2. 安装步骤
2.1 安装依赖包
yum install -y wget curl perl-JSON perl-libwww-perl libyaml-devel
2.2关闭并禁止重启后启动防火墙
systemctl stop firewalld.service ===>关闭防火墙
systemctl disable firewalld.service ===>禁止重启后启动防火墙
2.3下载及安装JDK
wget http://iso.epoint.com.cn/JDK/jdk-8u65-linux-x64.rpm
rpm -ivh jdk-8u65-linux-x64.rpm ##安装jdk
2.4下载及安装elasticsearch
2.4.1安装elasticsearch
wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-5.6.6.rpm ##下载elasticsearch
rpm -ivh elasticsearch-5.6.6.rpm ##安装elasticsearch
2.4.2 修改配置文件/etc/elasticsearch/elasticsearch.yml 中的network.host:服务器的IP
2.4.3 启动elasticsearch 服务
systemctl daemon-reload ##重载修改过的配置文件
systemctl enable elasticsearch.service ##开机启动elasticsearch
systemctl start elasticsearch.service ##启动elasticsearch
2.4.4 监听服务端口是否已经启动
netstat -nlp |grep LISTEN
2.4.5 检查elasticsearch是否正常启动
在浏览器中测试,输入http://服务器IP:9200/_cat ,查看是否能正常看到类似如下页面即为正常。
2.5 下载及安装Moloch
2.5.2 安装moloch rpm包(采用U盘挂载方式)
rpm -ivh moloch-1.8.0-1.x86_64.rpm
2.5.3 配置初始化Moloch
/data/moloch/bin/Configure
2.5.4 初始化、升级Elasticsearch Moloch配置
/data/moloch/db/db.pl http://localhost:9200 init ##第一次安装初始化、或者想删除所有数据
/data/moloch/db/db.pl http://localhost:9200 upgrade ##升级moloch 数据包
2.5.5 添加admin账户
/data/moloch/bin/moloch_add_user.sh admin "Admin User" moloch --admin ##新增admin账户,密码是moloch
2.5.6 开启所有服务
systemctl enable molochcapture.service ##开机启动Capture
systemctl start molochcapture.service ##启动Capture
systemctl enable molochviewer.service ##开机启动Viewer
systemctl start molochviewer.service ##启动Viewer
2.5.7 登陆Moloch http://172.18.20.223:8005