{"id":785,"date":"2026-09-17T22:18:41","date_gmt":"2026-09-17T19:18:41","guid":{"rendered":"https:\/\/imaxis.ru\/?p=785"},"modified":"2026-09-18T00:04:54","modified_gmt":"2026-09-17T21:04:54","slug":"elasticsearch-kibana-logstash-na-ubuntu-ustanovka-elk-stack-9","status":"publish","type":"post","link":"https:\/\/imaxis.ru\/?p=785","title":{"rendered":"Elasticsearch + Kibana + Logstash \u043d\u0430 Ubuntu: \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 ELK Stack 9"},"content":{"rendered":"<h1>Elasticsearch + Kibana + Logstash \u043d\u0430 Ubuntu: \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 ELK Stack 9<\/h1>\n<p>ELK Stack \u2014 \u044d\u0442\u043e \u0441\u0432\u044f\u0437\u043a\u0430 \u0438\u0437 \u0442\u0440\u0451\u0445 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u043e\u0432 Elastic: <strong>Elasticsearch<\/strong> (\u043f\u043e\u0438\u0441\u043a\u043e\u0432\u044b\u0439 \u0434\u0432\u0438\u0436\u043e\u043a \u0438 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435), <strong>Kibana<\/strong> (\u0432\u0435\u0431-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441) \u0438 <strong>Logstash<\/strong> (\u0441\u0431\u043e\u0440 \u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0430 \u043b\u043e\u0433\u043e\u0432). \u0412\u043c\u0435\u0441\u0442\u0435 \u043e\u043d\u0438 \u043e\u0431\u0440\u0430\u0437\u0443\u044e\u0442 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0446\u0435\u043d\u0442\u0440\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0441\u0431\u043e\u0440\u0430 \u0436\u0443\u0440\u043d\u0430\u043b\u043e\u0432: \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043f\u0440\u0438\u0441\u044b\u043b\u0430\u044e\u0442 \u043b\u043e\u0433\u0438, Logstash \u0438\u0445 \u0440\u0430\u0437\u0431\u0438\u0440\u0430\u0435\u0442, Elasticsearch \u0438\u043d\u0434\u0435\u043a\u0441\u0438\u0440\u0443\u0435\u0442, \u0430 Kibana \u043f\u043e\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0442\u0441\u044f Linux, Windows \u0438 BSD.<\/p>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 \u0440\u0430\u0437\u0431\u0435\u0440\u0451\u043c \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u043e\u0439 \u0447\u0430\u0441\u0442\u0438 <strong>ELK 9<\/strong> (\u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u0430\u044f \u0432\u0435\u0440\u0441\u0438\u044f \u2014 9.5.3) \u043d\u0430 Ubuntu \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u0441\u0431\u043e\u0440\u0430 \u043b\u043e\u0433\u043e\u0432 \u0441 Linux-\u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432.<\/p>\n<hr \/>\n<h2>\u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430<\/h2>\n<h3>1. \u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u043a\u044d\u0448\u0430 apt<\/h3>\n<pre><code class=\"language-bash\">apt update\napt upgrade\n<\/code><\/pre>\n<p><code>upgrade<\/code> \u0441\u0442\u043e\u0438\u0442 \u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0430 \u043d\u043e\u0432\u043e\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u0435, \u0433\u0434\u0435 \u043d\u0435 \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u043e \u0432\u0430\u0436\u043d\u044b\u0445 \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432.<\/p>\n<h3>2. \u0412\u044b\u0431\u043e\u0440 \u0441\u043f\u043e\u0441\u043e\u0431\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438<\/h3>\n<p>\u0415\u0441\u0442\u044c \u0434\u0432\u0430 \u0441\u043f\u043e\u0441\u043e\u0431\u0430 \u2014 \u0447\u0435\u0440\u0435\u0437 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0439 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 (\u0443\u0434\u043e\u0431\u043d\u0435\u0435 \u0438 \u0431\u044b\u0441\u0442\u0440\u0435\u0435) \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 deb-\u043f\u0430\u043a\u0435\u0442 (\u0435\u0441\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044e \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d).<\/p>\n<p><strong>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0438\u0437 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f.