Thanks, Mark! We've chatted quite a bit, I'm kmwilcox_ on Twitter
Here's the log from the data node that wouldn't rejoin -- this set was repeated each time I'd do a
systemctl restart elasticsearch
and I did verify that after "native controller stopped", no elasticsearch processes were running.
[2020-11-05T19:02:38,482][INFO ][o.e.n.Node ] [siemdata15] stopping ...
[2020-11-05T19:02:38,534][INFO ][o.e.x.w.WatcherService ] [siemdata15] stopping watch service, reason [shutdown initiated]
[2020-11-05T19:02:38,689][INFO ][o.e.c.c.Coordinator ] [siemdata15] master node [{geardachadh}{sI-w37AFTASGHuh4-9GVxA}{2wS9KYSfQg-cTg_78sLMJA}{192.168.100.60}{192.168.100.60:9300}{im}{ml.machine_memory=16637517824, ml.max_open_jobs=20, xpack.installed=true}] failed, restarting discovery
org.elasticsearch.transport.NodeDisconnectedException: [geardachadh][192.168.100.60:9300][disconnected] disconnected
[2020-11-05T19:02:38,697][INFO ][o.e.x.m.p.l.CppLogMessageHandler] [siemdata15] [controller/6546] [Main.cc@150] Ml controller exiting
[2020-11-05T19:02:38,700][INFO ][o.e.x.m.p.NativeController] [siemdata15] Native controller process has stopped - no new native processes can be started
[2020-11-05T19:02:38,761][WARN ][o.e.i.s.RetentionLeaseSyncAction] [siemdata15] [itis-windows-desktops-2020.09.24][1] retention lease background sync failed
org.elasticsearch.transport.SendRequestTransportException: [siemdata15][192.168.100.46:9300][indices:admin/seq_no/retention_lease_background_sync[p]]
[2020-11-05T19:02:38,948][WARN ][o.e.i.s.RetentionLeaseSyncAction] [siemdata15] [itis-windows-servers-duo-events-2020.12][3] retention lease background sync failed
org.elasticsearch.transport.SendRequestTransportException: [siemdata15][192.168.100.46:9300][indices:admin/seq_no/retention_lease_background_sync[p]]
[2020-11-05T19:02:39,070][WARN ][o.e.i.s.RetentionLeaseSyncAction] [siemdata15] [itis-windows-desktops-2020.09.18][4] retention lease background sync failed
org.elasticsearch.transport.SendRequestTransportException: [siemdata15][192.168.100.46:9300][indices:admin/seq_no/retention_lease_background_sync[p]]
[2020-11-05T19:02:42,451][INFO ][o.e.n.Node ] [siemdata15] stopped
[2020-11-05T19:02:42,451][INFO ][o.e.n.Node ] [siemdata15] closing ...
[2020-11-05T19:02:42,493][INFO ][o.e.n.Node ] [siemdata15] closed
[2020-11-05T19:06:20,252][INFO ][o.e.e.NodeEnvironment ] [siemdata15] using [1] data paths, mounts [[/var/lib/elasticsearch (/dev/nvme0n1)]], net usable_space [1.3tb], net total_space [2.9tb], types [xfs]
[2020-11-05T19:06:20,256][INFO ][o.e.e.NodeEnvironment ] [siemdata15] heap size [29.8gb], compressed ordinary object pointers [true]
[2020-11-05T19:06:29,102][INFO ][o.e.n.Node ] [siemdata15] node name [siemdata15], node ID [428f6b6dRAup9vP5p6vtkg], cluster name [siem]
[2020-11-05T19:06:29,105][INFO ][o.e.n.Node ] [siemdata15] version[7.3.0], pid[1322], build[default/rpm/de777fa/2019-07-24T18:30:11.767338Z], OS[Linux/3.10.0-1127.19.1.el7.x86_64/amd64], JVM[Oracle Corporation/OpenJDK 64-Bit Server VM/12.0.1/12.0.1+12]
[2020-11-05T19:06:29,105][INFO ][o.e.n.Node ] [siemdata15] JVM home [/usr/share/elasticsearch/jdk]
[2020-11-05T19:06:29,106][INFO ][o.e.n.Node ] [siemdata15] JVM arguments [-Xms30g, -Xmx30g, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -Des.networkaddress.cache.ttl=60, -Des.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true
, -Dio.netty.recycler.maxCapacityPerThread=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.io.tmpdir=/tmp/elasticsearch-8327095790812764947, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/elasticsearch, -XX:ErrorFile=/var/log/elasticsearch/hs_err_pid%p.log, -Xlog:gc*,gc+age=trace,safepoint:file=/var/log/elasticsearch/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -Djava.locale.providers=COMPAT, -Dio.netty.allocator.type=pooled, -
