Elasticsearch - Not able to see the latest logs

Hi,

Looking for the reason of not having updated logs in the log file.
I did the following sanity tests too,

  • Checked the owner of the process
  • Have enough resources, like memory as well as disk space
  • Log file is generated at the path mentioned at path.logs in elasticsearch.yml

Am I missing anything to validate?

Note: I am running Elasticsearch on the Windows machine.

Thanks,

Hi @chintushah46

Which logs are you talking about the elasticsearch logs? Or some other logs?

If elasticsearch logs, Can you post your elasticsearch.yml? Please format it with the </>button.

How did you install zip it MSI?

Are there any logs at all or just not new logs?

Hi, Stephen, Thanks for your response.

Sorry for not being clear enough on my initial question.

Yes, Elasticsearch logs.
Here is the content of elasticsearch.yml file,

network.host: 0.0.0.0
cluster.routing.allocation.disk.watermark.low: 1gb
cluster.routing.allocation.disk.watermark.high: 512mb
cluster.routing.allocation.disk.watermark.flood_stage: 512mb
cluster.name: domain
node.name: N1
discovery.zen.ping.unicast.hosts: ["N1","N2.domain.com","N3.domain.com"]
path.logs: C:\ProgramData\COMP\YSearch\

I am using OSS version of Elasticsearch, so I have just downloaded the zip file, unzipped it, created the required folders and start the service from bin folder.

Yes, There were logs initially and then it suddenly stopped adding new logs. I restarted Elasticsearch services a few times and every time it was generating logs for few hours and stops again adding new logs.

Note: Elasticsearch version: 6.3.1

Let me know If you need any more details.

Couple things

Why are you setting all the so small, those are incredibly small numbers for disk usage? , plus they are in the wrong order low should be the lowest setting not higher than high and flood_stage.

Also question when the logs stop is elasticsearch still running? Can you still

curl http://localhost:9200

and get a result?

Are you running out of disk space in general?

6.3.1 Is a very old release, but that should not be the issue.

For the QA, I have set with lower numbers. but for the production, I have higher numbers. Thanks for noting the order, I'll correct it.

Yes, Elasticsearch service is running fine. Elasticsearch was doing index, search, etc. operation perfectly fine. It's just the new logs are not being added to the log files.

Not really.

What log level do you have set?
How are looking at the logs?... they do rotate...
Are you looking at the new log file after it rotates?
Perhaps a misconfiguration in the log rotations settings?

Also elastic does not print a lot of logs when things are just static... so are you sure you are actually not getting logs?