本文主要介绍在安装部署ELK Stack时可能遇到的配置问题导致无法工作的解决方案,从而帮助你快速的排除故障.一般初始化配置导致的问题都是有检查不仔细所致.因此如您的ELK集群出现问题请仔细检查配置文件.
1.升级Kibana4后启动失败
elasticsearch is still initializing the kibana index... trying again in 2.5 second
解决办法:
清除elasticsearch中保存的.kibana索引
curl -XDELETE http://localhost:9200/.kibana
2.nxlog 收集IIS7 Access Log报错
ERROR if-else failed at line 64, character 257 in C:\Program Files (x86)\nxlog\conf\nxlog.conf. statement execution has been aborted; procedure 'parse_csv' failed at line 64, character 152 in C:\Program Files (x86)\nxlog\conf\nxlog.conf. statement execution has been aborted; Too many fields in CSV input, expected 15, got 16 in input '2015-11-19 07:15:10 172.31.1.176 GET .......'
或者
ERROR if-else failed at line 73, character 257 in C:\Program Files (x86)\nxlog\conf\nxlog.conf. statement execution has been aborted; procedure 'parse_csv' failed at line 73, character 152 in C:\Program Files (x86)\nxlog\conf\nxlog.conf. statement execution has been aborted; cannot parse integer, invalid modifier: '/'
解决办法:
在nxlog.conf配置文件中IIS Fields、Field-type必须与日志文件中的字段向匹配,否则会报错。
转载请注明:自动化运维 » ELK 常见错误与解决办法