{"id":956,"date":"2022-09-15T16:25:29","date_gmt":"2022-09-15T08:25:29","guid":{"rendered":"http:\/\/learning.sino-vt.com:8988\/?p=956"},"modified":"2022-11-29T08:57:14","modified_gmt":"2022-11-29T00:57:14","slug":"%e3%80%90es%e8%bf%81%e7%a7%bb%e3%80%91es%e7%ab%af%e5%8f%a3%e9%9d%9e%e9%bb%98%e8%ae%a49200%ef%bc%8c%e4%bd%bf%e7%94%a8logstash%e8%bf%81%e7%a7%bb%e8%84%9a%e6%9c%ac","status":"publish","type":"post","link":"http:\/\/learning.sino-vt.com:8988\/index.php\/2022\/09\/15\/%e3%80%90es%e8%bf%81%e7%a7%bb%e3%80%91es%e7%ab%af%e5%8f%a3%e9%9d%9e%e9%bb%98%e8%ae%a49200%ef%bc%8c%e4%bd%bf%e7%94%a8logstash%e8%bf%81%e7%a7%bb%e8%84%9a%e6%9c%ac\/","title":{"rendered":"\u3010es\u8fc1\u79fb\u3011es\u7aef\u53e3\u975e\u9ed8\u8ba49200\uff0c\u4f7f\u7528logstash\u8fc1\u79fb\u811a\u672c"},"content":{"rendered":"<p><strong>\u95ee\u9898\u7248\u672c\uff1a<\/strong><\/p>\n<p>ES\u5347\u7ea7\u6216\u6570\u636e\u8fc1\u79fb\u65f6\u4f7f\u7528<\/p>\n<p><strong>\u95ee\u9898\u73b0\u8c61\/\u62a5\u9519\uff1a<\/strong><\/p>\n<p>\u4e4b\u524d\u6211\u4eec\u6709\u5f00\u53d1\u63d0\u4f9b\u7684\u5173\u4e8eES\u6570\u636e\u4ece5.6.7\u7248\u672c\u8fc1\u79fb\u52307.8.1\u7248\u672c\u7684\u8fc1\u79fb\u811a\u672c\u7ed3\u5408logstash\u4f7f\u7528\uff0c\u4f46\u7aef\u53e3\u662f\u9ed8\u8ba4\u76849200\uff0c\u5e94\u8be5\u5982\u4f55\u5904\u7406<\/p>\n<p><strong>\u6392\u67e5\u601d\u8def\/\u89e3\u51b3\u65b9\u6848\uff1a<\/strong><\/p>\n<p>\u4e0d\u8981\u76f4\u63a5\u624b\u52a8\u5728\u811a\u672c\u4e2d\u4fee\u65399200\u7aef\u53e3\uff0c\u56e0\u4e3a\u6d89\u53ca\u5230\u4e86\u5176\u4ed6\u53d8\u91cf\u7684\u8c03\u7528\uff0c\u6240\u4ee5\u53ea\u6539\u67e5\u5230\u76849200\u4e0d\u53ef\u4ee5\u3002<\/p>\n<ul>\n<li>\u5728auditsys.ini\u6587\u4ef6\u4e2d\u6307\u5b9aES\u5730\u5740\u65f6\uff0c\u6dfb\u52a0\u4e0a\u7aef\u53e3\uff0c\u683c\u5f0f\uff1aip\uff1a\u7aef\u53e3\uff0c\u5982\uff1a192.168.1.66:9222<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-957\" src=\"http:\/\/learning.sino-vt.com:8988\/wp-content\/uploads\/2022\/09\/\u5fae\u4fe1\u56fe\u7247_20220915135735-300x70.png\" alt=\"\" width=\"300\" height=\"70\" srcset=\"http:\/\/learning.sino-vt.com:8988\/wp-content\/uploads\/2022\/09\/\u5fae\u4fe1\u56fe\u7247_20220915135735-300x70.png 300w, http:\/\/learning.sino-vt.com:8988\/wp-content\/uploads\/2022\/09\/\u5fae\u4fe1\u56fe\u7247_20220915135735.png 633w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<ul>\n<li>\u9700\u8981\u5728\u539f\u6709\u811a\u672c\u57fa\u7840\u4e0a\u66ff\u6362dataMigrate.sh<\/li>\n<\/ul>\n<p>\u66ff\u6362\u811a\u672c\u5185\u5bb9\u5982\u4e0b\uff1a<\/p>\n<p>\uff08\u65e0\u6cd5\u4ee5\u9644\u4ef6\u5f62\u5f0f\u4e0a\u4f20\uff0c\u53ef\u4ee5\u767e\u5ea6\u4e91\u4e0b\u8f7d\uff1a\u94fe\u63a5\uff1ahttps:\/\/pan.baidu.com\/s\/1pXtc6u4nLENhfGVybuYFUw<br \/>\n\u63d0\u53d6\u7801\uff1acazl\uff09<\/p>\n<p>source .\/auditsys.ini<\/p>\n<p>sourcehost=$(echo $sourcehost)<br \/>\ninithost=$(echo $inithost)<br \/>\ninitdate=$(echo $enddate)<br \/>\nstartdate=$(echo $startdate)<br \/>\nenddate=$(echo $enddate)<br \/>\ninitdate=${initdate\/\/-0\/-}<\/p>\n<p>inittimes=$(date -d &#8220;$initdate&#8221; +%s)<br \/>\nstarttimes=$(date -d &#8220;$startdate&#8221; +%s)<\/p>\n<p>while [ $starttimes -le $inittimes ]<br \/>\ndo<\/p>\n<p>logstashfile=auditsys-$initdate.conf<\/p>\n<p>cp auditsys.conf .