# Could Not index event to ElasticSearch

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027>\
**Category:** Elasticsearch\
**Created:** [September 25, 2020, 8:39pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027 "2020-09-25T20:39:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 25, 2020, 8:39pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/1 "2020-09-25T20:39:51Z")

</div>

I am new to Elasticsearch, and I had been running Elasticsearch, Kibana, Filebeat, and Zabbix Server.  
My visualization stopped on August 28. I can pull visualization before that just fine. But when I try to watch current visualization. Nothing. I am getting the error  
Could not index event to ElasticSearch.

Can someone advise, as to the first steps to look into. I assume it has to do with an update that took effect.

Thank you in advance.

Deb

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 28, 2020, 3:34am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/2 "2020-09-28T03:34:57Z")

</div>

Welcome to our community! 😃

What do your Elasticsearch logs show?

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 12:19pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/3 "2020-09-28T12:19:44Z")

</div>

I am not very confident in what I am looking for here.  
But this is what I find with a tail -f command.

[2020-09-28T06:25:13,774][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.5gb[11.9%], replicas will not be assigned to this node  
[2020-09-28T06:25:43,836][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.4gb[11.9%], replicas will not be assigned to this node  
[2020-09-28T06:26:13,887][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.4gb[11.8%], replicas will not be assigned to this node  
[2020-09-28T06:26:43,924][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.3gb[11.8%], replicas will not be assigned to this node  
[2020-09-28T06:27:13,981][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.2gb[11.8%], replicas will not be assigned to this node  
[2020-09-28T06:27:44,024][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.3gb[11.8%], replicas will not be assigned to this node  
[2020-09-28T06:28:14,108][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low disk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elasticsearch/nodes/0] free: 18.2gb[11.7%], replicas will not be assigned to this node  
[2020-09-28T06:28:44,147][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] rerouting shards: [one or more nodes has gone under the high or low watermark]

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 12:27pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/4 "2020-09-28T12:27:37Z")

</div>

Logstash logfile:

[2020-09-28T12:24:00,594][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x243c01c7], :response=\>{"index"=\>{"\_index"=\>"wazuh-alerts-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}  
[2020-09-28T12:24:00,594][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x2fa820a8], :response=\>{"index"=\>{"\_index"=\>"wazuh-alerts-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}  
[2020-09-28T12:24:00,598][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-archives-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x7c1544b5], :response=\>{"index"=\>{"\_index"=\>"wazuh-archives-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}  
[2020-09-28T12:24:01,502][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x600ede06], :response=\>{"index"=\>{"\_index"=\>"wazuh-alerts-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}  
[2020-09-28T12:24:01,503][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x2826615c], :response=\>{"index"=\>{"\_index"=\>"wazuh-alerts-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}  
[2020-09-28T12:24:01,504][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09.28", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x3343c290], :response=\>{"index"=\>{"\_index"=\>"wazuh-alerts-3.x-2020.09.28", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 12:37pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/5 "2020-09-28T12:37:02Z")

</div>

Logstash errors on status of logstash running:

[logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09  
Sep 28 12:31:34 ElasticSearch logstash[1049]: [2020-09-28T12:31:34,483][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"wazuh-alerts-3.x-2020.09

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 28, 2020, 9:02pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/6 "2020-09-28T21:02:07Z")

</div>

What is the output from `_cat/nodes?v`?

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 11:28pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/7 "2020-09-28T23:28:05Z")

</div>

What am I typing wrong?  
\_cat/nodes?v ?  
-bash: \_cat/nodes?v: No such file or directory

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 11:38pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/8 "2020-09-28T23:38:20Z")

</div>

I ran it with the curl command with no luck, I am not for sure of the port.  
curl -X GET "localhost:9200/\_cat/nodes?v&pretty"

curl: (7) Failed to connect to localhost port 9200: Connection refused

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 28, 2020, 11:44pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/9 "2020-09-28T23:44:25Z")

</div>

You need to run it against Elasticsearch. If it's not running on localhost, then change to your IP or DNs entry.

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 28, 2020, 11:50pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/10 "2020-09-28T23:50:40Z")

</div>

curl -X Get "XXX.XX.XXX.XXX/\_cat/nodes?v&h=id,ip,port,v,m&pretty"

I then get no answer

It just sits there.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 28, 2020, 11:54pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/11 "2020-09-28T23:54:32Z")

</div>

Sounds like Elasticsearch is having issues then, you may want to check its logs.

