# Troubleshooting resources?

**URL:** <https://discuss.elastic.co/t/troubleshooting-resources/265626>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [February 26, 2021, 3:42pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626 "2021-02-26T15:42:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [February 26, 2021, 3:42pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/1 "2021-02-26T15:42:38Z")

</div>

Hi folks,  
I have a 8 node cluster with 1 logstash server collecting winlogbeats data. It has been running fine until recently. I added more endpoints and I noticed in Kibana that all the events stopped at the same time.

What is the best way of finding the errors/cause of this? I've ran into something similar before were the index size of daily was too small so I set it to weekly. Deleting the data and restarting caused data to flow.

I'm reviewing logs in /var/log/elasticsearch but haven't found indication of an error yet. Any tips or pointers? My troubleshooting skills regarding elasticsearch are weak.

---

<div class="post-metadata">

**Author:** ![RLPowellJr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rlpowelljr/32/97049_2.png) [@RLPowellJr](https://discuss.elastic.co/u/RLPowellJr)\
**Post date:** [February 26, 2021, 5:25pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/2 "2021-02-26T17:25:15Z")

</div>

Don't forget the Kibana and Logstash logs, too. In fact, I'd start at Kibana, then go to Logstash, and then check the Elasticsearch nodes logs, because if everything stopped at once you should look for the common failure point. Note that you may not have a /var/log/kibana unless it's specifically set up in the kibana.yml, so you may need to add that first and restart Kibana.

---

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [February 26, 2021, 8:19pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/3 "2021-02-26T20:19:29Z")

</div>

thanks for the tip on logstash, found one error but that didn't resolve it. Found one more in elasticsearch but haven't had any luck yet digging up the solution.

> [2021-01-05T19:18:19,533][ERROR][o.e.x.s.a.s.m.NativeRoleMappingStore] [usta-elastic-01] failed to load role mappings from index [.security] skipping all mappings.  
> org.elasticsearch.action.search.SearchPhaseExecutionException: all shards failed

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 26, 2021, 9:44pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/4 "2021-02-26T21:44:10Z")

</div>

Do you have Monitoring enabled?

---

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [March 4, 2021, 6:34pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/5 "2021-03-04T18:34:45Z")

</div>

yes I do!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 5, 2021, 12:12am UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/6 "2021-03-05T00:12:17Z")

</div>

Does it show anything at the time you see the other issue?

What do your Elasticsearch, Logstash, Beats logs show?

---

<div class="post-metadata">

**Author:** ![jcor](https://avatars.discourse-cdn.com/v4/letter/j/8797f3/32.png) [@jcor](https://discuss.elastic.co/u/jcor)\
**Post date:** [March 18, 2021, 6:34pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/7 "2021-03-18T18:34:56Z")

</div>

I ended up finding out it was a combination of permissions being incorrect and lack of storage size on nodes (watermark kicked in). Thank you for all who replied. Data flows as expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2021, 6:35pm UTC](https://discuss.elastic.co/t/troubleshooting-resources/265626/8 "2021-04-15T18:35:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
