I have been using elk stack with metric beats to collect linux systems performance data from 28 servers. For the past few days I am able to get the stats & analyze data.
But today when I login I see the below status in Kibana:
Also I can see that the disk space is full because of the elasticsearch /var/lib/elasticsearch/nodes/0/indices
[root@elk-stack indices]# df -h
Filesystem Size Used Avail Use% Mounted on
/dev/sda3 392G 391G 64M 100% /
devtmpfs 7.8G 0 7.8G 0% /dev
tmpfs 7.8G 0 7.8G 0% /dev/shm
tmpfs 7.8G 116M 7.7G 2% /run
tmpfs 7.8G 0 7.8G 0% /sys/fs/cgroup
/dev/sda3 392G 391G 64M 100% /home
/dev/sda1 1014M 133M 882M 14% /boot
tmpfs 1.6G 0 1.6G 0% /run/user/1000
My questions are below:
I don't need more than 4 days logs. How can I set logrotation mechanism to delete elasticsearch indices older than 3 days?
How to increase the heap size as shown in kibana screenshot?
Could you please provide the information or point me to the link for the documentation related to this?
Thanks in advance.