一、Cluster  setting

  1. Cluster

indices.ttl.interval  允许设置多久过期的文件会被自动删除。默认值是60秒。

indices.cache.filter.size  ES的filter cache有两种,一种是node级别的cache(filter cache默认类型),一种是index级别的filter cache。Node级别的cache被整个node共享,并且可以使用百分比设置,对应的属性为index.cache.filter.size,这个属性的值可以使百分比,也可以是具体的大小。Index级别的cache,顾名思义,就是针对单个索引的大小。ES官方并不推荐使用这种设置,因为谁也无法预测索引级别的缓存到底有多大(可能非常大,超过了node的内存),一个索引可能分布在多个node上面,而多个node的结果如果汇总到一个node上,其结果可想而知。默认值是10%。

discovery.zen.minimum_master_nodes        避免脑裂现象(由于某些节点的失效,部分节点的网络连接会断开,并形成一个与原集群一样的集群,这种情况称为集群脑裂现象)discovery.zen.minimum_master_nodes参数决定了要选举一个master需要多少个节点(最少候选节点数)。默认值是1。根据一般经验这个一般设置成N/2+1(向下取整),N是集群中节点的数量。

  1. routing

node_initial_primaries_recoveries  每个初选节点允许控制初始修复的具体数量

cluster_concurrent_rebalance  控制集群宽度允许的分片平衡可以并发多少

awareness.attributes  集群配置意识允许配置分片和副本分配在与节点相关联的通用属性

node_concurrent_recoveries  每个节点上允许多少个并发修复,默认是2

disable_allocation   允许禁用主要分配

disable_replica_allocation   允许禁用副本分配

  1. recovery

concurrent_streams  设置当从对等中恢复碎片时限制打开的并发流的数量 默认5

file_chunk_size  文件块大小  默认512kb



max_bytes_per_sec   设置恢复时每分钟油门的吞吐量  默认20mb

compress  启用压缩为所有节点间的通信   默认禁用

二、Elasticsearch Configuration Example

#####################Elasticsearch Configuration Example #####################

# This file contains an overview of various configuration settings,


# targeted at operations staff. Application developers should

# consult the guide at <http://elasticsearch.org/guide>.


# The installation procedure is covered at

# <http://elasticsearch.org/guide/en/elasticsearch/reference/current/setup.html>.



# Elasticsearch comes with reasonable defaults for most settings,

# so you can try it out without bothering with configuration.



# Most of the time, these defaults are just fine for running a production

# cluster. If you're fine-tuning your cluster, or wondering about the

#  effect of certain configuration option, please _do ask_ on the

# mailing list or IRC channel [http://elasticsearch.org/community].



# Any element in the configuration can be replaced with environment variables

# by placing them in ${...} notation. For example:



#node.rack: ${RACK_ENV_VAR}

# For information on supported formats and syntax for the config file, see




################################### Cluster ###################################

################################## 集群设置###################################

# Cluster name identifies your cluster for auto-discovery. If you're running

# multiple clusters on the same network, make sure you're using unique names.



cluster.name: log-center-it-test


cluster.routing.allocation.disk.watermark.low: "90%"

cluster.routing.allocation.disk.watermark.high: "96%"

indices.fielddata.cache.size: "30%"



#################################### Node #####################################

################################## 节点设置###################################

# Node names are generated dynamically on startup, so you're relieved

# from configuring them manually. You can tie this node to a specific name:



node.name: "ip"

# Every node can be configured to allow or deny being eligible as the master,

# and to allow or deny to store the data.



# Allow this node to be eligible as a master node (enabled by default):



#node.master: true


# Allow this node to store data (enabled by default):



#node.data: true

# You can exploit these settings to design advanced cluster topologies.



# 1. You want this node to never become a master node, only to hold data.

#    This will be the "workhorse" of your cluster.



node.master: false

node.data: true


# 2. You want this node to only serve as a master: to not store any data and

#    to have free resources. This will be the "coordinator" of your cluster.



#node.master: true

#node.data: false


# 3. You want this node to be neither master nor data node, but

#    to act as a "search load balancer" (fetching data from nodes,

#    aggregating results, etc.)



#node.master: false

#node.data: false

# Use the Cluster Health API [http://localhost:9200/_cluster/health], the

# Node Info API [http://localhost:9200/_nodes] or GUI tools

# such as <http://www.elasticsearch.org/overview/marvel/>,

# <http://github.com/karmi/elasticsearch-paramedic>,

# <http://github.com/lukas-vlcek/bigdesk> and

# <http://mobz.github.com/elasticsearch-head> to inspect the cluster state.


# A node can have generic attributes associated with it, which can later be used

# for customized shard allocation filtering, or allocation awareness. An attribute

# is a simple key value pair, similar to node.key: value, here is an example:



#node.rack: rack314

# By default, multiple nodes are allowed to start from the same installation location

# to disable it, set the following:


#node.max_local_storage_nodes: 1


#################################### Index ####################################

# You can set a number of options (such as shard/replica options, mapping

# or analyzer definitions, translog settings, ...) for indices globally,

# in this file.



# Note, that it makes more sense to configure index settings specifically for

# a certain index, either when creating it or by using the index templates API.



#See<http://elasticsearch.org/guide/en/elasticsearch/reference/current/index-modules.html> and


