{"id":41159,"date":"2024-01-12T15:41:55","date_gmt":"2022-11-05T18:44:41","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/"},"modified":"2024-05-04T18:03:47","modified_gmt":"2024-05-04T10:03:47","slug":"%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/","title":{"rendered":"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838"},"content":{"rendered":"<h1>\u603b\u800c\u8a00\u4e4b<\/h1>\n<p>\u5927\u5bb6\u662f\u5426\u6b63\u5728\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\uff1f<br \/>\n\u76ee\u524d\uff0cElastic\u516c\u53f8\u63d0\u4f9b\u4e86\u4e00\u4e9b\u63d2\u4ef6\uff0c\u5982&#8221;Marvel&#8221;\u3001&#8221;Shield&#8221;\u548c&#8221;Watcher&#8221;\uff0c\u5728\u6b63\u5f0f\u8fd0\u8425\u65f6\u90fd\u975e\u5e38\u6709\u7528\uff0c\u53ef\u4ee5\u8bf4\u662f\u5fc5\u4e0d\u53ef\u5c11\u7684\u3002<\/p>\n<p>\u672c\u6b21\u6211\u4eec\u5c06\u5229\u7528Elasticsearch\u7684\u4ed8\u8d39\u63d2\u4ef6&#8221;Shield&#8221;\u6765\u8f93\u51faElasticsearch\u7684\u5ba1\u8ba1\u65e5\u5fd7\uff0c\u5e76\u4f7f\u7528&#8221;Watcher&#8221;\u4ece\u5ba1\u8ba1\u65e5\u5fd7\u4e2d\u68c0\u6d4b\u5230\u6076\u610f\u8bbf\u95ee\u5e76\u89e6\u53d1\u8b66\u62a5\uff08\u53d1\u9001\u90ae\u4ef6\uff09\u3002<\/p>\n<h1>\u4e00\u5f00\u59cb<\/h1>\n<h2>\u76fe\u662f\u4ec0\u4e48\u610f\u601d<\/h2>\n<p>\u8fd9\u662f\u4e00\u4e2a\u94fe\u63a5\uff1ahttps:\/\/www.elastic.co\/products\/shield<br \/>\n\u5b83\u662fElasticsearch\u7684\u5b89\u5168\u63d2\u4ef6\u3002<br \/>\n\u901a\u8fc7\u4f7f\u7528Shield\uff0c\u60a8\u53ef\u4ee5\u5bf9Elasticsearch\u7684\u8bbf\u95ee\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u548c\u6388\u6743\uff0c<br \/>\n\u8fd8\u53ef\u4ee5\u8bbe\u7f6eIP\u8fc7\u6ee4\u548c\u5ba1\u8ba1\u65e5\u5fd7\u8f93\u51fa\u7b49\u529f\u80fd\u3002<\/p>\n<h2>\u89c2\u5bdf\u8005\u6307\u7684\u662f<\/h2>\n<p>\u516c\u5f0f\u7f51\u5740\uff1ahttps:\/\/www.elastic.co\/products\/watcher<br \/>\nWatcher\u662fElasticsearch\u7684\u68c0\u6d4b\u8b66\u62a5\u63d2\u4ef6\u3002<br \/>\n\u901a\u8fc7\u4f7f\u7528Watcher\uff0c\u53ef\u4ee5\u4ece\u6ce8\u518c\u5728\u7d22\u5f15\u4e2d\u7684\u6570\u636e\u4e2d\u68c0\u6d4b\u7279\u5b9a\u7684\u5173\u952e\u8bcd\uff0c\u5e76\u6267\u884c\u8bf8\u5982\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\u7b49\u7684\u64cd\u4f5c\u3002<\/p>\n<h2>\u5728\u9605\u8bfb\u672c\u6587\u4e4b\u524d<\/h2>\n<p>\u5982\u679c\u60a8\u60f3\u8981\u4e86\u89e3\u6709\u5173Shield\u8ba4\u8bc1\u548c\u6388\u6743\u7b49\u65b9\u9762\u7684\u8be6\u7ec6\u4fe1\u606f\uff0c\u8bf7\u53c2\u8003\u6211\u4e4b\u524d\u53d1\u5e03\u7684\u8fd9\u7bc7\u6587\u7ae0\u3002<\/p>\n<p>\u4f7f\u7528Elasticsearch\u63d2\u4ef6&#8221;Shield&#8221;\u6765\u786e\u4fddELK\u7684\u5b89\u5168\u6027\uff01\u5c1d\u8bd5\u5728Kibana\u4e0a\u5b9e\u73b0\u8eab\u4efd\u9a8c\u8bc1\u548c\u6388\u6743\u3002<\/p>\n<h1>\u73af\u5883\u4fe1\u606f<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">OS\uff1aCentOS6.5 on VirtualBox + Vagrant<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Logstash 2.1.1<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Elasticsearch 2.1.0<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Kibana 4.3.0<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">Java 1.8.65<\/ul>\n<h1>\u5ba1\u8ba1\u8bc1\u636e\u8f93\u51fa<\/h1>\n<h2>\u4f7f\u7528\u906e\u7f69\u5c4f\u5e55\u5b89\u88c51<\/h2>\n<pre class=\"post-pre\"><code>\/usr\/share\/elasticsearch\/bin\/plugin <span class=\"nb\">install <\/span>elasticsearch\/shield\/latest\r\n<\/code><\/pre>\n<h2>\u9700\u8981\u8a2d\u5b9a\u8f38\u51fa\u529f\u7387\u7684\u554f\u984c\u3002<\/h2>\n<p>\u7531\u4e8e\u9ed8\u8ba4\u60c5\u51b5\u4e0b\u5ba1\u8ba1\u8bc1\u636e\u65e5\u5fd7\u7684\u8f93\u51fa\u662f\u65e0\u6548\u7684\uff0c\u56e0\u6b64\u5728elasticsearch.yml\u4e2d\u6dfb\u52a0\u4ee5\u4e0b\u5185\u5bb9\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">shield.audit.enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n<\/code><\/pre>\n<h2>\u8bbe\u5b9a\u8f93\u51fa\u76ee\u6807<\/h2>\n<p>\u76d1\u5ba1\u8bc1\u636e\u65e5\u5fd7\u53ef\u9009\u62e9&#8221;\u6587\u4ef6\u8f93\u51fa&#8221;\u548c&#8221;\u5bfc\u5165\u5230Elasticsearch\u7d22\u5f15&#8221;\u3002\u53ef\u4ee5\u5728`shield.audit.outputs`\u4e2d\u8fdb\u884c\u6307\u5b9a\u3002\u672c\u6b21\u9009\u62e9\u4e86\u540c\u65f6\u6307\u5b9a\u4e24\u79cd\u8f93\u51fa\u65b9\u5f0f\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">shield.audit.outputs<\/span><span