XX:MaxDirectMemorySize=16106127360, -Des.path.home=/usr/share/elasticsearch, -Des.path.conf=/etc/elasticsearch, -Des.distribution.flavor=default, -Des.distribution.type=rpm, -Des.bundled_jdk=true]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [aggs-matrix-stats]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [analysis-common]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [data-frame]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [flattened]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [ingest-common]
[2020-11-05T19:06:30,727][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [ingest-geoip]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [ingest-user-agent]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [lang-expression]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [lang-mustache]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [lang-painless]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [mapper-extras]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [parent-join]
[2020-11-05T19:06:30,728][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [percolator]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [rank-eval]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [reindex]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [repository-url]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [transport-netty4]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [vectors]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-ccr]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-core]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-deprecation]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-graph]
[2020-11-05T19:06:30,729][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-ilm]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-logstash]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-ml]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-monitoring]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-rollup]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-security]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-sql]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-voting-only-node]
[2020-11-05T19:06:30,730][INFO ][o.e.p.PluginsService ] [siemdata15] loaded module [x-pack-watcher]
[2020-11-05T19:06:30,731][INFO ][o.e.p.PluginsService ] [siemdata15] no plugins loaded
[2020-11-05T19:06:33,557][INFO ][o.e.x.s.a.s.FileRolesStore] [siemdata15] parsed [0] roles from file [/etc/elasticsearch/roles.yml]
[2020-11-05T19:06:33,997][INFO ][o.e.x.m.p.l.CppLogMessageHandler] [siemdata15] [controller/5706] [Main.cc@110] controller (64 bit): Version 7.3.0 (Build ff2f774f78ce63) Copyright (c) 2019 Elasticsearch BV
[2020-11-05T19:06:34,300][DEBUG][o.e.a.ActionModule ] [siemdata15] Using REST wrapper from plugin org.elasticsearch.xpack.security.Security
[2020-11-05T19:06:34,562][ERROR][o.e.g.GatewayMetaState ] [siemdata15] failed to read or upgrade local state, exiting...
java.io.IOException: failed to find metadata for existing index ois-duo-admin-2020.02.14 [location: BVqRvM9zSK6KLtHuA6HB_A, generation: 13]
[2020-11-05T19:06:34,569][ERROR][o.e.b.Bootstrap ] [siemdata15] Exception
org.elasticsearch.ElasticsearchException: failed to bind service
at org.elasticsearch.node.Node.<init>(Node.java:617) ~[elasticsearch-7.3.0.jar:7.3.0]
Caused by: java.io.IOException: failed to find metadata for existing index ois-duo-admin-2020.02.14 [location: BVqRvM9zSK6KLtHuA6HB_A, generation: 13]
at org.elasticsearch.gateway.MetaStateService.loadFullState(MetaStateService.java:99) ~[elasticsearch-7.3.0.jar:7.3.0]
[siemdata15] uncaught exception in thread [main]
org.elasticsearch.bootstrap.StartupException: ElasticsearchException[failed to bind service]; nested: IOException[failed to find metadata for existing index ois-duo-admin-2020.02.14 [location: BVqRvM9zSK6KLtHuA6HB_A, generation: 13]];
at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:163) ~[elasticsearch-7.3.0.jar:7.3.0]
[2020-11-05T19:06:34,576][INFO ][o.e.x.m.p.NativeController] [siemdata15] Native controller process has stopped - no new native processes can be started
I've pulled out some of the "at org.elasticsearch. ... " lines because they're repetitive but left the first line of the error. Let me know if I need to do the full java trace.