c\u6587\u7684\u6982\u8ff0 ELK\uff08Elasticsearch + Logstash + Kibana\uff09\u88ab\u5e7f\u6cdb\u8ba4\u53ef\u4f5c\u4e3a\u65e5\u5fd7\u6536\u96c6 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch\u7684\u63d2\u4ef6shield\u4f7felk\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728kibana\u4e0a\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-27T13:48:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T01:28:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/28-0.png\" \/>\n<meta name=\"author\" content=\"\u79d1, \u96c5\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u79d1, \u96c5\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/\",\"name\":\"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-10-27T13:48:32+00:00\",\"dateModified\":\"2024-04-29T01:28:05+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a\",\"name\":\"\u79d1, \u96c5\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g\",\"caption\":\"\u79d1, \u96c5\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/keya\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch\u7684\u63d2\u4ef6shield\u4f7felk\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728kibana\u4e0a\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743","og_description":"\u672c\u6587\u7684\u6982\u8ff0 ELK\uff08Elasticsearch + Logstash + Kibana\uff09\u88ab\u5e7f\u6cdb\u8ba4\u53ef\u4f5c\u4e3a\u65e5\u5fd7\u6536\u96c6 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528elasticsearch\u7684\u63d2\u4ef6shield\u4f7felk\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728kibana\u4e0a\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-10-27T13:48:32+00:00","article_modified_time":"2024-04-29T01:28:05+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d442037434c4406c9e40a\/28-0.png"}],"author":"\u79d1, \u96c5","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u79d1, \u96c5","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"3 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/","name":"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-10-27T13:48:32+00:00","dateModified":"2024-04-29T01:28:05+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u4f7fELK\u53d8\u5f97\u66f4\u52a0\u5b89\u5168\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8ba4\u8bc1\u548c\u6388\u6743"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/41e222757cdd2a3365361328bd79970a","name":"\u79d1, \u96c5","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1b2d3e00a7df03689797ebd4af8c5827ba5af936849a71050ec331f4cf902c5d?s=96&d=mm&r=g","caption":"\u79d1, \u96c5"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/keya\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e4%bd%bfelk%e5%8f%98%e5%be%97%e6%9b%b4%e5%8a%a0%e5%ae%89%e5%85%a8%ef%bc%81%e5%b0%9d%e8%af%95%e5%9c%a8kibana%e4%b8%8a\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=41030"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41030\/revisions"}],"predecessor-version":[{"id":84441,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41030\/revisions\/84441"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=41030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=41030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=41030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}