class=\"pi\">:<\/span> <span class=\"pi\">[<\/span><span class=\"nv\">index<\/span><span class=\"pi\">,<\/span> <span class=\"nv\">logfile<\/span><span class=\"pi\">]<\/span>\r\n<\/code><\/pre>\n<h2>\u786e\u8ba4\u4ea7\u51fa<\/h2>\n<p>\u5b8c\u6210\u8a2d\u5b9a\u540e\uff0c\u91cd\u65b0\u542f\u52a8Elasticsearch\u5e76\u786e\u8ba4\u5ba1\u6838\u8ddf\u8e2a\u65e5\u5fd7\u7684\u8f93\u51fa\u3002<br \/>\n\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6587\u4ef6\u5c06\u8f93\u51fa\u5230\/var\/log\/elasticsearch\/elasticsearch-access.log\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code>[2015-12-19 04:04:36,480] [Taskmaster] [transport] [access_granted]     origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk]\r\n[2015-12-19 04:04:36,480] [Taskmaster] [transport] [access_granted]     origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk[s]], indices=[.shield_audit_log-2015.12.19]\r\n[2015-12-19 04:04:36,515] [Taskmaster] [transport] [access_granted]     origin_type=[rest], origin_address=[127.0.0.1], principal=[kibana4_server], action=[cluster:monitor\/nodes\/info]\r\n[2015-12-19 04:04:36,515] [Taskmaster] [transport] [access_granted]     origin_type=[rest], origin_address=[127.0.0.1], principal=[kibana4_server], action=[cluster:monitor\/nodes\/info[n]]\r\n[2015-12-19 04:04:36,526] [Taskmaster] [transport] [access_granted]     origin_type=[rest], origin_address=[127.0.0.1], principal=[kibana4_server], action=[cluster:monitor\/health], indices=[.kibana]\r\n<\/code><\/pre>\n<p>\u4eceKibana\u4e2d\u67e5\u770b\u5230Elasticsearch\u7684\u5bfc\u5165\u60c5\u51b5\uff0c\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d453e37434c4406ca1e77\/26-0.png\" alt=\"capture.PNG\" \/><\/div>\n<h2>\u65e5\u5fd7\u6761\u76ee\u7c7b\u578b<\/h2>\n<p>\u53ea\u6709\u5728\u53d1\u751f\u4ee5\u4e0b\u7c7b\u578b\u7684\u4e8b\u4ef6\u65f6\uff0c\u624d\u4f1a\u751f\u6210\u5ba1\u8ba1\u8bc1\u8ff9\u65e5\u5fd7\u3002<\/p>\n<div>\n<div class=\"post-table\">\u7a2e\u5225\u8aac\u660eanonymous_access_denied\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u304c\u4ed8\u52a0\u3055\u308c\u3066\u3044\u306a\u3044\u3053\u3068\u306b\u3088\u308a\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u62d2\u5426\u3055\u308c\u305f\u5834\u5408authentication_failed\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u304c\u30de\u30c3\u30c1\u3057\u306a\u3044\u3053\u3068\u306b\u3088\u308a\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u62d2\u5426\u3055\u308c\u305f\u5834\u5408authentication_failed[&lt;realm&gt;]\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u304c\u30de\u30c3\u30c1\u3057\u306a\u3044\u3053\u3068\u306b\u3088\u308a\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u62d2\u5426\u3055\u308c\u305f\u5834\u5408 \uff08\u30ec\u30eb\u30e0\u3054\u3068\u306b\u51fa\u529b\uff09access_granted\u30ed\u30fc\u30eb\u3068\u3057\u3066\u8a31\u53ef\u3055\u308c\u3066\u3044\u308b\u64cd\u4f5c\u3092\u884c\u3063\u305f\u5834\u5408\uff08\u6b63\u5e38\u7cfb\uff09access_denied\u30ed\u30fc\u30eb\u3068\u3057\u3066\u8a31\u53ef\u3055\u308c\u3066\u3044\u306a\u3044\u64cd\u4f5c\u3092\u884c\u3063\u305f\u3053\u3068\u306b\u3088\u308a\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u62d2\u5426\u3055\u308c\u305f\u5834\u5408tampered_request\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u6539\u3056\u3093\u3055\u308c\u305f\u5834\u5408 \uff08typically relates tosearch\/scroll requests when the scroll id is believed to be tampered\uff09connection_grantedIP\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u306b\u3088\u308aTCP\u30b3\u30cd\u30af\u30b7\u30e7\u30f3\u304c\u8a31\u53ef\u3055\u308c\u305f\u5834\u5408\uff08\u6b63\u5e38\u7cfb\uff09connection_deniedIP\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u306b\u3088\u308aTCP\u30b3\u30cd\u30af\u30b7\u30e7\u30f3\u304c\u7834\u68c4\u3055\u308c\u305f\u5834\u5408<\/div>\n<\/div>\n<h2>\u5173\u4e8e\u65e5\u5fd7\u683c\u5f0f\u7684\u95ee\u9898<\/h2>\n<p>\u6211\u5c06\u7b80\u5355\u8bf4\u660e\u4e00\u4e0b\u65e5\u5fd7\u7684\u683c\u5f0f\u3002<\/p>\n<p>[&lt;\u65f6\u95f4\u6233&gt;] [&lt;\u672c\u5730\u8282\u70b9\u4fe1\u606f&gt;] [&lt;\u5c42\u7ea7&gt;] [&lt;\u6761\u76ee\u7c7b\u578b&gt;] &lt;\u5c5e\u6027\u5217\u8868&gt;<\/p>\n<p>* &lt;\u65f6\u95f4\u6233&gt;\u2026\u8bb0\u5f55\u65f6\u95f4\u6233<br \/>\n* &lt;\u672c\u5730\u8282\u70b9\u4fe1\u606f&gt;\u2026\u8f93\u51fa\u65e5\u5fd7\u7684\u8282\u70b9\u4fe1\u606f<br \/>\n* &lt;\u5c42\u7ea7&gt;\u2026\u4e0e\u65e5\u5fd7\u6761\u76ee\u76f8\u5173\u7684\u5c42\u7ea7\uff08\u53ef\u4e3arest\u3001transport\u3001ip_filter\u4e4b\u4e00\uff09<br \/>\n* &lt;\u6761\u76ee\u7c7b\u578b&gt;\u2026\u6761\u76ee\u7c7b\u578b\uff08\u53c2\u89c1\u4e0a\u8ff0\u8bf4\u660e\uff09<br \/>\n* &lt;\u5c5e\u6027\u5217\u8868&gt;\u2026\u4e0e\u4e8b\u4ef6\u76f8\u5173\u7684\u5c5e\u6027\u4fe1\u606f<\/p>\n<h1>\u5f02\u5e38\u8bbf\u95ee\u68c0\u6d4b\u548c\u8b66\u62a5<\/h1>\n<p>\u4e0b\u4e00\u6b65\uff0c\u4f7f\u7528Watcher\u6765\u68c0\u6d4b\u548c\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\u901a\u77e5\u6709\u5173\u975e\u6cd5\u8bbf\u95ee\u7684\u4fe1\u606f\u3002<br \/>\n\u672c\u6b21\u5c06\u5b9a\u4e49\u201c\u975e\u6cd5\u8bbf\u95ee\u201d\u4e3a\u201c\u5f53\u65e5\u5fd7\u7c7b\u578b\u4e3aanonymous_access_denied\u7684\u65e5\u5fd7\u88ab\u8f93\u51fa\u5230\u5ba1\u8ba1\u65e5\u5fd7\u65f6\u201d\u3002<br \/>\nanonymous_access_denied\u6307\u7684\u662f\u201c\u7531\u4e8e\u8bf7\u6c42\u88ab\u62d2\u7edd\u800c\u8f93\u51fa\u7684\u65e5\u5fd7\uff0c\u539f\u56e0\u662f\u672a\u9644\u52a0\u8ba4\u8bc1\u4ee4\u724c\u201d\u3002<\/p>\n<h2>\u89c2\u5bdf\u8005\u5b89\u88c51<\/h2>\n<pre class=\"post-pre\"><code>\/usr\/share\/elasticsearch\/bin\/plugin <span class=\"nb\">install <\/span>elasticsearch\/watcher\/latest\r\n<\/code><\/pre>\n<p>\u8bf7\u91cd\u65b0\u542f\u52a8Elasticsearch\uff0c\u5e76\u786e\u8ba4Watcher\u5df2\u7ecf\u542f\u52a8\u3002<br \/>\n\u5982\u679cwarcher_state\u4e3astarted\uff0c\u90a3\u5c31OK\u4e86\u3002<br \/>\n\u7531\u4e8e\u5df2\u7ecf\u5b89\u88c5\u4e86shield\uff0c\u6240\u4ee5\u8bf7\u6307\u5b9a\u7528\u6237\u540d\u548c\u5bc6\u7801\u8fdb\u884cGET\u8bf7\u6c42\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-XGET<\/span> <span class=\"nt\">-u<\/span> admin <span class=\"s1\">'http:\/\/localhost:9200\/_watcher\/stats?pretty'<\/span>\r\nEnter host password <span class=\"k\">for <\/span>user <span class=\"s1\">'admin'<\/span>:\r\n<span class=\"o\">{<\/span>\r\n  <span class=\"s2\">\"watcher_state\"<\/span> : <span class=\"s2\">\"started\"<\/span>,\r\n  <span class=\"s2\">\"watch_count\"<\/span> : 0,\r\n  <span class=\"s2\">\"execution_thread_pool\"<\/span> : <span class=\"o\">{<\/span>\r\n    <span class=\"s2\">\"queue_size\"<\/span> : 0,\r\n    <span class=\"s2\">\"max_size\"<\/span> : 0\r\n  <span class=\"o\">}<\/span>,\r\n  <span class=\"s2\">\"manually_stopped\"<\/span> : <span class=\"nb\">false<\/span>\r\n<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<h2>\u89c2\u770b\u7684\u5b9a\u4e49<\/h2>\n<p>\u901a\u8fc7\u53d1\u9001POST\u8bf7\u6c42\u5e76\u6dfb\u52a0Watcher\u7d22\u5f15\u6765\u6dfb\u52a0Watch\u5b9a\u4e49\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-XPUT<\/span> <span class=\"nt\">-u<\/span> admin <span class=\"s1\">'http:\/\/localhost:9200\/_watcher\/watch\/log_error_watch'<\/span> <span class=\"nt\">-d<\/span> <span class=\"s1\">'{\r\n  \"trigger\" : {\r\n    \"schedule\" : {\r\n      \"interval\" : \"10s\"\r\n    }\r\n  }\r\n, \"input\" : {\r\n    \"search\" : {\r\n      \"request\" : {\r\n        \"indices\" : [ \".shield_audit_log-*\" ]\r\n      , \"body\" : {\r\n          \"query\" : { \r\n            \"bool\" : { \r\n              \"must\" : [\r\n                { \"match\": { \"event_type\" : \"anonymous_access_denied\"}}\r\n              ]\r\n            , \"filter\" : [ \r\n                { \"range\": { \"@timestamp\" : { \"gte\": \"{{ctx.trigger.scheduled_time}}||-10s\" }}}\r\n              ]\r\n            }\r\n          }\r\n        }\r\n      }\r\n    }\r\n  }\r\n, \"condition\" : {\r\n    \"compare\" : {\r\n      \"ctx.payload.hits.total\" : { \r\n        \"gt\" : 0\r\n      }\r\n    }\r\n  }\r\n, \"actions\" : {\r\n    \"email_admin\" : { \r\n      \"email\": {\r\n        \"to\" : \"&lt;Your Mail Address&gt;\"\r\n      , \"subject\" : \"\u3010ERROR\u3011Elasticsearch\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\uff08{{ctx.payload.hits.total}}\u4ef6\uff09\"\r\n      , \"body\" : {\r\n          \"text\" : \"{{ctx.payload.hits.hits}}\" \r\n        }\r\n      }\r\n    }\r\n  }\r\n}'<\/span>\r\n<\/code><\/pre>\n<p>\u4ee5\u4e0a\u7684\u5b9a\u4e49\u662f\u5728\u6bcf10\u79d2\u949f\u7684\u95f4\u9694\u5185\u641c\u7d22\u5df2\u6ce8\u518c\u7684Elasticsearch\u5ba1\u8ba1\u65e5\u5fd7\u7d22\u5f15\uff0c\u5e76\u5728\u68c0\u6d4b\u5230\u975e\u6cd5\u8bbf\u95ee\u65e5\u5fd7\u65f6\u901a\u8fc7\u7535\u5b50\u90ae\u4ef6\u8fdb\u884c\u901a\u77e5\u3002<\/p>\n<p>\u8ba9\u6211\u4eec\u6309\u7167\u987a\u5e8f\u6765\u770b\u4e0b\u53bb\u5427\u3002<br \/>\nWatch\u7684\u5b9a\u4e49\u53ef\u4ee5\u5927\u81f4\u5206\u4e3a\u56db\u4e2a\u90e8\u5206\uff0c\u5373trigger\uff08\u89e6\u53d1\u5668\uff09\u3001input\uff08\u8f93\u5165\uff09\u3001condition\uff08\u6761\u4ef6\uff09\u548cactions\uff08\u52a8\u4f5c\uff09\u3002<\/p>\n<h3>\u89e6\u53d1 (ch\u016b f\u0101)<\/h3>\n<p>\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u4f7f\u7528\u8ba1\u5212\u89e6\u53d1\u5668\u4ee510\u79d2\u7684\u95f4\u9694\u542f\u52a8\u76d1\u89c6\u5668\u6765\u5b9a\u4e49\u89e6\u53d1\u5668\u3002<\/p>\n<pre class=\"post-pre\"><code>  <span class=\"dl\">\"<\/span><span class=\"s2\">trigger<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"dl\">\"<\/span><span class=\"s2\">schedule<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"dl\">\"<\/span><span class=\"s2\">interval<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">10s<\/span><span class=\"dl\">\"<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>\u8bf7\u53c2\u8003\u4ee5\u4e0b\u94fe\u63a5\uff1ahttps:\/\/www.elastic.co\/guide\/en\/watcher\/current\/trigger.html<\/p>\n<h3>\u8bf7\u7ed9\u6211\u4e00\u4e2a\u4e2d\u6587\u7684\u7ffb\u8bd1\u9009\u9879:<br \/>\n\u8f93\u5165<\/h3>\n<p>\u8f93\u5165\u5b9a\u4e49\u4e86Watcher\u7684\u5ba1\u8ba1\u76ee\u6807\u3002<br \/>\n\u8fd9\u91cc\u4ece.shield_audit_log\u7d22\u5f15\u4e2d\u6ce8\u518c\u7684\u6587\u6863\u4e2d\u63d0\u53d6event_type\u5b57\u6bb5\u4e3aanonymous_access_denied\u7684\u5185\u5bb9\u3002<\/p>\n<p>\u901a\u8fc7\u7b5b\u9009\u65f6\u95f4\u6233\u5927\u4e8e\u300cWatcher\u542f\u52a8\u88ab\u8c03\u5ea6\u7684\u65f6\u95f4 &#8211; 10\u79d2\u300d\u7684\u65e5\u5fd7\uff0c\u4ee5\u907f\u514d\u5bf9\u5df2\u7ecf\u68c0\u6d4b\u8fc7\u7684\u65e5\u5fd7\u8fdb\u884c\u91cd\u590d\u68c0\u6d4b\u3002<\/p>\n<pre class=\"post-pre\"><code>  <span class=\"dl\">\"<\/span><span class=\"s2\">input<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"dl\">\"<\/span><span class=\"s2\">search<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"dl\">\"<\/span><span class=\"s2\">request<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n        <span class=\"dl\">\"<\/span><span class=\"s2\">indices<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">[<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">.shield_audit_log-*<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">]<\/span>\r\n      <span class=\"p\">,<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">body<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n          <span class=\"dl\">\"<\/span><span class=\"s2\">query<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span> \r\n            <span class=\"dl\">\"<\/span><span class=\"s2\">bool<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span> \r\n              <span class=\"dl\">\"<\/span><span class=\"s2\">must<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">[<\/span>\r\n                <span class=\"p\">{<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">match<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"p\">{<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">event_type<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">anonymous_access_denied<\/span><span class=\"dl\">\"<\/span><span class=\"p\">}}<\/span>\r\n              <span class=\"p\">]<\/span>\r\n            <span class=\"p\">,<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">filter<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">[<\/span> \r\n                <span class=\"p\">{<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">range<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"p\">{<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">@timestamp<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">gte<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">{{ctx.trigger.scheduled_time}}||-10s<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">}}}<\/span>\r\n              <span class=\"p\">]<\/span>\r\n            <span class=\"p\">}<\/span>\r\n          <span class=\"p\">}<\/span>\r\n        <span class=\"p\">}<\/span>\r\n      <span class=\"p\">}<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>\u8bf7\u53c2\u8003\u4ee5\u4e0b\u94fe\u63a5\u83b7\u53d6\u66f4\u591a\u4fe1\u606f\uff1ahttps:\/\/www.elastic.co\/guide\/en\/watcher\/current\/input.html<\/p>\n<h3>\u72b6\u6001<\/h3>\n<p>\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5b9a\u4e49\u4e86\u53ea\u6709\u5f53\u8f93\u5165\u7684\u9879\u76ee\u6570\u5927\u4e8e\u6216\u7b49\u4e8e0\u65f6\u624d\u6267\u884c\u64cd\u4f5c\u7684\u6761\u4ef6\u3002<\/p>\n<pre class=\"post-pre\"><code>  <span class=\"dl\">\"<\/span><span class=\"s2\">condition<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"dl\">\"<\/span><span class=\"s2\">compare<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n      <span class=\"dl\">\"<\/span><span class=\"s2\">ctx.payload.hits.total<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span> \r\n        <span class=\"dl\">\"<\/span><span class=\"s2\">gt<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"mi\">0<\/span>\r\n      <span class=\"p\">}<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>\u8bf7\u67e5\u9605\uff1ahttps:\/\/www.elastic.co\/guide\/en\/watcher\/current\/condition.html<\/p>\n<h3>\u884c\u52a8<\/h3>\n<p>\u5f53\u68c0\u6d4b\u5230watch\u5bf9\u8c61\u65f6\uff0c\u5b9a\u4e49\u76f8\u5e94\u7684\u64cd\u4f5c\u3002<br \/>\n\u64cd\u4f5c\u53ef\u4ee5\u5305\u62ec\u53d1\u9001\u90ae\u4ef6\u3001\u4e0eSlack\u96c6\u6210\u3001\u4e0eHipchat\u96c6\u6210\u3001\u8f93\u51fa\u65e5\u5fd7\u7b49\u591a\u79cd\u65b9\u5f0f\uff0c<br \/>\n\u4f46\u5728\u6b64\u5904\u6211\u4eec\u9009\u62e9\u53d1\u9001\u90ae\u4ef6\u64cd\u4f5c\u3002<\/p>\n<pre class=\"post-pre\"><code>  <span class=\"dl\">\"<\/span><span class=\"s2\">actions<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n    <span class=\"dl\">\"<\/span><span class=\"s2\">email_admin<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span> \r\n      <span class=\"dl\">\"<\/span><span class=\"s2\">email<\/span><span class=\"dl\">\"<\/span><span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n        <span class=\"dl\">\"<\/span><span class=\"s2\">to<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">&lt;Your Mail Address&gt;<\/span><span class=\"dl\">\"<\/span>\r\n      <span class=\"p\">,<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">subject<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">\u3010ERROR\u3011Elasticsearch\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\uff08{{ctx.payload.hits.total}}\u4ef6\uff09<\/span><span class=\"dl\">\"<\/span>\r\n      <span class=\"p\">,<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">body<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"p\">{<\/span>\r\n          <span class=\"dl\">\"<\/span><span class=\"s2\">text<\/span><span class=\"dl\">\"<\/span> <span class=\"p\">:<\/span> <span class=\"dl\">\"<\/span><span class=\"s2\">{{ctx.payload.hits.hits}}<\/span><span class=\"dl\">\"<\/span> \r\n        <span class=\"p\">}<\/span>\r\n      <span class=\"p\">}<\/span>\r\n    <span class=\"p\">}<\/span>\r\n  <span class=\"p\">}<\/span>\r\n<\/code><\/pre>\n<p>\u53c2\u8003\uff1ahttps:\/\/www.elastic.co\/guide\/en\/watcher\/current\/actions.html<\/p>\n<p>\u8bf7\u67e5\u770b\u4ee5\u4e0b\u94fe\u63a5\uff0c\u83b7\u53d6\u66f4\u591a\u5173\u4e8e\u64cd\u4f5c\u7684\u8be6\u7ec6\u4fe1\u606f\u3002<\/p>\n<p>\u9700\u8981\u5728elasticsearch.yml\u4e2d\u8bbe\u7f6e\u90ae\u4ef6\u5e10\u6237\u624d\u80fd\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\u3002<br \/>\n\u672c\u6b21\u5c06\u4f7f\u7528GMail\u7684SMTP\u670d\u52a1\u5668\u3002\u4e09\u5341\u4e8c<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">watcher.actions.email.service.account<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">gmail_account<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">profile<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gmail<\/span>\r\n        <span