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 12:04am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/12 "2020-09-29T00:04:53Z")

</div>

[2020-09-28T00:59:12,777][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low di  
sk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elastic  
search/nodes/0] free: 23.1gb[14.9%], replicas will not be assigned to this node  
[2020-09-28T00:59:42,814][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] rerout  
ing shards: [one or more nodes has gone under the high or low watermark]  
[2020-09-28T01:00:42,915][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low di  
sk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elastic  
search/nodes/0] free: 23.2gb[14.9%], replicas will not be assigned to this node  
[2020-09-28T01:01:12,956][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low di  
sk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elastic  
search/nodes/0] free: 23.2gb[14.9%], replicas will not be assigned to this node  
[2020-09-28T01:01:43,019][INFO][o.e.c.r.a.DiskThresholdMonitor] [node-1] low di  
sk watermark [85%] exceeded on [NfUpB\_9USYOP63RF3NIEmA][node-1][/var/lib/elastic  
search/nodes/0] free: 23.2gb[14.9%], replicas will not be assigned to this node

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 12:05am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/13 "2020-09-29T00:05:13Z")

</div>

this is what I find in the elasticsearch log

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 12:05pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/14 "2020-09-29T12:05:50Z")

</div>

Any other thoughts what to check on ? Reinstall Elasticsearch?

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 12:11pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/15 "2020-09-29T12:11:58Z")

</div>

When I do a status of elasticsearch, the state is at a degraded status?  
Please help.

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 12:52pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/16 "2020-09-29T12:52:32Z")

</div>

"name" : "node-1",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "HgSWRRDZR76gW2a6NJjANg",  
"version" : {  
"number" : "7.5.1",  
"build\_flavor" : "default",  
"build\_type" : "deb",  
"build\_hash" : "3ae9ac9a93c95bd0cdc054951cf95d88e1e18d96",  
"build\_date" : "2019-12-16T22:57:37.835892Z",  
"build\_snapshot" : false,  
"lucene\_version" : "8.3.0",  
"minimum\_wire\_compatibility\_version" : "6.8.0",  
"minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
},  
"tagline" : "You Know, for Search"

thoughts, does Elasticsearch look ok?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 29, 2020, 2:10pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/17 "2020-09-29T14:10:30Z")

</div>

It looks like you are running low on disk space according to the logs.

Is it something in production? Or you are just testing?

If the later, could you please restart elasticsearch and share the full logs?

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 6:19pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/18 "2020-09-29T18:19:02Z")

</div>

Here is what is located after a restart of Elasticsearch: (I am still receiving no data on Kibana since 8.30.2020) But I can view data prior to that date.

020-09-29T17:50:47,342][INFO][o.e.c.m.MetaDataIndexTemplateService] [node-1]  
adding template [wazuh-agent] for index patterns [wazuh-monitoring-3.x-\*]  
[2020-09-29T17:50:50,533][INFO][o.e.c.r.a.AllocationService] [node-1] Cluster h  
ealth status changed from [RED] to [GREEN] (reason: [shards started [[.kibana\_ta  
sk\_manager\_1][0]]]).'

---

<div class="post-metadata">

**Author:** ![dhoman](https://avatars.discourse-cdn.com/v4/letter/d/3d9bf3/32.png) [@dhoman](https://discuss.elastic.co/u/dhoman)\
**Post date:** [September 29, 2020, 6:47pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/19 "2020-09-29T18:47:32Z")

</div>

I am also receiving this in alert.log on Ubuntu, Wazuh Manager system.

```
2020 Sep 29 00:12:39 (elasticsearch) any->/var/log/syslog
Rule: 1002 (level 2) -> 'Unknown problem somewhere in the system.'
Sep 29 00:12:29 ElasticSearch logstash[1049]: [2020-09-29T00:12:29,100][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"wazuh-alerts-3.x-2020.09.29", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x61e265ff>], :response=>{"index"=>{"_index"=>"wazuh-alerts-3.x-2020.09.29", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"validation_exception", "reason"=>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 29, 2020, 7:10pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027/20 "2020-09-29T19:10:36Z")

</div>

Can you please provide us with the full output of the [cluster stats API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-stats.html)?

[Next page](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/250027.md?page=2)
