# Failed to execute operation for shard

**URL:** <https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992>\
**Category:** Elasticsearch\
**Created:** [April 11, 2016, 12:43pm UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992 "2016-04-11T12:43:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [April 11, 2016, 12:43pm UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/1 "2016-04-11T12:43:12Z")

</div>

I am shipping Windows events including auditing events to Elasticsearch using Winlogbeat. It was woking perfect but as soon as I configured two more file servers, their logs are not being reflected in Kibana. I can confirm through winlogbeat log that events are being shipped.

Here is the Elasticsearch log:

[2016-04-11 15:12:39,090][INFO][node] [TAMUQ-Elastic1] version[2.2.0], pid[14788], build[8ff36d1/2016-01-27T13:32:39Z]  
[2016-04-11 15:12:39,090][INFO][node] [TAMUQ-Elastic1] initializing ...  
[2016-04-11 15:12:39,606][INFO][plugins] [TAMUQ-Elastic1] modules [lang-expression, lang-groovy], plugins [], sites []  
[2016-04-11 15:12:39,622][INFO][env] [TAMUQ-Elastic1] using [1] data paths, mounts [[D2 (e:)]], net usable\_space [17.3tb], net total\_space [17.4tb], spins? [unknown], types [NTFS]  
[2016-04-11 15:12:39,622][INFO][env] [TAMUQ-Elastic1] heap size [15.1gb], compressed ordinary object pointers [true]  
[2016-04-11 15:12:42,747][INFO][node] [TAMUQ-Elastic1] initialized  
[2016-04-11 15:12:42,747][INFO][node] [TAMUQ-Elastic1] starting ...  
[2016-04-11 15:12:43,060][INFO][transport] [TAMUQ-Elastic1] publish\_address {192.195.88.35:9300}, bound\_addresses {192.195.88.35:9300}  
[2016-04-11 15:12:43,075][INFO][discovery] [TAMUQ-Elastic1] TAMUQ-Elasticsearch/yv9Ry8Z8RXGSN\_tXFXK\_xw  
[2016-04-11 15:12:47,154][INFO][cluster.service] [TAMUQ-Elastic1] new\_master {TAMUQ-Elastic1}{yv9Ry8Z8RXGSN\_tXFXK\_xw}{192.195.88.35}{192.195.88.35:9300}, reason: zen-disco-join(elected\_as\_master, [0] joins received)  
[2016-04-11 15:12:47,232][INFO][http] [TAMUQ-Elastic1] publish\_address {192.195.88.35:9200}, bound\_addresses {192.195.88.35:9200}  
[2016-04-11 15:12:47,232][INFO][node] [TAMUQ-Elastic1] started  
[2016-04-11 15:12:48,951][INFO][gateway] [TAMUQ-Elastic1] recovered [104] indices into cluster\_state  
[2016-04-11 15:13:16,359][INFO][cluster.routing.allocation] [TAMUQ-Elastic1] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[winlogbeat-2016.02.18][2], [.kibana][0]] ...]).  
[2016-04-11 15:27:52,977][DEBUG][action.admin.indices.stats] [TAMUQ-Elastic1] [indices:monitor/stats] failed to execute operation for shard [[winlogbeat-fileaudit-2016.04.11][1], node[yv9Ry8Z8RXGSN\_tXFXK\_xw], [P], v[4], s[STARTED], a[id=cZ0p69B\_R0O37lyJfR\_l2A]]  
ElasticsearchException[failed to refresh store stats]; nested: AccessDeniedException[E:\elasticsearch\data\TAMUQ-Elasticsearch\nodes\0\indices\winlogbeat-fileaudit-2016.04.11\1\index\_8qk.fdx];

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 12, 2016, 4:00am UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/2 "2016-04-12T04:00:39Z")

</div>

> [@thyfere](#):
>
> AccessDeniedException

That looks like a permissions issue, I'd check the directory properties.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [April 13, 2016, 7:44am UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/3 "2016-04-13T07:44:39Z")

</div>

But it's working for other file servers.

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [April 13, 2016, 7:55am UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/4 "2016-04-13T07:55:23Z")

</div>

Is there a possibility that Elasticsearch can't handle the quick influx of events? Is yes, how can I optimize Elasticsearch or run diagnostics?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 13, 2016, 8:06am UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/5 "2016-04-13T08:06:20Z")

</div>

Did you check the permissions or are you just asking random questions?

---

<div class="post-metadata">

**Author:** ![thyfere](https://avatars.discourse-cdn.com/v4/letter/t/48db29/32.png) [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Post date:** [April 13, 2016, 8:26am UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/6 "2016-04-13T08:26:56Z")

</div>

Yes, I did check and it's the same as before. What should I check in those permissions or are their any recommended permissions by Elasticsearch?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:59pm UTC](https://discuss.elastic.co/t/failed-to-execute-operation-for-shard/46992/7 "2017-07-05T22:59:42Z")

</div>