class=\"na\">smtp<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">auth<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n            <span class=\"s\">starttls.enable<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n            <span class=\"na\">host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">smtp.gmail.com<\/span>\r\n            <span class=\"na\">port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">587<\/span>\r\n            <span class=\"na\">user<\/span><span class=\"pi\">:<\/span> <span class=\"s\">&lt;Google Account&gt;<\/span>\r\n            <span class=\"na\">password<\/span><span class=\"pi\">:<\/span> <span class=\"s\">&lt;Google Password&gt;<\/span>\r\n<\/code><\/pre>\n<p>\u53c2\u8003\uff1ahttps:\/\/www.elastic.co\/guide\/en\/watcher\/current\/email-services.html#gmail<\/p>\n<h2>\u786e\u8ba4<\/h2>\n<p>\u5b8c\u6210\u6b64\u6b65\u9aa4\u540e\uff0c\u8bf7\u91cd\u65b0\u542f\u52a8Elasticsearch\uff0c\u4ee5\u9a8c\u8bc1\u5ba1\u8ba1\u8ffd\u8e2a\u65e5\u5fd7\u7684\u68c0\u6d4b\u548c\u90ae\u4ef6\u53d1\u9001\u3002<\/p>\n<h3>\u975e\u6cd5\u8bbf\u95ee<\/h3>\n<p>\u6ca1\u6709\u8ba4\u8bc1\u4ee4\u724c\uff0c\u65e0\u6cd5\u8c03\u7528Elasticsearch\u7684API\u3002\u4f1a\u51fa\u73b0\u8ba4\u8bc1\u9519\u8bef\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-XGET<\/span> <span class=\"s1\">'http:\/\/localhost:9200'<\/span>\r\n<span class=\"o\">{<\/span><span class=\"s2\">\"error\"<\/span>:<span class=\"o\">{<\/span><span class=\"s2\">\"root_cause\"<\/span>:[<span class=\"o\">{<\/span><span class=\"s2\">\"type\"<\/span>:<span class=\"s2\">\"security_exception\"<\/span>,<span class=\"s2\">\"reason\"<\/span>:<span class=\"s2\">\"missing authentication token for REST request [\/]\"<\/span>,<span class=\"s2\">\"header\"<\/span>:<span class=\"o\">{<\/span><span class=\"s2\">\"WWW-Authenticate\"<\/span>:<span class=\"s2\">\"Basic realm=<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">shield<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">\"<\/span><span class=\"o\">}}]<\/span>,<span class=\"s2\">\"type\"<\/span>:<span class=\"s2\">\"security_exception\"<\/span>,<span class=\"s2\">\"reason\"<\/span>:<span class=\"s2\">\"missing authentication token for REST request [\/]\"<\/span>,<span class=\"s2\">\"header\"<\/span>:<span class=\"o\">{<\/span><span class=\"s2\">\"WWW-Authenticate\"<\/span>:<span class=\"s2\">\"Basic realm=<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">shield<\/span><span class=\"se\">\\\"<\/span><span class=\"s2\">\"<\/span><span class=\"o\">}}<\/span>,<span class=\"s2\">\"status\"<\/span>:401<span class=\"o\">}<\/span>\r\n<\/code><\/pre>\n<p>\u76d1\u5ba1\u8bc1\u636e\u65e5\u5fd7\u786e\u5b9e\u8f93\u51fa\u5230Elasticsearch\u7684.shield_audit_log\u7d22\u5f15\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code>[2015-12-20 22:56:50,628] [Plug] [rest] [anonymous_access_denied]       origin_address=[::1], uri=[\/]\r\n<\/code><\/pre>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d453e37434c4406ca1e77\/70-0.png\" alt=\"Alert.PNG\" \/><\/div>\n<h3>\u7535\u5b50\u90ae\u4ef6\u901a\u77e5<\/h3>\n<p>\u5f53\u6211\u67e5\u770bGmail\u65f6\uff0c\u786e\u5b9e\u6536\u5230\u4e86\u8b66\u62a5\u90ae\u4ef6\u3002\u975e\u5e38\u597d\uff0c\u4e00\u5207\u90fd\u5f88\u987a\u5229\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d453e37434c4406ca1e77\/73-0.png\" alt=\"Mail.PNG\" \/><\/div>\n<h2>\u89c0\u770b\u5b9a\u7fa9\u522a\u9664\u3002<\/h2>\n<p>\u5c06\u4e0d\u518d\u9700\u8981\u7684Watch\u5b9a\u4e49\u6309\u5982\u4e0b\u65b9\u5f0f\u5220\u9664\u3002<\/p>\n<pre class=\"post-pre\"><code>curl <span class=\"nt\">-XDELETE<\/span> <span class=\"nt\">-u<\/span> admin <span class=\"s1\">'http:\/\/localhost:9200\/_watcher\/watch\/log_error_watch'<\/span>\r\n<\/code><\/pre>\n<h1>\u603b\u7ed3<\/h1>\n<p>\u4f60\u89c9\u5f97\u5982\u4f55\u5462\uff1f\u7ee7\u524d\u4e00\u7bc7\u6587\u7ae0\u4e4b\u540e\uff0c\u6211\u8bd5\u7740\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\u6765\u63d0\u5347\u5b89\u5168\u6027\u3002\u5982\u679cWatcher\u7684\u5b9a\u4e49\u53ef\u4ee5\u5728Kibana\u4e0a\u901a\u8fc7\u56fe\u5f62\u754c\u9762\u8fdb\u884c\uff0c\u90a3\u5c31\u592a\u597d\u4e86\u3002\u5982\u679c\u6709\u673a\u4f1a\u7684\u8bdd\uff0c\u6211\u8fd8\u60f3\u5c1d\u8bd5\u4e0eSlack\u548cHipchat\u8fdb\u884c\u6574\u5408\u3002<\/p>\n<p>\u7531\u4e8e\u9519\u8fc7\u4e86Elasticsearch\u7684Advent