I have a config of Filebeat sending data to elasticsearch.
Data can be Multiline events or Singleline Events.
After a short period, I notice the following Error in Elasticsearch Log File: Failed to execute pipeline for a bulk
And it gets stuck, not processing any more data, just continuing to output that specific error.
Cluster restart solves it.
Cluster is 5 nodes:
2: Master + Ingest
1: Master + Data
Filebeat is configured to send data to both Ingest Nodes.
I did noticed that when stopping Filebeat from any source server, the problem starts.
Version is 5.0.0 for Filebeat and Elasticsearch.
I have same configuration running on two DC's successfully.
This is a Third DC on which the problem started to occur.
How can I find out what it is the real cause for it ? and Solve it.