服务器:Windows
版本:ELK(ES-Logstash-Kibana)版本6.5.0
Logstash日志输出报错:
[2020-05-19T10:10:50,867][INFO ][logstash.outputs.elasticsearch]
Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://localhost:9200/]}}
[2020-05-19T10:10:50,869][INFO ][logstash.outputs.elasticsearch]
Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http:/ /localhost:9200/, :path=>"/"}
[2020-05-19T10:10:55,837][INFO ][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http:/ /localhost:9200/, :path=>"/"}
ES启动日志输出报错:
org.elasticsearch.bootstrap.StartupException:java.lang.IllegalStateException: failed to obtain node locks, tried [[C:\ES\elasticsearch-6.5.0\data\elasticsearch]] with lock id [0]; maybe these locations are not writable or multiple nodes were started without increasing [node.max_local_storage_nodes] (was [1])?
原因推测:ES9200端口进程被占用,需kill该进程
解决步骤:
1.查询端口占用情况:
netstat -nao | findstr "9200"
2.杀死对应进程:
taskkill /pid 进程号 /F
3.重启ES和Logstash,查看日志是否正常
参考文档:
https://blog.youkuaiyun.com/zhouzhiwengang/article/details/107212796
如有错误请评论指正。
解决ELK Stack中Elasticsearch启动异常及Logstash日志输出问题
本文档描述了在Windows环境下,使用ELK Stack (版本6.5.0)时遇到的Elasticsearch和Logstash运行异常。Logstash日志显示Elasticsearch的9200端口可能被占用,导致无法建立连接。ES启动日志指出可能是因为同一存储节点多次启动,建议检查node.max_local_storage_nodes配置。解决方案包括:通过netstat命令查询9200端口占用情况,使用taskkill命令结束相关进程,然后重新启动ES和Logstash。通过这些步骤,可以尝试修复服务并恢复正常运行。
1845

被折叠的 条评论
为什么被折叠?



