<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Elasticsearch on O segundo cérebro de Bryan</title><link>https://bryanalbuquerque.dev/tags/elasticsearch/</link><description>Recent content in Elasticsearch on O segundo cérebro de Bryan</description><generator>Hugo -- gohugo.io</generator><language>pt-BR</language><copyright>Bryan Albuquerque</copyright><lastBuildDate>Tue, 18 Apr 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://bryanalbuquerque.dev/tags/elasticsearch/index.xml" rel="self" type="application/rss+xml"/><item><title>Elasticsearch</title><link>https://bryanalbuquerque.dev/wiki/elasticsearch/</link><pubDate>Tue, 18 Apr 2023 00:00:00 +0000</pubDate><guid>https://bryanalbuquerque.dev/wiki/elasticsearch/</guid><description>&lt;p&gt;&lt;em&gt;You know, for search (and analysis)&lt;/em&gt;&lt;/p&gt;</description><content:encoded><![CDATA[<p><em>You know, for search (and analysis)</em></p>
<h2 id="troubleshoot">Troubleshoot</h2>
<p>Check rápido da saúde do cluster via REST API:</p>





<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="ln">1</span><span class="cl"><span class="nb">export</span> <span class="nv">ENDPOINT</span><span class="o">=</span>localhost:9200
</span></span><span class="line"><span class="ln">2</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_cluster/health?wait_for_status=yellow&amp;timeout=50s&amp;pretty&#34;</span>
</span></span><span class="line"><span class="ln">3</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_cluster/stats?human&amp;pretty&#34;</span>
</span></span><span class="line"><span class="ln">4</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_cluster/pending_tasks&#34;</span>
</span></span><span class="line"><span class="ln">5</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_nodes&#34;</span>
</span></span><span class="line"><span class="ln">6</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_nodes/stats&#34;</span>
</span></span><span class="line"><span class="ln">7</span><span class="cl">curl -X GET <span class="s2">&#34;</span><span class="nv">$ENDPOINT</span><span class="s2">/_cluster/settings?include_defaults=true&amp;flat_settings=true&#34;</span></span></span></code></pre></div><h2 id="elasticsearch-interfaces">Elasticsearch Interfaces</h2>
<p>WebUI:</p>
<ul>
<li>kibana</li>
<li>cerebro</li>
<li>elasticsearch-head</li>
<li>elastic-hq</li>
</ul>
<h2 id="extensões-siem">Extensões SIEM</h2>
<ul>
<li>Elasticsearch Security</li>
<li>Zeek</li>
<li>Wazuh</li>
<li>HELK</li>
<li>Dsiem</li>
<li>S1EM</li>
<li>Pfelk</li>
<li>SIAC</li>
</ul>
<h2 id="referências">Referências</h2>
<ul>
<li><a href="https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html">Elasticsearch Reference - Cluster health</a></li>
<li><a href="https://logz.io/blog/elasticsearch-cheat-sheet/">Logz.io - ES cheat sheet</a></li>
<li><a href="http://elasticsearch-cheatsheet.jolicode.com/">Elasticsearch cheatsheet</a></li>
<li><a href="https://asquera.de/blog/2012-11-25/elasticsearch-pre-flight-checklist/">asquera.de - pre-flight check</a></li>
</ul>]]></content:encoded></item></channel></rss>