Calender\u6d3b\u52a8\u7684\u7b2c\u4e00\u5929\uff0c\u771f\u7684\u62b1\u6b49m(_ _)m<\/p>\n<h1>\u5982\u679c\u60a8\u6709\u76f8\u5173\u77e5\u8bc6\u6216\u7ecf\u9a8c\u7684\u8bdd<\/h1>\n<p>\u5982\u679c\u5c06Shield\u7684\u5ba1\u8ba1\u75d5\u8ff9\u65e5\u5fd7\u8f93\u51fa\u8bbe\u7f6e\u4e3a\u201c\u542f\u7528\u201d\uff0c\u5e76\u5c06\u8f93\u51fa\u76ee\u6807\u6307\u5b9a\u4e3a\u201c\u5bfc\u5165\u5230Elasticsearch\u7d22\u5f15\u201d\uff0c\u7136\u540e\u542f\u52a8Kibana\uff0c\u5c06\u4f1a\u5bfc\u81f4\u5ba1\u8ba1\u75d5\u8ff9\u65e5\u5fd7\u7684\u7d22\u5f15\u5bfc\u5165\u8fdb\u5165\u65e0\u9650\u5faa\u73af\u3002<br \/>\n\u884c\u4e3a\u662f\u8fd9\u6837\u7684\uff0cKibana\u5c06\u8bfb\u53d6\u7d22\u5f15\u7684\u64cd\u4f5c\u4f5c\u4e3a\u5ba1\u8ba1\u65e5\u5fd7\u5bfc\u5165\u5230\u7d22\u5f15\u4e2d\uff0c\u7136\u540eKibana\u53c8\u4f1a\u8fdb\u4e00\u6b65\u8bfb\u53d6\u8be5\u7d22\u5f15&#8230;\u5faa\u73af\u5f80\u590d\u3002<br \/>\n\u4e5f\u8bb8\u5c06\u5ba1\u8ba1\u75d5\u8ff9\u65e5\u5fd7\u7684\u8f93\u51fa\u7ea7\u522b\u8bbe\u7f6e\u4e3aERROR\u7b49\u53ef\u4ee5\u89e3\u51b3\u95ee\u9898\uff0c\u4f46\u5982\u679c\u6709\u4efb\u4f55\u89c1\u89e3\uff0c\u8bf7\u4e0d\u541d\u8d50\u6559\u3002<\/p>\n<pre class=\"post-pre\"><code>[2015-12-20 23:16:39,379] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk[s]], indices=[.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,222] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/write\/index], indices=[.triggered_watches]\r\n[2015-12-20 23:16:49,277] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,277] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,279] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,281] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,285] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,287] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,293] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,295] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,297] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,298] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,300] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,302] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/read\/search[phase\/query]], indices=[.shield_audit_log-2015.12.19,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,305] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/write\/index], indices=[.watch_history-2015.12.20]\r\n[2015-12-20 23:16:49,344] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__watcher_user], action=[indices:data\/write\/delete], indices=[.triggered_watches]\r\n[2015-12-20 23:16:49,395] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk]\r\n[2015-12-20 23:16:49,397] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk[s]], indices=[.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,397] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk[s]], indices=[.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20]\r\n[2015-12-20 23:16:49,398] [Plug] [transport] [access_granted]   origin_type=[local_node], origin_address=[127.0.0.1], principal=[__indexing_audit_user], action=[indices:data\/write\/bulk[s]], indices=[.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20,.shield_audit_log-2015.12.20]\r\n<\/code><\/pre>\n<h1>\u53ea\u63d0\u4f9b\u5176\u4ed6\u53c2\u8003\u6765\u6e90\uff0c\u4e0d\u5305\u62ec\u5b98\u65b9\u7f51\u7ad9\u3002<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">http:\/\/dev.classmethod.jp\/cloud\/aws\/using-elasticsearch-plugin-shield\/<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">http:\/\/dev.classmethod.jp\/cloud\/aws\/using-elasticsearch-plugin-watcher\/<\/ul>\n<div>\n<p>\u5728\u5b89\u88c5\u4efb\u4f55\u63d2\u4ef6\u4e4b\u524d\uff0c\u5fc5\u987b\u5148\u5b89\u88c5\u8bb8\u53ef\u8bc1\/license\uff0c\u65b9\u6cd5\u662f\u6267\u884c\/usr\/share\/elasticsearch\/bin\/plugin install