elasticsearch-curator: es索引生命周期(关闭、删除索引)

1,下载安装

  • rpm包下载安装
bash 复制代码
# 防止安装rpm包报错:error: [upel]: elasticsearch-curator NOKEY ; 
#                  error: [upel]: elasticsearch-curator signature check fail
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch #参考https://www.elastic.co/guide/en/elasticsearch/reference/7.17/rpm.html

rpm -ivh https://packages.elastic.co/curator/5/centos/7/Packages/elasticsearch-curator-5.8.4-1.x86_64.rpm

2, 配置使用

配置

bash 复制代码
TEST1:/root # cat action.yml
---
actions:
  1:
    action: close
    description: >-
      关闭指定索引,5天前的:test_logstash_
    options:
      skip_flush: False
      delete_aliases: False
      ignore_sync_failures: True
      ignore_empty_list: True
      disable_action: False
    filters:
    - filtertype: pattern
      kind: prefix
      #value: test_logstash_2023_11_12
      value: test_logstash_
    - filtertype: age
      source: name
      direction: older
      #timestring: '%Y.%m.%d'
      timestring: '%Y_%m_%d'
      unit: days
      unit_count: 5

  2:
    action: close
    description: >-
      关闭指定索引,10天前的:^(\w+)_logstash_.*$
    options:
      skip_flush: False
      delete_aliases: False
      ignore_sync_failures: True
      ignore_empty_list: True
      disable_action: False
    filters:
    - filtertype: pattern
      kind: regex
      #value: logstash-
      #value: test_logstash_2023_11_12
      value: '^(\w+)_logstash_.*$'
    - filtertype: age
      source: name
      direction: older
      #timestring: '%Y.%m.%d'
      timestring: '%Y_%m_%d'
      unit: days
      unit_count: 10
      
  3:
    action: delete_indices
    description: >-
      删除过期30天的索引: 按天存储
    options:
      ignore_empty_list: True
      continue_if_exception: True
      disable_action: False
    filters:
    - filtertype: pattern
      kind: regex
      #value: test_logstash_2023_11_12
      value: '^(\w+)_logstash_.*$'
    - filtertype: age
      source: name
      direction: older
      #timestring: '%Y.%m.%d'
      timestring: '%Y_%m_%d'
      unit: days
      unit_count: 31

  4:
    action: delete_indices
    description: >-
      删除过期30天的索引: 按月存储
    options:
      ignore_empty_list: True
      continue_if_exception: True
      disable_action: False
    filters:
    - filtertype: pattern
      kind: regex
      #value: logstash-
      #value: test_logstash_2023_11_12
      value: '^(\w+)_logstash_(\d{4}\S\d{2})$'
    - filtertype: age
      source: name
      direction: older
      #timestring: '%Y.%m.%d'
      timestring: '%Y_%m_%d'
      unit: days
      unit_count: 60

TEST1:/root # cat curator/curatorConfig.yaml 
client:
  hosts:
    - 192.168.0.106
    - 192.168.0.107
    - 192.168.0.108
  port: 9200
  url_prefix:
  use_ssl: False
  certificate:
  client_cert:
  client_key:
  ssl_no_validate: False
  username: elastic
  password: elk123456
  timeout: 60
  master_only: False

logging:
  loglevel: INFO
  logfile: /applog/elk/curator/curator.log
  logformat: default
  blacklist: ['elasticsearch', 'urllib3']

使用

  • curator --config 全局配置文件 action动作配置文件
bash 复制代码
TEST1:/root # curator --config curator/curatorConfig.yaml  action.yml  


TEST1:/root #  tail  /applog/elk/curator/curator.log -f
2024-01-02 11:19:02,339 INFO      Preparing Action ID: 1, "close"
2024-01-02 11:19:02,339 INFO      Creating client object and testing connection
2024-01-02 11:19:02,341 INFO      Instantiating client object
2024-01-02 11:19:02,342 INFO      Testing client connectivity
2024-01-02 11:19:02,345 INFO      Successfully created Elasticsearch client object with provided settings
2024-01-02 11:19:02,348 INFO      Trying Action ID: 1, "close": 关闭指定索引,5天前的:test_logstash_
2024-01-02 11:19:04,088 INFO      Skipping action "close" due to empty list: <class 'curator.exceptions.NoIndices'>
2024-01-02 11:19:04,089 INFO      Action ID: 1, "close" completed.

