# Смена состояние кластера после запроса

**URL:** <https://discuss.elastic.co/t/topic/170306>\
**Category:** Вопросы на русском языке\
**Created:** [February 28, 2019, 9:49am UTC](https://discuss.elastic.co/t/topic/170306 "2019-02-28T09:49:01Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [February 28, 2019, 9:49am UTC](https://discuss.elastic.co/t/topic/170306/1 "2019-02-28T09:49:01Z")

</div>

Добрый день ! Пожалуйста помогите разобраться, сегодня 2 ноды моего кластера потеряли друг друга и кластер стал не операбелен. Ниже часть лога до и во время события:

```
[2019-02-28T09:43:52,747][DEBUG][o.e.a.s.TransportSearchAction] [elastic-hot] [graylog_608][3], node[euwPHAKwQLOLNfx0fps02g], [P], s[STARTED], a[id=d8Bhiy6fQeWnz0BTErc__g]: Failed to execute [SearchRequest{searchType=QUERY_THEN_FETCH, indices=[graylog_608, graylog_609], indicesOptions=IndicesOptions[id=38, ignore_unavailable=false, allow_no_indices=true, expand_wildcards_open=true, expand_wildcards_closed=false, allow_alisases_to_multiple_indices=true, forbid_closed_indices=true], types=[message], routing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=10, batchedReduceSize=512, preFilterShardSize=64, source={
[2019-02-28T09:43:52,755][DEBUG][o.e.a.s.TransportSearchAction] [elastic-hot] [graylog_609][3], node[euwPHAKwQLOLNfx0fps02g], [P], s[STARTED], a[id=_eLHFO5qSeihsSPWdUL8UA]: Failed to execute [SearchRequest{searchType=QUERY_THEN_FETCH, indices=[graylog_608, graylog_609], indicesOptions=IndicesOptions[id=38, ignore_unavailable=false, allow_no_indices=true, expand_wildcards_open=true, expand_wildcards_closed=false, allow_alisases_to_multiple_indices=true, forbid_closed_indices=true], types=[message], routing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=10, batchedReduceSize=512, preFilterShardSize=64, source={
[2019-02-28T09:43:52,757][DEBUG][o.e.a.s.TransportSearchAction] [elastic-hot] All shards failed for phase: [query]
[2019-02-28T09:43:58,825][INFO][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][58996] overhead, spent [251ms] collecting in the last [1s]
[2019-02-28T09:44:27,127][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T09:44:43,845][INFO][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][59041] overhead, spent [420ms] collecting in the last [1s]
[2019-02-28T09:45:27,130][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T09:45:30,320][INFO][o.e.c.r.a.AllocationService] [elastic-hot] Cluster health status changed from [GREEN] to [RED] (reason: []).
[2019-02-28T09:45:30,321][INFO][o.e.c.s.ClusterService] [elastic-hot] removed {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-failed({elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}), reason(failed to ping, tried [3] times, each with maximum [30s] timeout)
[2019-02-28T09:45:31,338][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T09:45:31,339][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T09:45:31,347][INFO][o.e.c.r.DelayedAllocationService] [elastic-hot] scheduling reroute for delayed shards in [58.8s] (64 delayed shards)
[2019-02-28T09:45:53,089][INFO][o.e.c.s.ClusterService] [elastic-hot] added {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-join
[2019-02-28T09:46:23,109][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [82] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T09:46:23,156][WARN][o.e.d.z.ElectMasterService] [elastic-hot] value for setting "discovery.zen.minimum_master_nodes" is too low. This can result in data loss! Please set it to at least a quorum of master-eligible nodes (current value: [1], total number of master-eligible nodes used for publishing in this round: [2])
[2019-02-28T09:46:23,157][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [zen-disco-node-join] took [30s] above the warn threshold of 30s
[2019-02-28T09:46:53,173][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [83] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T09:46:53,253][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [cluster_reroute(async_shard_fetch)] took [30s] above the warn threshold of 30s
[2019-02-28T09:47:46,578][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T09:47:51,214][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [86] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T09:47:51,348][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [shard-started shard id [[graylog_605][2]], allocation id [GpHfybP4T4O-SdUhuRJSwA], primary term [0], message [after existing recovery], shard-started shard id [[graylog_605][0]], allocation id [PkQ1r-llQcW5KbHChhZvRQ], primary term [0], message [after existing recovery], shard-started shard id [[graylog_605][2]], allocation id [GpHfybP4T4O-SdUhuRJSwA], primary term [0], message [master {elastic-hot}{euwPHAKwQLOLNfx0fps02g}{hlIxMvyMTxO1wrpiZG4ymA}{192.168.150.109}{192.168.150.109:9300}{box_type=hot} marked shard as initializing, but shard state is [POST_RECOVERY], mark shard as started], shard-started shard id [[graylog_605][1]], allocation id [gwhVa9NbQ0eHa9TPpakI1A], primary term [0], message [after existing recovery], shard-started shard id [[graylog_605][1]], allocation id [gwhVa9NbQ0eHa9TPpakI1A], primary term [0], message [master {elastic-hot}{euwPHAKwQLOLNfx0fps02g}{hlIxMvyMTxO1wrpiZG4ymA}{192.168.150.109}{192.168.150.109:9300}{box_type=hot} marked shard as initializing, but shard state is [POST_RECOVERY], mark shard as started], shard-started shard id [[graylog_605][0]], allocation id [PkQ1r-llQcW5KbHChhZvRQ], primary term [0], message [master {elastic-hot}{euwPHAKwQLOLNfx0fps02g}{hlIxMvyMTxO1wrpiZG4ymA}{192.168.150.109}{192.168.150.109:9300}{box_type=hot} marked shard as initializing, but shard state is [POST_RECOVERY], mark shard as started]] took [30.1s] above the warn threshold of 30s
```

