Debian上配置Filebeat的网络安全
一 基础加固
二 传输加密 TLS
output.elasticsearch:
hosts: ["https://es.example.com:9200"]
username: "filebeat_writer"
password: "<强口令或从凭据存储读取>"
ssl.enabled: true
ssl.certificate_authorities: ["/etc/filebeat/pki/tls/certs/ca.crt"]
ssl.certificate: "/etc/filebeat/pki/tls/certs/filebeat.crt"
ssl.key: "/etc/filebeat/pki/tls/private/filebeat.key"
ssl.verification_mode: full
三 网络访问控制
四 认证与授权
五 运行监控与维护
logging.level: info
logging.to_files: true
logging.files:
path: /var/log/filebeat
name: filebeat
keepfiles: 7
permissions: 0644