Shards Failed

(Jim) #1

I have created a Data Table Visualization that gives me the "" for 4 Windows servers running Metricbeat 6.5.4. Unfortunately, no matter what timeframe I query, I get "20 Shards out of X Failed" in Kiabana.

My Agents are Windows, my Elasticsearch cluster is 3 RHEL Master nodes with 1 RHEL Logstash Server, and 1 RHEL Kibana Web server with a Coordinating Only node installed. Everything is running 6.5.4.

When I installed everything I loaded the default Metricbeat setup configuration from the agent using ".\metricbeat.exe setup -e -E output.logstash.enabled=false -E output.elasticsearch.hosts=['localhost:9200'] -E" because I am a Logstash user. I don't have xpac installed.

Whenever I get the "20 Shards out of X Failed" message, I see in the Coordinating Nodes logs ...

Caused by: java.lang.IllegalArgumentException: Fielddata is disabled on text fields by default. Set fielddata=true on [beat.hostname] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.
at org.elasticsearch.index.mapper.TextFieldMapper$TextFieldType.fielddataBuilder( ~[elasticsearch-6.5.4.jar:6.5.4]
at org.elasticsearch.index.fielddata.IndexFieldDataService.getForField( ~[elasticsearch-6.5.4.jar:6.5.4]
at org.elasticsearch.index.query.QueryShardContext.getForField( ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at$ ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at$100( ~[elasticsearch-6.5.4.jar:6.5.4]
at$2.onResponse( ~[elasticsearch-6.5.4.jar:6.5.4]
at$2.onResponse( ~[elasticsearch-6.5.4.jar:6.5.4]
at$4.doRun( ~[elasticsearch-6.5.4.jar:6.5.4]
at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun( ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at org.elasticsearch.common.util.concurrent.TimedRunnable.doRun( ~[elasticsearch-6.5.4.jar:6.5.4]
at ~[elasticsearch-6.5.4.jar:6.5.4]
at java.util.concurrent.ThreadPoolExecutor.runWorker( ~[?:1.8.0_191]
at java.util.concurrent.ThreadPoolExecutor$ ~[?:1.8.0_191]
at [?:1.8.0_191]

My logstash output configuration is as follows ....

output {
elasticsearch {
hosts => ["localhost1:9200", "localhost2:9200", "localhost3:9200"]
manage_template => false
index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

Through previous experimentation and learning, I've found that if I don't have the index template installed properly, I do, I get strange mapping issues and ".keyword" fields created for everything. But this time around, I've done all that. What I've noticed this time around is no ".keyword" fields have been created for aggregation use in my Visualizations. Which I believe what is causing my error because By Default field data is not turned on (and I don't want it turned on) and no ".keyword" fields are being created by the Metricbeat template in the index.

  • On a side node, Filebeat and Winglog beat act the same way, no ".keyword" fields for aggregation but I don't get the Shard error with them.
  • All of my indices don't have unassigned Shards.
  1. So, HOW do I turn ".keyword"s on so I can use aggregation in my Visualization properly?
    Oddly enough, I am getting the Uptime, I just get this error for some reason.
  2. OR, how do make this error go away?


(ruflin) #2

I assume what happens on your side is that you have indices now without the mapping and with the mapping as the template only applies to new indices. Could you try to delete the existing indices, apply the template and then start loading the data?

You mention x-pack above: How is this related to all this?

(system) closed #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.