<\/strong> \u0412 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u043a\u043b\u044e\u0447 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0442 \u0432 keyring (\u043a\u043e\u043c\u0430\u043d\u0434\u0430 <code>apt-key<\/code> \u0443\u0441\u0442\u0430\u0440\u0435\u043b\u0430 \u0438 \u0443\u0434\u0430\u043b\u0435\u043d\u0430 \u0432 Ubuntu 24.04):<\/p>\n<pre><code class=\"language-bash\">apt install apt-transport-https gnupg\ncurl -s https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch | \n  gpg --no-default-keyring --keyring gnupg-ring:\/etc\/apt\/trusted.gpg.d\/elasticsearch-keyring.gpg --import\nchmod 644 \/etc\/apt\/trusted.gpg.d\/elasticsearch-keyring.gpg\n<\/code><\/pre>\n<p>\u0421\u043e\u0437\u0434\u0430\u0451\u043c \u0444\u0430\u0439\u043b \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/apt\/sources.list.d\/elastic-9.x.list\n<\/code><\/pre>\n<pre><code>deb https:\/\/artifacts.elastic.co\/packages\/9.x\/apt stable main\n<\/code><\/pre>\n<p>\u041e\u0431\u043d\u043e\u0432\u043b\u044f\u0435\u043c \u0438\u043d\u0434\u0435\u043a\u0441:<\/p>\n<pre><code class=\"language-bash\">apt-get update -o Dir::Etc::sourcelist=&quot;\/etc\/apt\/sources.list.d\/elastic-9.x.list&quot;\n<\/code><\/pre>\n<p><strong>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0438\u0437 deb-\u043f\u0430\u043a\u0435\u0442\u0430.<\/strong> \u041f\u043e\u0434\u043e\u0439\u0434\u0451\u0442, \u0435\u0441\u043b\u0438 IP \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d. \u0421\u0442\u0430\u0432\u0438\u043c \u0443\u0442\u0438\u043b\u0438\u0442\u0443 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0438 \u0441\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c \u043f\u0430\u043a\u0435\u0442\u044b \u0441 <a href=\"https:\/\/www.elastic.co\/downloads\/\">\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a<\/a>:<\/p>\n<pre><code class=\"language-bash\">apt install wget\n<\/code><\/pre>\n<h3>3. \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0431\u0440\u0430\u043d\u0434\u043c\u0430\u0443\u044d\u0440\u0430<\/h3>\n<p>\u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c \u043f\u043e\u0440\u0442\u044b:<\/p>\n<pre><code class=\"language-bash\">iptables -I INPUT -p tcp --dport 5044 -j ACCEPT\niptables -I INPUT -p tcp --dport 5601 -j ACCEPT\n<\/code><\/pre>\n<p>\u0433\u0434\u0435 <code>5044<\/code> \u2014 \u043f\u043e\u0440\u0442 \u043f\u0440\u0438\u0451\u043c\u0430 Logstash, <code>5601<\/code> \u2014 Kibana.<\/p>\n<p>\u0421\u043e\u0445\u0440\u0430\u043d\u044f\u0435\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u0430:<\/p>\n<pre><code class=\"language-bash\">apt install iptables-persistent\nnetfilter-persistent save\n<\/code><\/pre>\n<hr \/>\n<h2>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Java<\/h2>\n<p>\u041f\u0440\u043e\u0434\u0443\u043a\u0442\u044b Elastic \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u0443\u044e \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0443\u044e JDK, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0430\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 Java \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f. \u0415\u0441\u043b\u0438 \u043d\u0443\u0436\u0435\u043d \u0432\u043d\u0435\u0448\u043d\u0438\u0439 JDK (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u043b\u044f \u043f\u043b\u0430\u0433\u0438\u043d\u043e\u0432), \u0441\u0442\u0430\u0432\u0438\u043c:<\/p>\n<pre><code class=\"language-bash\">apt install default-jdk\njava -version\n<\/code><\/pre>\n<hr \/>\n<h2>Elasticsearch<\/h2>\n<h3>\u0430) \u0418\u0437 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f<\/h3>\n<pre><code class=\"language-bash\">apt install elasticsearch\n<\/code><\/pre>\n<h3>\u0431) \u0418\u0437 deb-\u043f\u0430\u043a\u0435\u0442\u0430<\/h3>\n<p>\u0421\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u043e <a href=\"https:\/\/www.elastic.co\/downloads\/elasticsearch\">\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438<\/a>:<\/p>\n<pre><code class=\"language-bash\">wget https:\/\/artifacts.elastic.co\/downloads\/elasticsearch\/elasticsearch-9.5.3-amd64.deb\ndpkg -i elasticsearch-*.deb\n<\/code><\/pre>\n<h3>\u041f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438<\/h3>\n<p>\u041f\u0440\u0438 \u043f\u0435\u0440\u0432\u043e\u043c \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u0432\u044b\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u0431\u043b\u043e\u043a Security autoconfiguration \u0441 \u043f\u0430\u0440\u043e\u043b\u0435\u043c \u0441\u0443\u043f\u0435\u0440\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f:<\/p>\n<pre><code>--------------------------- Security autoconfiguration information ----------------------------\nThe generated password for the elastic built-in superuser is : MFVg1a6NpglV69yci_rr\n<\/code><\/pre>\n<p><strong>\u041f\u0430\u0440\u043e\u043b\u044c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f <code>elastic<\/code> \u0441\u043e\u0445\u0440\u0430\u043d\u0438\u0442\u0435 \u2014 \u043e\u043d \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0434\u0430\u043b\u044c\u0448\u0435.<\/strong><\/p>\n<p>\u0421\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043c\u043e\u0436\u043d\u043e \u043a\u043e\u043c\u0430\u043d\u0434\u043e\u0439:<\/p>\n<pre><code class=\"language-bash\">\/usr\/share\/elasticsearch\/bin\/elasticsearch-reset-password -u elastic\n<\/code><\/pre>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u0441\u0435\u0440\u0432\u0438\u0441 \u0438 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0430\u0432\u0442\u043e\u0437\u0430\u043f\u0443\u0441\u043a:<\/p>\n<pre><code class=\"language-bash\">systemctl enable elasticsearch --now\n<\/code><\/pre>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">curl -k -u elastic:MFVg1a6NpglV69yci_rr https:\/\/localhost:9200\n<\/code><\/pre>\n<p>\u041e\u0442\u0432\u0435\u0442 \u0431\u0443\u0434\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u0442\u0430\u043a\u0438\u043c:<\/p>\n<pre><code class=\"language-json\">{\n  &quot;name&quot; : &quot;elk&quot;,\n  &quot;cluster_name&quot; : &quot;elasticsearch&quot;,\n  &quot;cluster_uuid&quot; : &quot;uZQ6-MAqThyLq3OJgU5-fQ&quot;,\n  &quot;version&quot; : {\n    &quot;number&quot; : &quot;9.5.3&quot;,\n    &quot;build_flavor&quot; : &quot;default&quot;,\n    &quot;build_type&quot; : &quot;deb&quot;,\n    &quot;lucene_version&quot; : &quot;10.x&quot;,\n    &quot;minimum_wire_compatibility_version&quot; : &quot;8.19.0&quot;\n  },\n  &quot;tagline&quot; : &quot;You Know, for Search&quot;\n}\n<\/code><\/pre>\n<hr \/>\n<h2>Kibana<\/h2>\n<h3>\u0430) \u0418\u0437 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f<\/h3>\n<pre><code class=\"language-bash\">apt install kibana\n<\/code><\/pre>\n<h3>\u0431) \u0418\u0437 deb-\u043f\u0430\u043a\u0435\u0442\u0430<\/h3>\n<p>\u0421\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c \u0441\u043e <a href=\"https:\/\/www.elastic.co\/downloads\/kibana\">\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 Kibana<\/a>:<\/p>\n<pre><code class=\"language-bash\">wget https:\/\/artifacts.elastic.co\/downloads\/kibana\/kibana-9.5.3-amd64.deb\ndpkg -i kibana-*.deb\n<\/code><\/pre>\n<h3>\u041f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438<\/h3>\n<p>\u0420\u0435\u0434\u0430\u043a\u0442\u0438\u0440\u0443\u0435\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/kibana\/kibana.yml\n<\/code><\/pre>\n<p>\u0423\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u043f\u0440\u043e\u0441\u043b\u0443\u0448\u0438\u0432\u0430\u043d\u0438\u044f:<\/p>\n<pre><code class=\"language-yaml\">server.host: &quot;192.168.1.10&quot;\n<\/code><\/pre>\n<p>\u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0430\u0432\u0442\u043e\u0437\u0430\u043f\u0443\u0441\u043a \u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">systemctl enable kibana\nsystemctl restart kibana\n<\/code><\/pre>\n<p>\u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 <code>http:\/\/&lt;IP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430&gt;:5601<\/code>. \u041f\u043e\u044f\u0432\u0438\u0442\u0441\u044f \u0444\u043e\u0440\u043c\u0430 \u0432\u0432\u043e\u0434\u0430 \u0442\u043e\u043a\u0435\u043d\u0430. \u041f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0442\u043e\u043a\u0435\u043d \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435:<\/p>\n<pre><code class=\"language-bash\">\/usr\/share\/elasticsearch\/bin\/elasticsearch-create-enrollment-token -s kibana\n<\/code><\/pre>\n<p>\u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0442\u043e\u043a\u0435\u043d \u0432 Kibana \u0438 \u043d\u0430\u0436\u0438\u043c\u0430\u0435\u043c <strong>Configure Elastic<\/strong>. \u041e\u0442\u043a\u0440\u043e\u0435\u0442\u0441\u044f \u043e\u043a\u043d\u043e \u0432\u0432\u043e\u0434\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043e\u0447\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u2014 \u043f\u043e\u043b\u0443\u0447\u0430\u0435\u043c \u0435\u0433\u043e:<\/p>\n<pre><code class=\"language-bash\">\/usr\/share\/kibana\/bin\/kibana-verification-code\n<\/code><\/pre>\n<p>\u0412\u0432\u043e\u0434\u0438\u043c 6-\u0437\u043d\u0430\u0447\u043d\u044b\u0439 \u043a\u043e\u0434, \u043d\u0430\u0436\u0438\u043c\u0430\u0435\u043c <strong>Verify<\/strong>. \u041f\u043e\u0441\u043b\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043f\u043e\u044f\u0432\u0438\u0442\u0441\u044f \u043e\u043a\u043d\u043e \u0432\u0445\u043e\u0434\u0430 \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c \u043b\u043e\u0433\u0438\u043d <code>elastic<\/code> \u0438 \u043f\u0430\u0440\u043e\u043b\u044c \u0438\u0437 \u0448\u0430\u0433\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 Elasticsearch.<\/p>\n<hr \/>\n<h2>Logstash<\/h2>\n<h3>\u0430) \u0418\u0437 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f<\/h3>\n<pre><code class=\"language-bash\">apt install logstash\n<\/code><\/pre>\n<h3>\u0431) \u0418\u0437 deb-\u043f\u0430\u043a\u0435\u0442\u0430<\/h3>\n<p>\u0421\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c \u0441\u043e <a href=\"https:\/\/www.elastic.co\/downloads\/logstash\">\u0441\u0442\u0440\u0430\u043d\u0438\u0446\u044b \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 Logstash<\/a>:<\/p>\n<pre><code class=\"language-bash\">wget https:\/\/artifacts.elastic.co\/downloads\/logstash\/logstash-9.5.3-amd64.deb\ndpkg -i logstash-*.deb\n<\/code><\/pre>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 Logstash<\/h3>\n<p>\u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0430\u0432\u0442\u043e\u0437\u0430\u043f\u0443\u0441\u043a \u0438 \u0441\u0442\u0430\u0440\u0442\u0443\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">systemctl enable logstash\nsystemctl start logstash\n<\/code><\/pre>\n<p>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0445\u0440\u0430\u043d\u044f\u0442\u0441\u044f \u0432 <code>\/etc\/logstash\/conf.d\/<\/code> \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u0430\u0445 \u0441 \u0441\u0435\u043a\u0446\u0438\u044f\u043c\u0438:<\/p>\n<ol>\n<li><code>input<\/code> \u2014 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445;<\/li>\n<li><code>filter<\/code> \u2014 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0430;<\/li>\n<li><code>output<\/code> \u2014 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435.<\/li>\n<\/ol>\n<p><strong>input.conf:<\/strong><\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/input.conf\n<\/code><\/pre>\n<pre><code>input {\n  beats {\n    port =&gt; 5044\n  }\n}\n<\/code><\/pre>\n<p><strong>filter.conf:<\/strong><\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/filter.conf\n<\/code><\/pre>\n<pre><code>filter {\n  if [type] == &quot;syslog&quot; {\n    grok {\n      match =&gt; { &quot;message&quot; =&gt; &quot;%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:[%{POSINT:syslog_pid}])?: %{GREEDYDATA:syslog_message}&quot; }\n      add_field =&gt; [ &quot;received_at&quot;, &quot;%{@timestamp}&quot; ]\n      add_field =&gt; [ &quot;received_from&quot;, &quot;%{host}&quot; ]\n    }\n    date {\n      match =&gt; [ &quot;syslog_timestamp&quot;, &quot;MMM  d HH:mm:ss&quot;, &quot;MMM dd HH:mm:ss&quot; ]\n    }\n  }\n}\n<\/code><\/pre>\n<p><strong>output.conf:<\/strong><\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/output.conf\n<\/code><\/pre>\n<pre><code>output {\n  elasticsearch {\n    hosts =&gt; [&quot;https:\/\/localhost:9200&quot;]\n    ssl =&gt; true\n    ssl_certificate_verification =&gt; false\n    manage_template =&gt; false\n    index =&gt; &quot;%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}&quot;\n    user =&gt; elastic\n    password =&gt; &quot;MFVg1a6NpglV69yci_rr&quot;\n  }\n}\n<\/code><\/pre>\n<p><strong>\u0417\u0430\u043c\u0435\u043d\u0438\u0442\u0435 \u043f\u0430\u0440\u043e\u043b\u044c \u043d\u0430 \u0441\u0432\u043e\u0439, \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u044b\u0439 \u043f\u0440\u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0435 Elasticsearch.