Possible Issues and Solutions in Elasticsearch
Problem | Elasticsearch stopping log writing due to disk space full on Elasticsearch servers. |
---|---|
Reason/Cause | When Elasticsearch is installed with default settings, it issues a warning when the disk reaches 85% full and stops log writing when it reaches 90%. |
Solution | Free up space on the disk or resize the disk. After this operation, the following command should be used to indicate that the disk is ready for writing again.
|
Additional Suggestion | This situation can lead to a significant amount of unused space on large disks, so it is recommended to customize it for your servers. These limits can be updated either as a percentage or directly with a numerical value. Setting the disk size with a numerical limit:
Setting the disk size with a percentage limit:
|
Problem | Error in log searches in Kibana: "x of y shards failed: The data you are seeing might be incomplete or wrong. The length of [X] field of [Y] doc of [<INDEX_NAME>] index has exceeded [1000000] - maximum allowed to be analyzed for highlighting." |
---|---|
Reason/Cause | The default limit for the data size that Elasticsearch can perform highlighting for each record is 1.000.000 characters. This limit is set by Elasticsearch for optimal JVM RAM usage and search speed. |
Solution | This setting can be increased with the following command. If you don't know the size of your data, it is recommended to gradually increase this value to set a limit suitable for your data. curl -XPUT " "index" : { "highlight.max_analyzed_offset" : 2000000 } }' |
Problem | Warning of "Request cannot be executed; I/O reactor status: STOPPED" on Api Traffic pages with no logs |
---|---|
Reason/Cause | It is necessary to increase the RAM limits used by Elasticsearch. |
Solution | This setting can be increased from the jvm.options file. It is recommended not to exceed half of the total amount of system RAM. sudo vi /opt/elasticsearch/elasticsearch-7.9.2/config/jvm.options -Xms8g systemctl restart elasticsearch |
Problem | Elasticsearch exception [type=validation_exception, reason=Validation Failed: 1: this action would add [2] total shards, but this cluster currently has [1000]/[1000] maximum shards open;] |
---|---|
Reason/Cause | You are reaching the limit cluster.max_shards_per_node. Add more data node, reduce the number of shards in cluster or increase the shard limit on the system. |
Solution | The correct solution to this problem is increasing the data node amount. |
Alternative Solution | Since increasing the data nodes may not always be possible, manual management to the shards is also an usable solution. To do this, following commands can be used.
curl http://<ELASTICSEARCH_IP>:9200/apinizer-log-apiproxy-<INDEX_KEY>/_rollover |
Alternative Solution | If both previous solutions may not be applicable, the latest resort is to clear/delete old indices which is NOT RECOMMENDED since it will cause the loss on old logs. curl -XDELETE http://<ELASTICSEARCH_IP>:9200/apinizer-log-apiproxy-<INDEX_KEY>-<INDEX_NUMBER>/_rollover |
Problem | UnassignedShards-CLUSTER-RECOVERED |
---|---|
Solution | Bu sorunun birden fazla çözümü olabilir. Tüm elasticsearch node'larının çalıştığından ve dosya kaybı olmadığından emin olunması gerekmektedir. |
Since increasing the data nodes may not always be possible, manual management to the shards is also an usable solution. To do this, following commands can be used.
curl http://<ELASTICSEARCH_IP>:9200/apinizer-log-apiproxy-<INDEX_KEY>/_rollover | |
Problem | UnassignedShards-CLUSTER-RECOVERED |
---|---|
Solution | There may be more than one solution to this problem. It is necessary to ensure that all elasticsearch nodes are running and that there is no file loss. |
Alternative Solution |
The status of nodes, clusters and shards is checked with the following commands. curl "<ELASTICSEARCH_IP>:9200/_nodes" curl "<ELASTICSEARCH_IP>:9200/_cluster/allocation/explain" curl "<ELASTICSEARCH_IP>:9200/_cat/shards?v=true&h=index,shard,prirep,state,node,unassigned.reason&s=state" #The following command will reactivate the sharing on the nodes. curl -XPUT "<ELASTICSEARCH_IP>:9200/_cluster/settings?pretty" -H 'Content-Type: application/json' -d' { "transient" : { "cluster.routing.allocation.enable": true } }'
curl -XPOST "<ELASTICSEARCH_IP>:9200/_cluster/reroute?retry_failed=true&pretty" |
Reason/Cause |
|
Problem | Access error in mounting the disk connected with Nas |
---|---|
Reason/Cause | When trying to connect to a NAS disk, file system access permissions need to be set. |
Solution | #nas disk: //192.168.111.248/LogApinizer
uid=1000(elasticsearch) gid=1000(elasticsearch) groups=1000(elasticsearch),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),101(lxd) #To mount the NAS disk, mount it with the following command by giving the appropriate authorizations. sudo mount -t cifs -o rw,uid=1000,gid=1000,file_mode=0755,dir_mode=0755,username=elasticsearch,password=1234 //192.168.111.248/LogApinizer /home/data/ #To make the mount permanent, we add the following lines to the fstab file. vi /etc/fstab //192.168.111.248/LogApinizer /home/data cifs rw,uid=1000,gid=1000,file_mode=0755,dir_mode=0755,username=elasticsearch,password=1234 0 0 |