\/conf\/$logstashfile<br \/>\nsed -i &#8220;s\/_sourcehost_\/$sourcehost\/g&#8221; .\/conf\/$logstashfile<br \/>\nsed -i &#8220;s\/_inithost_\/$inithost\/g&#8221; .\/conf\/$logstashfile<br \/>\nsed -i &#8220;s\/_sourceindex_\/metadata-$initdate\/g&#8221; .\/conf\/$logstashfile<\/p>\n<p>sourcecount=$(bash getSourceCount.sh http:\/\/$sourcehost\/metadata-$initdate\/_count)<\/p>\n<p>imetadatacount=$(bash getInitCount.sh http:\/\/$inithost\/meta-metadata-$initdate\/_count)<br \/>\nif [[ $imetadatacount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nimetadatacount=0<br \/>\nfi<\/p>\n<p>iclickcount=$(bash getInitCount.sh http:\/\/$inithost\/meta-click-$initdate\/_count)<br \/>\nif [[ $iclickcount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\niclickcount=0<br \/>\nfi<\/p>\n<p>isessioncount=$(bash getInitCount.sh http:\/\/$inithost\/meta-session-$initdate\/_count)<br \/>\nif [[ $isessioncount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nisessioncount=0<br \/>\nfi<\/p>\n<p>iinfractcount=$(bash getInitCount.sh http:\/\/$inithost\/meta-infract-$initdate\/_count)<br \/>\nif [[ $iinfractcount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\niinfractcount=0<br \/>\nfi<\/p>\n<p>iefficiencycount=$(bash getInitCount.sh http:\/\/$inithost\/meta-efficiency-$initdate\/_count)<br \/>\nif [[ $iefficiencycount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\niefficiencycount=0<br \/>\nfi<\/p>\n<p>let &#8220;iinittotal=$imetadatacount+$iclickcount+$isessioncount+$iinfractcount+$iefficiencycount&#8221;<\/p>\n<p>echo &#8220;sourcecount:$sourcecount&#8221;<br \/>\necho &#8220;iinittotal:$iinittotal&#8221;<br \/>\nif [[ $sourcecount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$sourcehost\/metadata-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nelif [[ $sourcecount == &#8220;0&#8221; ]];<br \/>\nthen<br \/>\nsourceResult=$(curl -s http:\/\/$sourcehost\/metadata-$initdate\/_count)<br \/>\necho &#8220;sourceResult:$sourceResult&#8221;<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$sourcehost\/metadata-$initdate\/_count count is 0&#8221;<br \/>\nafterdate=$(date -d &#8220;$initdate -1 day &#8221; +%Y-%m-%d)<br \/>\nafterdate=${afterdate\/\/-0\/-}<br \/>\nsed -i &#8220;s\/enddate=$initdate\/enddate=$afterdate\/g&#8221; auditsys.ini<br \/>\ninitdate=$afterdate<br \/>\ninitdate=${initdate\/\/-0\/-}<br \/>\ninittimes=$(date -d &#8220;$initdate&#8221; +%s)<br \/>\nsource .\/auditsys.ini<br \/>\ncontinue<br \/>\nfi<br \/>\necho &#8220;file:$logstashfile&#8221;<br \/>\nbash \/usr\/share\/logstash\/bin\/logstash -f .