<\/strong><\/p>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e:<\/p>\n<pre><code class=\"language-bash\">\/usr\/share\/logstash\/bin\/logstash --path.settings \/etc\/logstash -t\n<\/code><\/pre>\n<p>\u0414\u043e\u043b\u0436\u043d\u044b \u0443\u0432\u0438\u0434\u0435\u0442\u044c <code>Configuration OK<\/code>. \u041f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">systemctl restart logstash\n<\/code><\/pre>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a \u0437\u0430\u043d\u0438\u043c\u0430\u0435\u0442 \u043e\u043a\u043e\u043b\u043e \u043c\u0438\u043d\u0443\u0442\u044b. \u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u043f\u043e\u0440\u0442 \u0441\u043b\u0443\u0448\u0430\u0435\u0442\u0441\u044f:<\/p>\n<pre><code class=\"language-bash\">ss -tunlp | grep 5044\n<\/code><\/pre>\n<pre><code>tcp LISTEN 0 128 :::5044 :::* users:((&quot;java&quot;,pid=11745,fd=114))\n<\/code><\/pre>\n<p>\u0421\u0435\u0440\u0432\u0438\u0441 \u0433\u043e\u0442\u043e\u0432 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0442\u044c \u043b\u043e\u0433\u0438.<\/p>\n<hr \/>\n<h2>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 (Filebeat)<\/h2>\n<p>\u0414\u043b\u044f \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u043b\u043e\u0433\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c <strong>Filebeat<\/strong>. \u041e\u043d \u0435\u0441\u0442\u044c \u0434\u043b\u044f Linux, Windows \u0438 macOS.<\/p>\n<h3>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u043d\u0430 CentOS \/ RHEL<\/h3>\n<pre><code class=\"language-bash\">rpm --import https:\/\/packages.elastic.co\/GPG-KEY-elasticsearch\nvi \/etc\/yum.repos.d\/elastic-9.x.repo\n<\/code><\/pre>\n<pre><code>[elastic-9.x]\nname=Elastic repository for 9.x packages\nbaseurl=https:\/\/artifacts.elastic.co\/packages\/9.x\/yum\ngpgcheck=1\ngpgkey=https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch\nenabled=1\nautorefresh=1\ntype=rpm-md\n<\/code><\/pre>\n<pre><code class=\"language-bash\">yum install filebeat\n<\/code><\/pre>\n<p>\u0418\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 RPM:<\/p>\n<pre><code class=\"language-bash\">wget https:\/\/artifacts.elastic.co\/downloads\/beats\/filebeat\/filebeat-9.5.3-x86_64.rpm\nrpm -ivh filebeat-*.rpm\n<\/code><\/pre>\n<h3>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u043d\u0430 Ubuntu \/ Debian<\/h3>\n<pre><code class=\"language-bash\">vi \/etc\/apt\/sources.list.d\/elastic-9.x.list\n<\/code><\/pre>\n<pre><code>deb https:\/\/artifacts.elastic.co\/packages\/9.x\/apt stable main\n<\/code><\/pre>\n<pre><code class=\"language-bash\">apt update\napt install filebeat\n<\/code><\/pre>\n<p>\u0418\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 deb:<\/p>\n<pre><code class=\"language-bash\">wget https:\/\/artifacts.elastic.co\/downloads\/beats\/filebeat\/filebeat-9.5.3-amd64.deb\ndpkg -i filebeat-*.deb\n<\/code><\/pre>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438<\/h3>\n<pre><code class=\"language-bash\">vi \/etc\/filebeat\/filebeat.yml\n<\/code><\/pre>\n<p>\u0412 \u0440\u0430\u0437\u0434\u0435\u043b\u0435 <code>filebeat.inputs<\/code> \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0441\u0431\u043e\u0440 (<code>enabled: true<\/code>) \u0438 \u0437\u0430\u0434\u0430\u0451\u043c \u043f\u0443\u0442\u0438:<\/p>\n<pre><code class=\"language-yaml\">filebeat.inputs:\n  - type: filestream\n    enabled: true\n    paths:\n      - \/var\/log\/*.log\n      - \/var\/log\/secure\n      - \/var\/log\/messages\n      - \/var\/log\/syslog\n<\/code><\/pre>\n<blockquote>\n<p>\u0412 Filebeat 9 \u0432\u043c\u0435\u0441\u0442\u043e \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0435\u0433\u043e <code>type: log<\/code> \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f <code>type: filestream<\/code>.