elasticsearch 内置 elastic, kibana, logstash_system,beats_system 共4个用户,用途如下:
elastic 账号:内置的超级用户,拥有 superuser 角色。
kibana 账号:用来连接 elasticsearch 并与之通信。Kibana 服务器以该用户身份提交请求以访问集群监视 API 和 .kibana 索引,不能访问 index。
logstash_system 账号:用户 Logstash 在 Elasticsearch 中存储监控信息时使用。
1、elasticsearch-reset-password,设置用户密码
命令:bin/elasticsearch-reset-password -u logstash_system
2、elasticsearch-users 添加用户
#角色列表: roles Known roles: [watcher_admin, apm_system, viewer, logstash_system, rollup_user, kibana_user, beats_admin, remote_monitoring_agent, rollup_admin, snapshot_user, data_frame_transforms_admin, monitoring_user, enrich_user, kibana_admin, logstash_admin, editor, data_frame_transforms_user, machine_learning_user, machine_learning_admin, watcher_user, apm_user, beats_system, transform_user, reporting_user, kibana_system, transform_admin, remote_monitoring_collector, transport_client, superuser, ingest_admin]
#增加授权: #superuser能正常打开es的9200端口,kibana_system配置后才可以正常对接kb和es bin/elasticsearch-users roles -a superuser logadmin
bin/elasticsearch-users roles -a kibana_system logadmin
#移除授权:
bin/elasticsearch-users roles -r kibana_admin logadmin
#查看授权:
bin/elasticsearch-users roles -v logadmin
logadmin : kibana_system,superuser