I am getting a slightly different one now:
2015-08-19_16:12:58.88945 WARN [SearchResource] Unable to execute search:
Failed to execute phase [query], all shards failed; shardFailures
{[5eRP1nSkR5-ffQFtbFVobg][graylog_20][0]: RemoteTransportException[[Robert
Bruce
Banner][inet[/IP_ADDRESS_OF_MASTER:9300]][indices:data/read/search[phase/query]]];
nested:
ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData
cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData];
}{[5eRP1nSkR5-ffQFtbFVobg][graylog_20][1]: RemoteTransportException[[Robert
Bruce
Banner][inet[/IP_ADDRESS_OF_MASTER:9300]][indices:data/read/search[phase/query]]];
nested:
ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData
cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData];
}{[kggTGd35S5qbXlSPVh8eIw][graylog_20][2]:
RemoteTransportException[[Corona][inet[/IP_ADDRESS_OF_SECOND_SERVER:9300]][indices:data/read/search[phase/query]]];
nested:
ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData
cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData];
}{[kggTGd35S5qbXlSPVh8eIw][graylog_20][3]:
RemoteTransportException[[Corona][inet[/IP_ADDRESS_OF_SECOND_SERVER:9300]][indices:data/read/search[phase/query]]];
nested:
ClassCastException[org.elasticsearch.index.fielddata.plain.PagedBytesIndexFieldData
cannot be cast to org.elasticsearch.index.fielddata.IndexNumericFieldData];
}
not sure what that might mean.
On Wednesday, 19 August 2015 14:42:17 UTC+1, Graylog2 wrote:
>
> Hi Guys,
>
> I have a cluster combined of 2 graylog servers with ElasticSearch on them
> and one additional Vm acting as a web interface.
>
> All has been deployed using the graylog OVA (VMware).
>
> All was working fine untill today when I spotted that I cannot perform any
> searches nor I can see any messages in defined streams. Error I am getting
> is this :
>
> *org.elasticsearch.action.search.SearchPhaseExecutionException*
> Unable to execute search
>
> 1. I have restarted the whole cluster, no joy.
> 2. Checked log files but nothing specific was found in relation to this
> error
> 3. There is space on the boxes, server one capacity is roung 85 % used and
> server 2 roung 81%. Webserver is ok alltogether.
>
> Could you stear me in the right direction on where to start to tackle this
> issue please ?
>
> Cheers.
>
--
You received this message because you are subscribed to the Google Groups
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/graylog2/56bf88c0-224c-418a-9aa7-f24068ded8fa%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.