\/conf\/$logstashfile<\/p>\n<p>metadatacount=$(bash getInitCount.sh http:\/\/$inithost\/meta-metadata-$initdate\/_count)<br \/>\nif [[ $metadatacount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$inithost\/meta-metadata-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nfi<\/p>\n<p>clickcount=$(bash getInitCount.sh http:\/\/$inithost\/meta-click-$initdate\/_count)<br \/>\nif [[ $clickcount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$inithost\/meta-click-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nfi<\/p>\n<p>sessioncount=$(bash getInitCount.sh http:\/\/$inithost\/meta-session-$initdate\/_count)<br \/>\nif [[ $sessioncount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$inithost\/meta-session-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nfi<\/p>\n<p>infractcount=$(bash getInitCount.sh http:\/\/$inithost\/meta-infract-$initdate\/_count)<br \/>\nif [[ $infractcount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$sourcehost\/meta-infract-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nfi<\/p>\n<p>efficiencycount=$(bash getInitCount.sh http:\/\/$inithost\/meta-efficiency-$initdate\/_count)<br \/>\nif [[ $efficiencycount == &#8220;unknown error&#8221; ]];<br \/>\nthen<br \/>\nsleep 1<br \/>\necho &#8220;curl -s http:\/\/$inithost\/meta-efficiency-$initdate\/_count unknown error&#8221;<br \/>\ncontinue<br \/>\nfi<\/p>\n<p>let &#8220;totalcount=$metadatacount+$sessioncount+$clickcount+$infractcount+$efficiencycount&#8221;<br \/>\necho &#8220;totalcount:$totalcount&#8221;<br \/>\nlet &#8220;totalcount=$totalcount-$iinittotal&#8221;<br \/>\necho &#8220;synctotalcount:$totalcount&#8221;<\/p>\n<p>if [[ &#8220;$totalcount&#8221; == &#8220;$sourcecount&#8221; ]];<br \/>\nthen<\/p>\n<p>echo &#8220;$initdate success,sourcecount:$sourcecount,initcount:$totalcount&#8221;<br \/>\nafterdate=$(date -d &#8220;$initdate -1 day &#8221; +%Y-%m-%d)<br \/>\nafterdate=${afterdate\/\/-0\/-}<br \/>\nsed -i &#8220;s\/enddate=$initdate\/enddate=$afterdate\/g&#8221; auditsys.ini<br \/>\ninitdate=$afterdate<br \/>\ninitdate=${initdate\/\/-0\/-}<br \/>\ninittimes=$(date -d &#8220;$initdate&#8221; +%s)<br \/>\nsource .\/auditsys.ini<\/p>\n<p>else<\/p>\n<p>echo &#8220;error totalcount:$totalcount sourcecount:$sourcecount&#8221;<\/p>\n<p>fi<\/p>\n<p>done<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u95ee\u9898\u7248\u672c\uff1a ES\u5347\u7ea7\u6216\u6570\u636e\u8fc1\u79fb\u65f6\u4f7f\u7528 \u95ee\u9898\u73b0\u8c61\/\u62a5\u9519\uff1a \u4e4b\u524d\u6211\u4eec\u6709\u5f00\u53d1\u63d0\u4f9b\u7684\u5173\u4e8eES\u6570\u636e\u4ece5.6.7\u7248\u672c\u8fc1\u79fb\u5230 [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,15],"tags":[],"class_list":["post-956","post","type-post","status-publish","format-standard","hentry","category-elasticsearch","category-15"],"_links":{"self":[{"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/posts\/956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/comments?post=956"}],"version-history":[{"count":1,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/posts\/956\/revisions"}],"predecessor-version":[{"id":958,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/posts\/956\/revisions\/958"}],"wp:attachment":[{"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/media?parent=956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/categories?post=956"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/learning.sino-vt.com:8988\/index.php\/wp-json\/wp\/v2\/tags?post=956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}