<\/p>\n<\/blockquote>\n<p>\u041a\u043e\u043c\u043c\u0435\u043d\u0442\u0438\u0440\u0443\u0435\u043c \u043f\u0440\u044f\u043c\u043e\u0439 \u0432\u044b\u0432\u043e\u0434 \u0432 Elasticsearch:<\/p>\n<pre><code class=\"language-yaml\">#output.elasticsearch:\n#  hosts: [&quot;localhost:9200&quot;]\n<\/code><\/pre>\n<p>\u0412\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0432\u044b\u0432\u043e\u0434 \u0432 Logstash \u0438 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u0430\u0434\u0440\u0435\u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430:<\/p>\n<pre><code class=\"language-yaml\">output.logstash:\n  hosts: [&quot;192.168.1.10:5044&quot;]\n<\/code><\/pre>\n<p><strong>\u0433\u0434\u0435 <code>192.168.1.10<\/code> \u2014 \u0430\u0434\u0440\u0435\u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 ELK.<\/strong><\/p>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">systemctl enable filebeat\nsystemctl restart filebeat\n<\/code><\/pre>\n<hr \/>\n<h2>\u041f\u0440\u043e\u0441\u043c\u043e\u0442\u0440 \u043b\u043e\u0433\u043e\u0432 \u0432 Kibana<\/h2>\n<p>\u041e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c <code>http:\/\/&lt;IP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430&gt;:5601<\/code>, \u0432\u0445\u043e\u0434\u0438\u043c \u043f\u043e\u0434 <code>elastic<\/code>. \u0412 \u043c\u0435\u043d\u044e <strong>Analytics \u2192 Discover<\/strong> \u0443\u0432\u0438\u0434\u0438\u043c \u043b\u043e\u0433\u0438 \u0441 \u043a\u043b\u0438\u0435\u043d\u0442\u0430. \u041f\u0440\u0438 \u043f\u0435\u0440\u0432\u043e\u043c \u0432\u0445\u043e\u0434\u0435 Kibana \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0438\u0442 \u0441\u043e\u0437\u0434\u0430\u0442\u044c Data View \u2014 \u0443\u043a\u0430\u0436\u0438\u0442\u0435 \u0448\u0430\u0431\u043b\u043e\u043d <code>filebeat-*<\/code> \u0438\u043b\u0438 <code>logstash-*<\/code>. \u041d\u0430\u0448 ELK \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u0438 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442.<\/p>\n<hr \/>\n<h2>\u041e\u0442\u043f\u0440\u0430\u0432\u043a\u0430 \u043b\u043e\u0433\u043e\u0432 \u0447\u0435\u0440\u0435\u0437 Rsyslog<\/h2>\n<p>Rsyslog \u0443\u043c\u0435\u0435\u0442 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u0436\u0443\u0440\u043d\u0430\u043b\u044b \u043f\u043e \u0441\u0435\u0442\u0438 \u043f\u0440\u044f\u043c\u043e \u0432 Logstash. \u041d\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0435 \u0441\u043e\u0437\u0434\u0430\u0451\u043c \u0448\u0430\u0431\u043b\u043e\u043d \u043b\u043e\u0433\u0430:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/rsyslog.d\/json-template.conf\n<\/code><\/pre>\n<pre><code>template(name=&quot;json-template&quot; type=&quot;list&quot;) {\n  constant(value=&quot;{&quot;)\n    constant(value=&quot;&quot;@timestamp&quot;:&quot;&quot;)     property(name=&quot;timereported&quot; dateFormat=&quot;rfc3339&quot;)\n    constant(value=&quot;&quot;,&quot;@version&quot;:&quot;1&quot;)\n    constant(value=&quot;&quot;,&quot;message&quot;:&quot;&quot;)      property(name=&quot;msg&quot; format=&quot;json&quot;)\n    constant(value=&quot;&quot;,&quot;sysloghost&quot;:&quot;&quot;)   property(name=&quot;hostname&quot;)\n    constant(value=&quot;&quot;,&quot;severity&quot;:&quot;&quot;)     property(name=&quot;syslogseverity-text&quot;)\n    constant(value=&quot;&quot;,&quot;facility&quot;:&quot;&quot;)     property(name=&quot;syslogfacility-text&quot;)\n    constant(value=&quot;&quot;,&quot;programname&quot;:&quot;&quot;)  property(name=&quot;programname&quot;)\n    constant(value=&quot;&quot;,&quot;procid&quot;:&quot;&quot;)       property(name=&quot;procid&quot;)\n  constant(value=&quot;&quot;}n&quot;)\n}\n<\/code><\/pre>\n<p>\u0424\u0430\u0439\u043b \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/rsyslog.d\/logstash.conf\n<\/code><\/pre>\n<pre><code>*.* @@192.168.1.10:5045;json-template\n<\/code><\/pre>\n<p>\u0433\u0434\u0435:<\/p>\n<ul>\n<li><code>*<\/code> \u2014 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a \u043b\u043e\u0433\u043e\u0432 (\u0432\u0441\u0435);<\/li>\n<li><code>.