Kibana 记录
Kibana 大版本已经出到了8.0 ,近期使用Kibana的时候已经加入日志告警 。
[warning] # 从kibana8.0 开始 ,日志格式将会发生变化
Starting in 8.0, the Kibana logging format will be changing. # 新变化可能会影响一些旧的日志处理,比如集成日志到ES进行分析的时候 This may affect you if you are doing any special handling of your Kibana logs, such as ingesting logs into Elasticsearch for further analysis.
# 如果您正在使用新的日志配置,那么您已经接收到旧格式和新格式的日志,旧格式将会消失。 If you are using the new logging configuration, you are already receiving logs in both old and new formats, and the old format will simply be going away. # 如果您还没有使用新的日志配置,升级到8.0 以后日志格式会发生变化 If you are not yet using the new logging configuration, the log format will change upon upgrade to 8.0. # 从8.0开始,JSON日志的格式将是ecs兼容的JSON,并且默认的模式日志格式将与我们的新日志系统进行配置。 有关新日志格式的更多信息,请参阅文档。 Beginning in 8.0, the format of JSON logs will be ECS-compatible JSON, and the default pattern log format will be configurable with our new logging system.
Please refer to the documentation for more information about the new logging format. [warning] # Kibana使用“elastic”用户对Elasticsearch进行身份验证告警。官方建议使用账户TOKEN代替。
Kibana is configured to authenticate to Elasticsearch with the "elastic" user. Use a service account token instead. [warning] # 使用Kibana应用程序权限授予报表权限。“xpack.reporting.roles。
Use Kibana application privileges to grant reporting privileges.
# "xpack.reporting.roles.allow" 授予报表权限已被弃用。() Using "xpack.reporting.roles.allow" to grant reporting privileges is deprecated. # "xpack.reporting.roles.enabled" 未来的版本 默认设置为 false The "xpack.reporting.roles.enabled" setting will default to false in a future release. # 8.0 用户会话空闲8小时自动超时断开,可以根据需求设置 User sessions will automatically time out after 8 hours of inactivity starting in 8.0. Override this value to change the timeout. [warning] # 8.0 用户30天需要重新登陆,可以根据需求设置
Users are automatically required to log in again after 30 days starting in 8.0. Override this value to change the timeout.
[warning][config][plugins][security] # xpack.security.encryptionKey 为32位随机key
Generating a random key for xpack.security.encryptionKey. # 为防止kibana重启 用户会话失效,配置文件增加 xpack.security.encryptionKey 配置;或者 使用 kibana-encryption-keys启动 To prevent sessions from being invalidated on restart,
please set xpack.security.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command. [warning][config][plugins][security] # 官方建议使用https 所以http访问会有告警 Session cookies will be transmitted over insecure connections. This is not recommended. [warning][config][plugins][reporting] Generating a random key for xpack.reporting.encryptionKey.
To prevent sessions from being invalidated on restart,
please set xpack.reporting.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command. [warning][encryptedSavedObjects][plugins] # xpack.encryptedSavedObjects.encryptionKey 未设置,kibaba 部分功能受限
Saved objects encryption key is not set.
This will severely limit Kibana functionality. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command. [warning][actions][plugins]
# API功能关闭; 设置 xpack.encryptedSavedObjects.encryptionKey 启用 APIs are disabled because the Encrypted Saved Objects plugin is missing encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command.
# 官方建议 启动沙箱可以增加保护 [warning][chromium][plugins][reporting] Enabling the Chromium sandbox provides an additional layer of protection. # 启动告警不严重,Kibana会降级启动,服务可用 [info][status] Kibana is now available (was degraded) # [warning][fetcher][plugins][telemetry] Error fetching usage. (Error: Not all collectors are ready.) [info][0][1] [endpoint:metadata-check-transforms-task:0][plugins][securitySolution] no endpoint metadata transforms found