I am using ELK stack v6.5.3.
I have a 7 node cluster (5 datanodes [elasticsearch + logstash ] and 2 coordinator nodes [elasticsearch + kibana])
from past some days I am getting below error on one of my logstash nodes [2020-09-21T16:05:50,889][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 429 ({"type"=>"es_rejected_execution_exception", "reason"=>"rejected execution of processing of [142901911][indices:data/write/bulk[s][p]]: request: BulkShardRequest [[indexName-2020.39][0]] containing [5] requests, target allocation id: F50tII90RQuy4HdjO_G6Kw, primary term: 1 on EsThreadPoolExecutor[name = node1/write, queue capacity = 200, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@638276c2[Running, pool size = 8, active threads = 8, queued tasks = 200, completed tasks = 99902900]]"})
There is a lot of gc as well.
I read the below document but not able to figure out the problem. https://www.elastic.co/blog/why-am-i-seeing-bulk-rejections-in-my-elasticsearch-cluster
CPU utilization is also going high for the same node around 98% as an 95 percentile aggregation with a @timestamp bucket of every second.
Also there is a huge lag in the logs , I hope the reason is this only please suggest on this as well.
Please help.
I followed below doc and reduced the heap from 32 to 26 (I think I have given a huge amount for less number of shards following the basic formula of 20 shards per GB of heap , I have around 266 shards per node ) https://www.elastic.co/blog/a-heap-of-trouble#fn4
How many indices and shards are you actively indexing into? How are you indexing into Elasticsearch (what does you Elasticsearch output config in Logstash look like)?
I have around 50 weekly indices and 1 daily index. for the weekly index I have 1 shard and for daily I have 3 shards.
I am simply giving my outputs in output.elasticsearch.
Sorry I can not share the file here.
Do you want ay specific info from that file?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.