*<\/code> \u2014 \u0432\u0441\u0435 \u0443\u0440\u043e\u0432\u043d\u0438 \u0432\u0430\u0436\u043d\u043e\u0441\u0442\u0438;<\/li>\n<li><code>@@<\/code> \u2014 TCP (\u043e\u0434\u0438\u043d <code>@<\/code> \u2014 UDP);<\/li>\n<li><code>192.168.1.10<\/code> \u2014 \u0430\u0434\u0440\u0435\u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430;<\/li>\n<li><code>5045<\/code> \u2014 \u043f\u043e\u0440\u0442 Logstash \u0434\u043b\u044f rsyslog;<\/li>\n<li><code>json-template<\/code> \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0439 \u0448\u0430\u0431\u043b\u043e\u043d.<\/li>\n<\/ul>\n<p>\u041f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c:<\/p>\n<pre><code class=\"language-bash\">systemctl restart rsyslog\n<\/code><\/pre>\n<p>\u041d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0434\u043e\u043f\u0438\u0441\u044b\u0432\u0430\u0435\u043c \u043f\u0440\u0438\u0451\u043c \u0432 <code>input.conf<\/code>:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/input.conf\n<\/code><\/pre>\n<pre><code>  tcp {\n    port =&gt; 5045\n    codec =&gt; &quot;json&quot;\n    type =&gt; &quot;rsyslog&quot;\n  }\n<\/code><\/pre>\n<p>\u0418 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0432\u044b\u0432\u043e\u0434\u0430 \u0432 <code>output.conf<\/code> \u043f\u0435\u0440\u0435\u0434 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u043c\u0438:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/output.conf\n<\/code><\/pre>\n<pre><code>  if [type] == &quot;rsyslog&quot; {\n    elasticsearch {\n      hosts =&gt; [ &quot;https:\/\/localhost:9200&quot; ]\n      ssl =&gt; true\n      ssl_certificate_verification =&gt; false\n      user =&gt; elastic\n      password =&gt; &quot;MFVg1a6NpglV69yci_rr&quot;\n    }\n  }\n<\/code><\/pre>\n<pre><code class=\"language-bash\">systemctl restart logstash\n<\/code><\/pre>\n<p>\u041f\u0440\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0432\u0430\u0435\u043c \u043f\u043e\u0440\u0442:<\/p>\n<pre><code class=\"language-bash\">iptables -I INPUT -p tcp --dport 5045 -j ACCEPT\n<\/code><\/pre>\n<hr \/>\n<h2>\u041f\u0440\u0438\u043c\u0435\u0440 \u0441\u0431\u043e\u0440\u0430 \u043b\u043e\u0433\u043e\u0432 NGINX<\/h2>\n<p>\u0414\u0432\u0430 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430: <code>NGINX \u2192 Filebeat \u2192 Logstash \u2192 Elastic<\/code> \u0438 <code>NGINX \u2192 Logstash \u2192 Elastic<\/code> \u043d\u0430\u043f\u0440\u044f\u043c\u0443\u044e.<\/p>\n<h3>\u0427\u0435\u0440\u0435\u0437 Filebeat<\/h3>\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043f\u0443\u0442\u044c \u0432 <code>filebeat.yml<\/code>:<\/p>\n<pre><code>paths:\n  - \/var\/log\/nginx\/*.log\n<\/code><\/pre>\n<pre><code class=\"language-bash\">systemctl restart filebeat\n<\/code><\/pre>\n<p>\u0414\u0435\u043b\u0430\u0435\u043c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a \u0441\u0430\u0439\u0442\u0443 \u0438 \u0438\u0449\u0435\u043c \u0432 Kibana \u043f\u043e <code>nginx<\/code>.<\/p>\n<h3>\u041d\u0430\u043f\u0440\u044f\u043c\u0443\u044e \u0432 Logstash<\/h3>\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043f\u0440\u0438\u0451\u043c syslog:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/logstash\/conf.d\/input.conf\n<\/code><\/pre>\n<pre><code>  syslog {\n    port =&gt; 5140\n  }\n<\/code><\/pre>\n<pre><code class=\"language-bash\">systemctl restart logstash\n<\/code><\/pre>\n<p>\u041d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c nginx:<\/p>\n<pre><code class=\"language-bash\">vi \/etc\/nginx\/nginx.conf\n<\/code><\/pre>\n<pre><code>log_format logstash '$remote_addr - $remote_user [$time_local] &quot;$host&quot; '\n                    '&quot;$request&quot; $status $body_bytes_sent '\n                    '&quot;$http_referer&quot; &quot;$http_user_agent&quot;';\n\naccess_log syslog:server=localhost:5140,tag=nginx_access logstash;\nerror_log  syslog:server=localhost:5140,tag=nginx_error notice;\n<\/code><\/pre>\n<pre><code class=\"language-bash\">nginx -t &amp;&amp; nginx -s reload\n<\/code><\/pre>\n<p>\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043b\u043e\u0433\u0438 \u0432 Kibana.