Graylog 5.1 安裝紀錄

1.安裝mongodb
2.安裝opensearch
3.安裝graylog server

1.安裝mongodb

#tee /etc/yum.repos.d/mongodb-org.repo << EOF
[mongodb-org-6.0]
name=MongoDB Repository
baseurl=https://repo.mongodb.org/yum/redhat//mongodb-org/6.0/x86_64/
gpgcheck=1
enabled=1
gpgkey=https://www.mongodb.org/static/pgp/server-6.0.asc
EOF
#yum -y install mongodb-org
#systemctl start mongod.service
#systemctl enable mongod.service

2.安裝opensearch
關閉THP

#echo "Description=Disable Transparent Huge Pages (THP)
DefaultDependencies=no
After=sysinit.target local-fs.target
[Service]
Type=oneshot
ExecStart=/bin/sh -c 'echo never | tee /sys/kernel/mm/transparent_hugepage/enabled > /dev/null'
[Install]
WantedBy=basic.target" | sudo tee /etc/systemd/system/disable-transparent-huge-pages.service
#systemctl daemon-reload
#systemctl enable disable-transparent-huge-pages.service
#systemctl start disable-transparent-huge-pages.service

新增opensearch repo

#curl -SL https://artifacts.opensearch.org/releases/bundle/opensearch/2.x/opensearch-2.x.repo -o /etc/yum.repos.d/opensearch-2.x.repo

安裝opensearch

#yum -y install opensearch

設定opensearch

#vim /etc/opensearch/opensearch.yml
path.data: /var/lib/opensearch
path.logs: /var/log/opensearch
network.host: 0.0.0.0
http.port: 9200
discovery.type: single-node
plugins.security.disabled: true
#systemctl start opensearch
#systemctl enable opensearch

3.安裝graylog server

#rpm -Uvh https://packages.graylog2.org/repo/packages/graylog-5.1-repository_latest.rpm
#yum -y install graylog-server
#yum -y install pwgen

產生密碼

#pwgen -N 1 -s 96
#echo -n "Enter Password: " && head -1 </dev/stdin | tr -d '\n' | sha256sum | cut -d" " -f1

設定graylog server

#vim /etc/graylog/server/server.conf
password_secret = xxx
root_password_sha2 = xxx
http_bind_address = 0.0.0.0:9000
mongodb_uri = mongodb://localhost/graylog

啟動服務

#systemctl start graylog-server
#systemctl enable graylog-server.service
Facebook Comments