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [February 28, 2019, 3:36pm UTC](https://discuss.elastic.co/t/topic/170306/2 "2019-02-28T15:36:44Z")

</div>

```auto
[2019-02-28T09:44:43,845][INFO][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][59041] overhead, spent [420ms] collecting in the last [1s]

```

Скорее всего нехватка памяти. Что было с heap-ом в момент отказа?

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 1, 2019, 3:57am UTC](https://discuss.elastic.co/t/topic/170306/3 "2019-03-01T03:57:51Z")

</div>

Вообщем там 24 гигабайта памяти на сервере, heap не смотрел на момент отказа. Как-то по старому логу его можно найти сейчас ?

По логу нашел только это:

```
sysadmin@elastic-hot:~$ grep "heap" /var/log/elasticsearch/graylog-2019-02-28.log 
[2019-02-28T10:29:35,576][INFO][o.e.e.NodeEnvironment] [elastic-hot] heap size [11.8gb], compressed ordinary object pointers [true]
[2019-02-28T10:52:46,794][INFO][o.e.e.NodeEnvironment] [elastic-hot] heap size [11.8gb], compressed ordinary object pointers [true]
```

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 1, 2019, 3:20pm UTC](https://discuss.elastic.co/t/topic/170306/4 "2019-03-01T15:20:24Z")

</div>

А что в логе следует перед этими строками? Эти строки обычно появляются, когда узел перестартовывает. Причину перестартовки можно часто найти перед информацией о старте узла.

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 4, 2019, 3:55am UTC](https://discuss.elastic.co/t/topic/170306/5 "2019-03-04T03:55:28Z")

</div>

Подскажите а как смотреть сосояние heap в момент отказа вообщем ?

