# Unbalanced distribution of index (shards) between HOT servers ES

**URL:** <https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603>\
**Category:** Elasticsearch\
**Created:** [September 30, 2022, 8:24pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603 "2022-09-30T20:24:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleksei](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@Aleksei](https://discuss.elastic.co/u/Aleksei)\
**Post date:** [September 30, 2022, 8:24pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/1 "2022-09-30T20:24:25Z")

</div>

Hi community !

I apologize if this topic has been covered for a long time.  
But I never found it in the open Elastic Сommunity. 🫣

We have 11 cluster servers in the infrastructure ES:  
Servers HOT - 3  
Servers WARM - 3  
Servers COULD - 2  
Servers Master - 3

Some time ago I noticed that on HOT servers there is a discrepancy in disk space utilization.  
The HOT 1 server began to fill up disk space faster than on the HOT 2 and HOT 3 servers.

I don’t understand why there is an uneven distribution of indexes (shards) between HOT servers in the cluster.

Sending to these three servers HOT-1 HOT-2 HOT-3 is configured on all logstash servers in the output section.

Can anyone suggest what are the special parameters for properly balancing the distribution of indexes ?

How to understand this and, most importantly, how to set up the correct distribution of indexes on servers with the HOT role ? 😲

Moreover, on all other servers with the roles of WARM and COULD, the distribution of the index record is even.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 4, 2022, 5:06am UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/2 "2022-10-04T05:06:28Z")

</div>

How have you setup the allocation filtering you are using?

---

<div class="post-metadata">

**Author:** ![Aleksei](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@Aleksei](https://discuss.elastic.co/u/Aleksei)\
**Post date:** [October 4, 2022, 12:54pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/3 "2022-10-04T12:54:08Z")

</div>

> [@warkolm](#):
>
> How have you setup the allocation filtering you are using?

Sending to three HOT servers is configured on all logstah in otptut.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6ef7717b12039281a1f92599214fcec5e1b1b1f.png)

Or are you talking about some other allocation ? 🤔

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 4, 2022, 10:39pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/4 "2022-10-04T22:39:23Z")

</div>

Please don't post pictures of text, logs or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![Aleksei](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@Aleksei](https://discuss.elastic.co/u/Aleksei)\
**Post date:** [October 10, 2022, 5:49pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/5 "2022-10-10T17:49:30Z")

</div>

Hi.  
I figured out the reason, the topic is closed.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 10, 2022, 10:27pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/6 "2022-10-10T22:27:23Z")

</div>

It'd be great if you could share your solution, it might help someone in future.

---

<div class="post-metadata">

**Author:** ![Aleksei](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@Aleksei](https://discuss.elastic.co/u/Aleksei)\
**Post date:** [October 17, 2022, 1:44pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/7 "2022-10-17T13:44:03Z")

</div>

At first, on the first and then on the second HOT servers, I had more than 85% full.  
New shards could not be recognized (unsigned).  
found ~ 1000 unsigned shards.

After I corrected the ILM policy by expanding storage towards WARM servers, all shards recovered, in less than a week the space on XOT servers stabilized.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2022, 1:44pm UTC](https://discuss.elastic.co/t/unbalanced-distribution-of-index-shards-between-hot-servers-es/315603/8 "2022-11-14T13:44:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
