packetbeat启动
sudo ./packetbeat -e -c sniff_search.yml -strict.perms=false
启动logstash
bin/logstash -f sniff_search.conf
启动生产集群
启动kibana
bin/kibana -e http://127.0.0.1:8200 -p 8601
启动monitor集群
/bin/elasticsearch -Ecluset.name=sniff_search -Ehttp.port=8200 -Epath.data=sniff_search
_cat/indices