安装依赖软件
sudo add-apt-repository universe
sudo apt-get update && sudo apt-get upgrade
sudo apt-get install apt-transport-https openjdk-8-jre-headless uuid-runtime pwgen
MongoDB
sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv 9DA31620334BD75D9DCB49F368818C72E52529D4
echo "deb [ arch=amd64 ] https://repo.mongodb.org/apt/ubuntu bionic/mongodb-org/4.0 multiverse" | sudo tee /etc/apt/sources.list.d/mongodb-org-4.0.list
sudo apt-get update
sudo apt-get install -y mongodb-org
启动验证MongoDB
sudo systemctl daemon-reload
sudo systemctl enable mongod.service
sudo systemctl restart mongod.service
sudo systemctl --type=service --state=active | grep mongod
Elasticsearch 7.x
wget -q https://artifacts.elastic.co/GPG-KEY-elasticsearch -O myKey
sudo apt-key add myKey
echo "deb https://artifacts.elastic.co/packages/oss-7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install elasticsearch-oss
修改配置
sudo tee -a /etc/elasticsearch/elasticsearch.yml > /dev/null <<EOT
cluster.name: graylog
action.auto_create_index: false
EOT
启动验证Elasticsearch
sudo systemctl daemon-reload
sudo systemctl enable elasticsearch.service
sudo systemctl restart elasticsearch.service
sudo systemctl --type=service --state=active | grep elasticsearch
下载graylog
https://packages.graylog2.org/packages
wget https://packages.graylog2.org/repo/packages/graylog-4.0-repository_latest.deb --no-check-certificate
安装 graylog
sudo dpkg -i graylog-4.0-repository_latest.deb
sudo apt-get update && sudo apt-get install graylog-server
安装企业插件【可选】
sudo apt-get install graylog-enterprise-plugins graylog-integrations-plugins graylog-enterprise-integrations-plugins
配置graylog
获取root_password_sha2 密码
echo -n "Enter Password: " && head -1 </dev/stdin | tr -d '\n' | sha256sum | cut -d" " -f1
Enter Password: admin
8c6976e5b5410415bde908bd4dee15dfb167a9c873fc4bb8a81f6f2ab448a918
打开/etc/graylog/server/server.conf配置文件
vi /etc/graylog/server/server.conf
设置 password_secret 、 root_password_sha2 密码,这里的password_secret需要最少16位密码,必须设置否则启动报错
找到#http_bind_address = 127.0.0.1:9000
取消注释,如需外网访问,修改成外网IP
启动验证graylog
sudo systemctl daemon-reload
sudo systemctl enable graylog-server.service
sudo systemctl start graylog-server.service
sudo systemctl --type=service --state=active | grep graylog
有下面的信息代表服务已经启动
graylog-server.service loaded active running Graylog server
打开浏览器输入http://127.0.0.1:9000
用户名:admin
密 码:admin //注意密码是root_password_sha2设置的