elasticsearch\/license\/latest\u3002<\/p>\n<p>\u5728Gmail\u7684\u8bbe\u7f6e\u4e2d\uff0c\u9700\u8981\u5c06\u201c\u8bbf\u95ee\u4f4e\u5b89\u5168\u6027\u5e94\u7528\u7a0b\u5e8f\u201d\u8bbe\u4e3a\u201c\u542f\u7528\u201d\u3002<\/p>\n<p>\u7531\u4e8e\u5c1d\u8bd5\u4eceWatcher\u53d1\u9001\u7535\u5b50\u90ae\u4ef6\u65f6\u51fa\u73b0\u4e86UnsupportedDataTypeException\u9519\u8bef\uff0c\u6211\u4eec\u6b63\u5728\u6267\u884c\u6b64\u6587\u7ae0\u4e2d\u63d0\u5230\u7684\u89e3\u51b3\u65b9\u6cd5\u3002\u662f\u5426\u662f\u4e2a\u95ee\u9898\uff1f<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u603b\u800c\u8a00\u4e4b \u5927\u5bb6\u662f\u5426\u6b63\u5728\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\uff1f \u76ee\u524d\uff0cElastic\u516c\u53f8\u63d0\u4f9b\u4e86\u4e00\u4e9b\u63d2\u4ef6\uff0c\u5982&#038;#8 [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-41159","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u901a\u8fc7elasticsearch\u7684\u63d2\u4ef6shield\u548cwatcher\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838\" \/>\n<meta property=\"og:description\" content=\"\u603b\u800c\u8a00\u4e4b \u5927\u5bb6\u662f\u5426\u6b63\u5728\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\uff1f \u76ee\u524d\uff0cElastic\u516c\u53f8\u63d0\u4f9b\u4e86\u4e00\u4e9b\u63d2\u4ef6\uff0c\u5982&amp;#8 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u901a\u8fc7elasticsearch\u7684\u63d2\u4ef6shield\u548cwatcher\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-05T18:44:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-04T10:03:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d453e37434c4406ca1e77\/26-0.png\" \/>\n<meta name=\"author\" content=\"\u97f5, \u79d1\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u97f5, \u79d1\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/\",\"name\":\"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2022-11-05T18:44:41+00:00\",\"dateModified\":\"2024-05-04T10:03:47+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e\",\"name\":\"\u97f5, \u79d1\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g\",\"caption\":\"\u97f5, \u79d1\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u901a\u8fc7elasticsearch\u7684\u63d2\u4ef6shield\u548cwatcher\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\/","og_locale":"zh_CN","og_type":"article","og_title":"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838","og_description":"\u603b\u800c\u8a00\u4e4b \u5927\u5bb6\u662f\u5426\u6b63\u5728\u4f7f\u7528Elasticsearch\u7684\u63d2\u4ef6\uff1f \u76ee\u524d\uff0cElastic\u516c\u53f8\u63d0\u4f9b\u4e86\u4e00\u4e9b\u63d2\u4ef6\uff0c\u5982&#8 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u901a\u8fc7elasticsearch\u7684\u63d2\u4ef6shield\u548cwatcher\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2022-11-05T18:44:41+00:00","article_modified_time":"2024-05-04T10:03:47+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d453e37434c4406ca1e77\/26-0.png"}],"author":"\u97f5, \u79d1","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u97f5, \u79d1","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"6 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/","name":"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2022-11-05T18:44:41+00:00","dateModified":"2024-05-04T10:03:47+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u901a\u8fc7Elasticsearch\u7684\u63d2\u4ef6\u201cShield\u201d\u548c\u201cWatcher\u201d\u8fdb\u884c\u5bf9\u975e\u6cd5\u8bbf\u95ee\u7684\u76d1\u89c6\u548c\u5ba1\u6838"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/6530331a63adef3b3443a1fab53a0e6e","name":"\u97f5, \u79d1","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/429ccb39b3fff5188bc17986222cfb0936cbadb8cc933cff04ab5ca01bd30a08?s=96&d=mm&r=g","caption":"\u97f5, \u79d1"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/yunke\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e9%80%9a%e8%bf%87elasticsearch%e7%9a%84%e6%8f%92%e4%bb%b6shield%e5%92%8cwatcher%e8%bf%9b%e8%a1%8c%e5%af%b9%e9%9d%9e%e6%b3%95%e8%ae%bf%e9%97%ae%e7%9a%84%e7%9b%91\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=41159"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41159\/revisions"}],"predecessor-version":[{"id":99852,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/41159\/revisions\/99852"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=41159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=41159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=41159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}