Hey, recently i had a problem with elasticsearch where all shards were with RED flag. So i deleted everything from ES, deleted registry of filebeat and restarted everything.
Right now the data is not being indexed in ES, i checked the registry file of filebeat and it shows all files opened but with offset as 0 in all files.
What can be causing this?
EDIT: Also there is no filebeat log file generated as before.
Dont know why but when i tried to run logstash directly from bin folder instead of running it as a service it worked. This is so weird.
EDIT: Back to square one, i reinstalled ES, LS and FileBeat, started working good, got to a moment where it stopped processing logs. Again, deleted everything, restarted and now back to not processing anything
can someone please help me?
EDIT2:
OK, so i found out that if i stop one specific filebeat prospector, everything works ok. This prospector in specific is harvesting a 5GB log file, any chance this is breaking ELK?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.