<\/p>\n<hr \/>\n<h2>\u0422\u043e\u043d\u043a\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0434\u0432\u043e\u0434\u043d\u044b\u0435 \u043a\u0430\u043c\u043d\u0438<\/h2>\n<ul>\n<li><strong><code>apt-key<\/code> \u0443\u0434\u0430\u043b\u0451\u043d<\/strong> \u2014 \u0432 Ubuntu 24.04\/26.04 \u043a\u043b\u044e\u0447 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 <code>gpg --no-default-keyring<\/code> \u0432 <code>\/etc\/apt\/trusted.gpg.d\/<\/code>.<\/li>\n<li><strong>Filebeat 9: <code>type: log<\/code> \u0443\u0441\u0442\u0430\u0440\u0435\u043b<\/strong> \u2014 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 <code>filestream<\/code>.<\/li>\n<li><strong>\u0412\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u0430\u044f Java<\/strong> \u2014 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0430\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 JDK \u043d\u0435 \u043d\u0443\u0436\u043d\u0430, \u0432\u0441\u0435 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u044b \u0438\u0434\u0443\u0442 \u0441\u043e \u0441\u0432\u043e\u0435\u0439.<\/li>\n<li><strong>\u041f\u0430\u0440\u043e\u043b\u044c elastic<\/strong> \u2014 \u0445\u0440\u0430\u043d\u0438\u0442\u0435 \u043d\u0430\u0434\u0451\u0436\u043d\u043e; \u043f\u0440\u0438 \u0443\u0442\u0435\u0447\u043a\u0435 \u0441\u043c\u0435\u043d\u0438\u0442\u0435 \u0447\u0435\u0440\u0435\u0437 <code>elasticsearch-reset-password<\/code>.<\/li>\n<li><strong><code>ssl_certificate_verification =&gt; false<\/code><\/strong> \u2014 \u0443\u0434\u043e\u0431\u043d\u043e \u0434\u043b\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0441\u0442\u0435\u043d\u0434\u0430; \u043d\u0430 \u043f\u0440\u043e\u0434\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u0442\u0435 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u0439 CA-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442.<\/li>\n<li><strong>Data View \u0432 Kibana<\/strong> \u2014 \u0431\u0435\u0437 \u043d\u0435\u0433\u043e Discover \u043d\u0435 \u043f\u043e\u043a\u0430\u0436\u0435\u0442 \u0434\u0430\u043d\u043d\u044b\u0435, \u043d\u0435 \u0437\u0430\u0431\u0443\u0434\u044c\u0442\u0435 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u043f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0432\u043e\u0433\u043e \u0432\u0445\u043e\u0434\u0430.<\/li>\n<\/ul>\n<hr \/>\n<h2>\u0428\u043f\u0430\u0440\u0433\u0430\u043b\u043a\u0430<\/h2>\n<pre><code class=\"language-bash\"># \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439\ncurl -s https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch | \n  gpg --no-default-keyring --keyring gnupg-ring:\/etc\/apt\/trusted.gpg.d\/elasticsearch-keyring.gpg --import\necho &quot;deb https:\/\/artifacts.elastic.co\/packages\/9.x\/apt stable main&quot; &gt; \/etc\/apt\/sources.list.d\/elastic-9.x.list\napt update\n\n# \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u0430\u044f \u0447\u0430\u0441\u0442\u044c\napt install elasticsearch kibana logstash\nsystemctl enable elasticsearch kibana logstash --now\n\n# \u043a\u043b\u0438\u0435\u043d\u0442\napt install filebeat\nsystemctl enable filebeat --now\n<\/code><\/pre>\n<p><em>\u041f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043e \u043d\u0430: Ubuntu 22.04\/24.04\/26.04 + ELK 9.5.3.<\/em><br \/>\n<em>\u0414\u0430\u0442\u0430: \u0421\u0435\u043d\u0442\u044f\u0431\u0440\u044c 2026.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Elasticsearch + Kibana + Logstash \u043d\u0430 Ubuntu: \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 ELK Stack<\/p>\n","protected":false},"author":0,"featured_media":953,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"aioseo_notices":[],"views":11,"_links":{"self":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=785"}],"version-history":[{"count":2,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/785\/revisions"}],"predecessor-version":[{"id":788,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/posts\/785\/revisions\/788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=\/wp\/v2\/media\/953"}],"wp:attachment":[{"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/imaxis.ru\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}