I am also receiving this in alert.log on Ubuntu, Wazuh Manager system.
2020 Sep 29 00:12:39 (elasticsearch) any->/var/log/syslog
Rule: 1002 (level 2) -> 'Unknown problem somewhere in the system.'
Sep 29 00:12:29 ElasticSearch logstash[1049]: [2020-09-29T00:12:29,100][WARN ][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"wazuh-alerts-3.x-2020.09.29", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x61e265ff>], :response=>{"index"=>{"_index"=>"wazuh-alerts-3.x-2020.09.29", "_type"=>"_doc", "_id"=>nil, "status"=>400, "error"=>{"type"=>"validation_exception", "reason"=>"Validation Failed: 1: this action would add [1] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}