Лог перед перезапуском, перезапуск делался вручную для того чтобы хот нода нашла варм ноду:

```
[2019-02-28T10:21:54,627][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:22:53,481][INFO][o.e.c.s.ClusterService] [elastic-hot] removed {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-failed({elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}), reason(failed to ping, tried [3] times, each with maximum [30s] timeout)
[2019-02-28T10:22:54,353][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:22:54,353][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:22:54,355][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:22:54,356][INFO][o.e.c.r.DelayedAllocationService] [elastic-hot] scheduling reroute for delayed shards in [59s] (61 delayed shards)
[2019-02-28T10:23:30,131][INFO][o.e.c.s.ClusterService] [elastic-hot] added {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-join
[2019-02-28T10:24:00,152][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [132] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T10:24:00,198][WARN][o.e.d.z.ElectMasterService] [elastic-hot] value for setting "discovery.zen.minimum_master_nodes" is too low. This can result in data loss! Please set it to at least a quorum of master-eligible nodes (current value: [1], total number of master-eligible nodes used for publishing in this round: [2])
[2019-02-28T10:24:00,198][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [zen-disco-node-join] took [30s] above the warn threshold of 30s
[2019-02-28T10:24:30,202][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [133] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T10:24:30,238][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [delayed_allocation_reroute] took [30s] above the warn threshold of 30s
[2019-02-28T10:26:10,314][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:26:14,086][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [139] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T10:26:14,536][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [shard-started shard id [[graylog_603][1]], allocation id [pSgqhJC_Qk25OJABSt2faw], primary term [0], message [master {elastic-hot}{euwPHAKwQLOLNfx0fps02g}{hlIxMvyMTxO1wrpiZG4ymA}{192.168.150.109}{192.168.150.109:9300}{box_type=hot} marked shard as initializing, but shard state is [POST_RECOVERY], mark shard as started], shard-started shard id [[graylog_603][1]], allocation id [pSgqhJC_Qk25OJABSt2faw], primary term [0], message [after existing recovery]] took [30.4s] above the warn threshold of 30s
[2019-02-28T10:27:10,320][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:27:14,388][INFO][o.e.c.s.ClusterService] [elastic-hot] removed {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-failed({elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}), reason(failed to ping, tried [3] times, each with maximum [30s] timeout)
[2019-02-28T10:27:14,586][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:27:14,586][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:27:14,586][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elastic-hot] failed to execute [indices:monitor/stats] on node [vMZI77LoTyuHlEH-xVvJJQ]
[2019-02-28T10:27:14,593][INFO][o.e.c.r.DelayedAllocationService] [elastic-hot] scheduling reroute for delayed shards in [59.7s] (13 delayed shards)
[2019-02-28T10:27:42,300][INFO][o.e.c.s.ClusterService] [elastic-hot] added {{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm},}, reason: zen-disco-node-join
[2019-02-28T10:28:05,445][INFO][o.e.n.Node] [elastic-hot] stopping ...
[2019-02-28T10:28:12,322][WARN][o.e.d.z.PublishClusterStateAction] [elastic-hot] timed out waiting for all nodes to process published state [142] (timeout [30s], pending nodes: [{elastic-warm}{vMZI77LoTyuHlEH-xVvJJQ}{hIKLM1muRAOjZEbfWjNYaA}{192.168.150.108}{192.168.150.108:9300}{box_type=warm}])
[2019-02-28T10:28:12,354][WARN][o.e.d.z.ElectMasterService] [elastic-hot] value for setting "discovery.zen.minimum_master_nodes" is too low. This can result in data loss! Please set it to at least a quorum of master-eligible nodes (current value: [1], total number of master-eligible nodes used for publishing in this round: [2])
[2019-02-28T10:28:12,354][WARN][o.e.c.s.ClusterService] [elastic-hot] cluster state update task [zen-disco-node-join] took [30s] above the warn threshold of 30s
[2019-02-28T10:28:12,378][DEBUG][o.e.a.a.c.n.s.TransportNodesStatsAction] [elastic-hot] failed to execute on node [vMZI77LoTyuHlEH-xVvJJQ]
```

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 4, 2019, 4:01am UTC](https://discuss.elastic.co/t/topic/170306/6 "2019-03-04T04:01:07Z")

</div>

Заметил что после запуска появляються строки, что они значат ?

[2019-02-28T10:31:52,569][INFO][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][122] overhead, spent [807ms] collecting in the last [1.7s]  
[2019-02-28T10:36:15,737][WARN][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][385] overhead, spent [584ms] collecting in the last [1s]  
[2019-02-28T10:43:03,977][INFO][o.e.m.j.JvmGcMonitorService] [elastic-hot] [gc][793] overhead, spent [358ms] collecting in the last [1s]

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 4, 2019, 2:31pm UTC](https://discuss.elastic.co/t/topic/170306/7 "2019-03-04T14:31:16Z")

</div>

Эти строки значат, что у вас узел 50% времени проводит в GC?, что, в свою очередь, означает, что этот узел перегружен каким-то образом (может быть нехватка памяти, процессор занят или что-то еще). Надо смотреть на [stats](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-stats.html).

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 5, 2019, 4:12am UTC](https://discuss.elastic.co/t/topic/170306/8 "2019-03-05T04:12:28Z")

</div>

Сохранил вывод [https://pastebin.com/FDzXTg8b](https://pastebin.com/FDzXTg8b)

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 6, 2019, 3:07pm UTC](https://discuss.elastic.co/t/topic/170306/9 "2019-03-06T15:07:04Z")

</div>

Ничего подозрительного не вижу кроме большого swap-а. На нодах проблемы были, когда вы этот stats запустили?

