# Maximum normal shards open achived

**URL:** <https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529>\
**Category:** Elasticsearch\
**Created:** [July 28, 2023, 10:39am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529 "2023-07-28T10:39:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patryk\_Ostrowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patryk_ostrowski/32/111965_2.png) [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Post date:** [July 28, 2023, 10:39am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/1 "2023-07-28T10:39:17Z")

</div>

Hello, I have one node ELK, I know that is not the best solution, but I cannot change that. I put logs to ELK, and every day I have new index for example: alerts-2023-07-23. But after few months of working filebeat showed me error that maximum open shard is achived. Could you explain me what is the best solution in this case. It is possible that I join all of this indexes (one month) to one index?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 28, 2023, 12:28pm UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/2 "2023-07-28T12:28:23Z")

</div>

You could index reindex to one single shard. But in most recent versions, I think that using [data streams](https://www.elastic.co/guide/en/elasticsearch/reference/current/data-streams.html) is much better and efficient.

What is the output of:

```auto
GET /
GET /_cat/nodes?v
GET /_cat/health?v
GET /_cat/indices?v

```

If some outputs are too big, please share them on [gist.github.com](http://gist.github.com) and link them here.

---

<div class="post-metadata">

**Author:** ![Patryk\_Ostrowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patryk_ostrowski/32/111965_2.png) [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Post date:** [July 28, 2023, 1:13pm UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/3 "2023-07-28T13:13:16Z")

</div>

Thanks for anserw. Unfortunately the problem appear in indexes generated by Wazuh, so probably I don't have possibility to use better option like data stream. It is possible to reindex automatically it every month? Below I attach the output: [log.txt · GitHub](https://gist.github.com/PatrykWAT/bfa68c7f393683bd6c320c55f7e7b929)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 28, 2023, 2:11pm UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/4 "2023-07-28T14:11:15Z")

</div>

Looking at the indices info, you are wasting plenty of resources by oversharding.  
You should have only one shard per index instead of 3 sometimes.  
Also, some indices are super small which is indeed inefficient.

I'd ask Wazuh to change their settings and use datastreams. But in the meantime, I suppose that wazuh is generating an index template. May be you can change it and set the number of primary shard to 1.

Then you could reindex your data and squeeze them into one bigger index and shard.

> It is possible to reindex automatically it every month?

Not automatically, no but you can probably write a simple cron script for that.

May be you can configure Wazuh to use an alias instead of an index by day? And then use the [rollover API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-rollover-index.html)?

---

<div class="post-metadata">

**Author:** ![Patryk\_Ostrowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patryk_ostrowski/32/111965_2.png) [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Post date:** [July 31, 2023, 8:25am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/5 "2023-07-31T08:25:24Z")

</div>

I found options to change that in Wazuh (alerts - in pipeline, monitoring and statistics in Wazuh option). Moreover I reindexed this indexes and created one index with past data, new data will be create indexes per month. Also I changed number of primary shards to one.

I am grateful for the help, thank you.

If I think about auto jobs my idea is create job that will join indexes (that now is created per month) to groups that have 50GB of data. It is good idea?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 31, 2023, 8:30am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/6 "2023-07-31T08:30:30Z")

</div>

> [@Patryk\_Ostrowski](#):
>
> If I think about auto jobs my idea is create job that will join indexes (that now is created per month) to groups that have 50GB of data. It is good idea?

If you have one or a few monthly indices with a single primary shard I would expect the shard count to be managable, so I do not think this is required nor adds much value.

---

<div class="post-metadata">

**Author:** ![Patryk\_Ostrowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patryk_ostrowski/32/111965_2.png) [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Post date:** [July 31, 2023, 9:10am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/7 "2023-07-31T09:10:58Z")

</div>

thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2023, 9:11am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529/8 "2023-08-28T09:11:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