# for more information.

# Set the number of shards (splits) of an index (5 by default):



#index.number_of_shards: 5

# Set the number of replicas (additional copies) of an index (1 by default):



#index.number_of_replicas: 1

# Note, that for development on a local machine, with small indices, it usually

# makes sense to "disable" the distributed features:



#index.number_of_shards: 1

#index.number_of_replicas: 0

# These settings directly affect the performance of index and search operations

# in your cluster. Assuming you have enough machines to hold shards and

# replicas, the rule of thumb is replicas, the rule of thumb is:



# 1. Having more *shards* enhances the _indexing_ performance and allows to

#    _distribute_ a big index across machines.

# 2. Having more *replicas* enhances the _search_ performance and improves the

#    cluster _availability_.




# The "number_of_shards" is a one-time setting for an index.


# "number_of_shards"对一个索引的一次性设置

# The "number_of_replicas" can be increased or decreased anytime,

# by using the Index Update Settings API.



# Elasticsearch takes care about load balancing, relocating, gathering the

# results from nodes, etc. Experiment with different settings to fine-tune

# your setup.


# Use the Index Status API (<http://localhost:9200/A/_status>) to inspect

# the index status.



################################### Paths ####################################

################################# 路径设置##################################

# Path to directory containing configuration (this file and logging.yml):



#path.conf: /path/to/conf

# Path to directory where to store index data allocated for this node.



#path.data: /path/to/data


# Can optionally include more than one location, causing data to be striped across

# the locations (a la RAID 0) on a file level, favouring locations with most free

# space on creation. For example:



#path.data: /path/to/data1,/path/to/data2

# Path to temporary files:



#path.work: /path/to/work

# Path to log files:



#path.logs: /path/to/logs

# Path to where plugins are installed:



#path.plugins: /path/to/plugins


#################################### Plugin ###################################

#################################### 插件 ###################################

# If a plugin listed here is not installed for current node, the node will not start.



#plugin.mandatory: mapper-attachments,lang-groovy


################################### Memory ####################################

################################### 内存 ####################################

# Elasticsearch performs poorly when JVM starts swapping: you should ensure that

# it _never_ swaps.


#当JVM开始启动时,ela执行很差:应该确保它是it _never_ swaps

# Set this property to true to lock the memory:



#bootstrap.mlockall: true

bootstrap.mlockall: true

# Make sure that the ES_MIN_MEM and ES_MAX_MEM environment variables are set

# to the same value, and that the machine has enough memory to allocate

#  for Elasticsearch, leaving enough memory for the operating system itself.



# You should also make sure that the Elasticsearch process is allowed to lock

# the memory, eg. by using `ulimit -l unlimited`.

#应该确保ela过程允许锁定内存,如通过使用`ulimit -l unlimited`

九、Network And HTTP

############################## Network And HTTP ###############################

##############################网络和HTTP设置 ###############################

# Elasticsearch, by default, binds itself to the address, and listens

# on port [9200-9300] for HTTP traffic and on port [9300-9400] for node-to-node

# communication. (the range means that if the port is busy, it will automatically

# try the next port).


# Set the bind address specifically (IPv4 or IPv6):




# Set the address other nodes will use to communicate with this node. If not

# set, it is automatically derived. It must point to an actual IP address.




# Set both 'bind_host' and 'publish_host':




# Set a custom port for the node to node communication (9300 by default):



#transport.tcp.port: 9300

# Enable compression for all communication between nodes (disabled by default):



#transport.tcp.compress: true

# Set a custom port to listen for HTTP traffic:



#http.port: 9200

# Set a custom allowed content length:



#http.max_content_length: 100mb

# Disable HTTP completely:



#http.enabled: false


################################### Gateway ###################################

# The gateway allows for persisting the cluster state between full cluster

# restarts. Every change to the state (such as adding an index) will be stored

# in the gateway, and when the cluster starts up for the first time,

# it will read its state from the gateway.


# There are several types of gateway implementations. For more information, see

# <http://elasticsearch.org/guide/en/elasticsearch/reference/current/modules-gateway.html>.

# The default gateway type is the "local" gateway (recommended):




#gateway.type: local

# Settings below control how and when to start the initial recovery process on

# a full cluster restart (to reuse as much local data as possible when using shared

# gateway).


# Allow recovery process after N nodes in a cluster are up:



#gateway.recover_after_nodes: 1