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 7, 2019, 3:20am UTC](https://discuss.elastic.co/t/topic/170306/10 "2019-03-07T03:20:25Z")

</div>

Не было, добавил в конфигурацию кое что, как я понял в следующий раз поможет больше информации получить.

```
sysadmin@elastic-hot:~$ curl -X GET "localhost:9200/_cluster/settings"
{"persistent":{"logger":{"org":{"elasticsearch":{"discovery":{"zen":{"MasterFaultDetection":"TRACE","NodesFaultDetection":"TRACE"}}}}}},"transient":{"cluster":{"routing":{"allocation":{"disk":{"watermark":{"low":"90%"}}}},"info":{"update":{"interval":"1m"}}}}}
```

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 7, 2019, 1:54pm UTC](https://discuss.elastic.co/t/topic/170306/11 "2019-03-07T13:54:50Z")

</div>

Было бы здорово, если бы вы добавили еще один маленький узел с отдельным кластером на нем и свалили бы туда данные мониторинга с основного кластера. Тогда сразу было бы понятно, что происходило перед тем как узел отвалился.

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 11, 2019, 5:09am UTC](https://discuss.elastic.co/t/topic/170306/12 "2019-03-11T05:09:50Z")

</div>

Поднять еще одну виртуальную машину с еластиком, не входящую в этот кластер ? Простите, я не очень понял что нужно мне сделать. У меня подняты еще 4 ноды для этого кластера, 2 варма и 2 хота. Пока не вводил их в бой. Так как нужен полный рестарт кластера.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 11, 2019, 2:18pm UTC](https://discuss.elastic.co/t/topic/170306/13 "2019-03-11T14:18:34Z")

</div>

Я имел в виду налаживание [мониторинга кластера](https://www.elastic.co/products/stack/monitoring), что бы можно было понять, что с кластером происходит перед тем, как он падает

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 12, 2019, 3:25am UTC](https://discuss.elastic.co/t/topic/170306/14 "2019-03-12T03:25:18Z")

</div>

Хорошо, спасибо, пойду почитаю.

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 12, 2019, 3:36am UTC](https://discuss.elastic.co/t/topic/170306/15 "2019-03-12T03:36:39Z")

</div>

Уточнение, как можно "свалить данные" мониторинга когда я подниму кибану, у нас кстати она была, стояла на основном кластере.

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 12, 2019, 2:27pm UTC](https://discuss.elastic.co/t/topic/170306/16 "2019-03-12T14:27:35Z")

</div>

Посмотрите [https://www.elastic.co/guide/en/elastic-stack-overview/6.6/monitoring-production.html](https://www.elastic.co/guide/en/elastic-stack-overview/6.6/monitoring-production.html) и [https://www.elastic.co/guide/en/elasticsearch/reference/6.6/collecting-monitoring-data.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/collecting-monitoring-data.html)

---

<div class="post-metadata">

**Author:** ![nessero](https://avatars.discourse-cdn.com/v4/letter/n/7cd45c/32.png) [@nessero](https://discuss.elastic.co/u/nessero)\
**Post date:** [March 13, 2019, 5:12am UTC](https://discuss.elastic.co/t/topic/170306/17 "2019-03-13T05:12:20Z")

</div>

узел мониторинга может быть одной нодой ? То есть мне нужно еще одну виртуальную машину, там еластик поднять и через кибану отправлять туда данные мониторинга, верно ? Еластик у меня версии 5.6.11, обновление планирую, но позже. Возможно всю эту схему с мониторингом на 5.6.11 использовать ?

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 13, 2019, 2:04pm UTC](https://discuss.elastic.co/t/topic/170306/18 "2019-03-13T14:04:07Z")

</div>

> [@nessero](#):
>
> узел мониторинга может быть одной нодой ?

Да, одной больше чем достаточно

> [@nessero](#):
>
> и через кибану отправлять туда данные мониторинга, верно ?

Нет, кибаной вы будете смотреть результаты. Данные будет отправлять [экспортер мониторинга](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/http-exporter.html), который будет работать в самом elasticsearch.

> [@nessero](#):
>
> Возможно всю эту схему с мониторингом на 5.6.11 использовать ?

Да хоть на 2.x - эта схема уже давно существует. Только документация немного по другому отформатирована [Monitoring Elasticsearch | X-Pack for the Elastic Stack [5.6] | Elastic](https://www.elastic.co/guide/en/x-pack/5.6/monitoring-cluster.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2019, 2:04pm UTC](https://discuss.elastic.co/t/topic/170306/19 "2019-04-10T14:04:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
