Elasticsearch/Kibana 7.9 - Troubleshooting

What is the best way to troubleshoot in Elasticsearch/Kibana to find the root cause why only part of my raw data is getting indexed?

Currently I have Kibana 6.2 and 7.9 in my environment.
While in Kibana 6.2 one of the indexed data has ~40GB in size the same data only shows ~19GB in Kibana 7.9.
I can't find any error in the logs.
It seems that there is some kind of configuration setting the index size limit.
Any suggestion to troubleshoot this is highly appreciated.

How are you sending the data to Elasticsearch?

remotely via SSH

Elasticsearch doesn't accept data via SSH though.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.