# Set the timeout to initiate the recovery process, once the N nodes

# from previous setting are up (accepts time value):



#gateway.recover_after_time: 5m

# Set how many nodes are expected in this cluster. Once these N nodes

# are up (and recover_after_nodes is met), begin recovery process immediately

# (without waiting for recover_after_time to expire):



#gateway.expected_nodes: 2


十一、Recovery Throttling

############################# Recovery Throttling #############################

############################# 恢复限流 #############################

# These settings allow to control the process of shards allocation between

# nodes during initial recovery, replica allocation, rebalancing,

# or when adding and removing nodes.


# Set the number of concurrent recoveries happening on a node:



# 1. During the initial recovery



#cluster.routing.allocation.node_initial_primaries_recoveries: 4


# 2. During adding/removing nodes, rebalancing, etc



#cluster.routing.allocation.node_concurrent_recoveries: 2

# Set to throttle throughput when recovering (eg. 100mb, by default 20mb):



#indices.recovery.max_bytes_per_sec: 20mb

# Set to limit the number of open concurrent streams when

# recovering a shard from a peer:



#indices.recovery.concurrent_streams: 5


################################## Discovery ##################################

################################## 发现 ##################################

# Discovery infrastructure ensures nodes can be found within a cluster

# and master node is elected. Multicast discovery is the default.


# Set to ensure a node sees N other master eligible nodes to be considered

# operational within the cluster. This should be set to a quorum/majority of

# the master-eligible nodes in the cluster.


#确保一个节点在集群中和在N个其他有资格的节点中被认为是操作者。#discovery.zen.minimum_master_nodes: 1

# Set the time to wait for ping responses from other nodes when discovering.

# Set this option to a higher value on a slow or congested network

# to minimize discovery failures:




#discovery.zen.ping.timeout: 3s

discovery.zen.ping.timeout: 120s

# For more information, see

# <http://elasticsearch.org/guide/en/elasticsearch/reference/current/modules-discovery-zen.html>

# Unicast discovery allows to explicitly control which nodes will be used

# to discover the cluster. It can be used when multicast is not present,

# or to restrict the cluster communication-wise.



# 1. Disable multicast discovery (enabled by default):



#discovery.zen.ping.multicast.enabled: false


# 2. Configure an initial list of master nodes in the cluster

#    to perform discovery when new nodes (master or data) are started:



#discovery.zen.ping.unicast.hosts: ["host1", "host2:port"]

# EC2 discovery allows to use AWS EC2 API in order to perform discovery.


#EC2发现允许使用AWS WC2 API来执行发现

# You have to install the cloud-aws plugin for enabling the EC2 discovery.



# For more information, see

# <http://elasticsearch.org/guide/en/elasticsearch/reference/current/modules-discovery-ec2.html>


# See <http://elasticsearch.org/tutorials/elasticsearch-on-ec2/>

# for a step-by-step tutorial.

# GCE discovery allows to use Google Compute Engine API in order to perform discovery.



# You have to install the cloud-gce plugin for enabling the GCE discovery.



# For more information, see <https://github.com/elasticsearch/elasticsearch-cloud-gce>.

# Azure discovery allows to use Azure API in order to perform discovery.


#Azure发现允许使用Azure API来执行发现

# You have to install the cloud-azure plugin for enabling the Azure discovery.



# For more information, see <https://github.com/elasticsearch/elasticsearch-cloud-azure>.

十三、Slow Log

################################## Slow Log ##################################

############################ 日志 ##################################

# Shard level query and fetch threshold logging.

#index.search.slowlog.threshold.query.warn: 10s

#index.search.slowlog.threshold.query.info: 5s

#index.search.slowlog.threshold.query.debug: 2s

#index.search.slowlog.threshold.query.trace: 500ms

#index.search.slowlog.threshold.fetch.warn: 1s

#index.search.slowlog.threshold.fetch.info: 800ms

#index.search.slowlog.threshold.fetch.debug: 500ms

#index.search.slowlog.threshold.fetch.trace: 200ms

#index.indexing.slowlog.threshold.index.warn: 10s

#index.indexing.slowlog.threshold.index.info: 5s

#index.indexing.slowlog.threshold.index.debug: 2s

#index.indexing.slowlog.threshold.index.trace: 500ms

################################## GC Logging ################################

#monitor.jvm.gc.young.warn: 1000ms

#monitor.jvm.gc.young.info: 700ms

#monitor.jvm.gc.young.debug: 400ms

#monitor.jvm.gc.old.warn: 10s

#monitor.jvm.gc.old.info: 5s

#monitor.jvm.gc.old.debug: 2s

################################## Security ################################

# Uncomment if you want to enable JSONP as a valid return transport on the

# http server. With this enabled, it may pose a security risk, so disabling

# it unless you need it is recommended (it is disabled by default).


#http.jsonp.enable: true