2024-01-02 11:19:04,089 INFO      Preparing Action ID: 2, "close"
2024-01-02 11:19:04,089 INFO      Creating client object and testing connection
2024-01-02 11:19:04,089 INFO      Instantiating client object
2024-01-02 11:19:04,090 INFO      Testing client connectivity
2024-01-02 11:19:04,095 INFO      Successfully created Elasticsearch client object with provided settings
2024-01-02 11:19:04,097 INFO      Trying Action ID: 2, "close": 关闭指定索引,10天前的:^(\w+)_logstash_.*$
2024-01-02 11:19:04,610 INFO      Closing 30 selected indices: [ 'test_net_logstash_2023_12_15', 'metric_net_logstash_2023_12_16', 'mytest_logstash_2023_12_15',... ]
2024-01-02 11:19:06,240 INFO      Action ID: 2, "close" completed.

2024-01-02 13:49:45,975 INFO      Preparing Action ID: 3, "delete_indices"
2024-01-02 13:49:45,975 INFO      Creating client object and testing connection
2024-01-02 13:49:45,975 INFO      Instantiating client object
2024-01-02 13:49:45,976 INFO      Testing client connectivity
2024-01-02 13:49:45,978 INFO      Successfully created Elasticsearch client object with provided settings
2024-01-02 13:49:45,981 INFO      Trying Action ID: 3, "delete_indices": 删除过期30天的索引
2024-01-02 13:49:46,218 INFO      Deleting 8 selected indices: ['test123_logstash_2023_12_01', 'metric_logstash_2023_12_02', 'monitor_logstash_2023_12_02', ...]
2024-01-02 13:49:46,218 INFO      ---deleting index test123_logstash_2023_12_01
2024-01-02 13:49:46,218 INFO      ---deleting index metric_logstash_2023_12_02
2024-01-02 13:49:46,218 INFO      ---deleting index monitor_logstash_2023_12_02
2024-01-02 13:49:47,475 INFO      Action ID: 3, "delete_indices" completed.

2024-01-02 13:50:49,047 INFO      Trying Action ID: 4, "delete_indices": 删除过期60天的索引: 按月存储
2024-01-02 13:50:49,326 INFO      Deleting 22 selected indices: ['test1_logstash_2023_11', 'test2_logstash_2023_12', 'test3_logstash_2023_11'...]
2024-01-02 13:50:49,326 INFO      ---deleting index test1_logstash_2023_11
2024-01-02 13:50:49,326 INFO      ---deleting index test2_logstash_2023_12
2024-01-02 13:50:49,326 INFO      ---deleting index test3_logstash_2023_11
...
2024-01-02 13:50:56,240 INFO      Job completed.
相关推荐
lilye66几秒前
精益数据分析(55/126):双边市场模式的挑战、策略与创业阶段关联
大数据·人工智能·数据分析
white.tie4 分钟前
Docker部署单节点Elasticsearch
elasticsearch·docker·jenkins
码上地球6 分钟前
因子分析基础指南:原理、步骤与地球化学数据分析应用解析
大数据·数据挖掘·数据分析
胡小禾9 分钟前
ES常识7:ES8.X集群允许4个 master 节点吗
大数据·elasticsearch·搜索引擎
火龙谷1 小时前
【hadoop】Kafka 安装部署
大数据·hadoop·kafka
强哥叨逼叨1 小时前
没经过我同意,flink window就把数据存到state里的了?
大数据·flink
胡小禾2 小时前
ES常识8:ES8.X如何实现热词统计
大数据·elasticsearch·jenkins
appsvip2 小时前
用短说社区搭建的沉浸式生活方式分享平台
大数据·生活
我爱写代码?3 小时前
MapReduce架构-打包运行
大数据·spark
MZWeiei4 小时前
Spark SQL 运行架构详解(专业解释+番茄炒蛋例子解读)
大数据·分布式·sql·架构·spark