I just installed elastic search elasticsearch-6.1.3 on RHEL (Red Hat Enterprise Linux Server release 7.4 (Maipo)). I have 2 servers where log stash is installed. I m parsing HTTP server logs successfully. Issue is after some time ES just doesn't do anything. Logstash is still running . I have both logstash running in debug mode and i see log getting updated. ES is up and running and i can do curl
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
yellow open logstash-2018.02.06 NQbQo-QkTdqQhwdsIQpUMw 5 1 12473 0 2.2mb 2.2mb
yellow open logstash-2018.02.04 9W2VRUoZQcW_Gp_pP7V1rQ 5 1 19291 0 2.3mb 2.3mb
yellow open logstash-2018.02.05 chEwnCioTJKZnbq14LrMsw 5 1 8408 0 1.4mb 1.4mb
yellow open logstash-2018.02.03 oExmnZhzQyW9UgqZngD9VQ 5 1 51866 0 6mb 6mb
yellow open .kibana ccvDflniSbSQNFaw3Q8igQ 1 1 2 1 11.3kb 11.3kb
yellow open logstash-2018.02.02 VhhO4YwzSxWhPlfxjFm88w 5 1 11508 0 1.4mb 1.4mb
but line 1 has 12473 documents and it has been like that for 3 hours. Moment i restart ES it changes. I just restarted ES and first line has # docs changed to 18092.
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
yellow open logstash-2018.02.06 NQbQo-QkTdqQhwdsIQpUMw 5 1 18092 0 2.8mb 2.8mb
yellow open logstash-2018.02.04 9W2VRUoZQcW_Gp_pP7V1rQ 5 1 19291 0 2.3mb 2.3mb
yellow open logstash-2018.02.05 chEwnCioTJKZnbq14LrMsw 5 1 8408 0 1.4mb 1.4mb
yellow open logstash-2018.02.03 oExmnZhzQyW9UgqZngD9VQ 5 1 51866 0 6mb 6mb
yellow open .kibana ccvDflniSbSQNFaw3Q8igQ 1 1 2 1 11.3kb 11.3kb
yellow open logstash-2018.02.02 VhhO4YwzSxWhPlfxjFm88w 5 1 11508 0 1.4mb 1.4mb
There is no error in ES logs. I just dont know where to look and what to look
- I m pretty new to to ES *
Raj