This was the best resource I have used myself : https://stackoverflow.com/questions/19967472/elasticsearch-unassigned-shards-how-to-fix
It has several solutions which might work; Ultimately, i like Splanger's edit of W. Andrew Loe III's script which i edited a copy to accept server & node as parameters ) On Tuesday, March 8, 2016 at 11:03:57 AM UTC-6, Francois Franck wrote: > > Hi all, > > My question is about the elasticsearch cluster. Its state is RED whith 32 > shards unassigned. This happened after upgrading from 1.0.1 to 1.3.3. > As I could'nt upgrade with dpkg, I renamed the /var/opt/graylog folder, > uninstalled the old version then installed the v.1.3.3 and renamed back the > /var/opt/graylog folder. > Except the admin password, all data were right there but I'm now facing > this shards issue. > Any idea would be helpfull. Thanks. > > > *curl -XGET http://172.16.10.116:9200/_cluster/health?pretty > <http://172.16.10.116:9200/_cluster/health?pretty>* > { > "cluster_name" : "graylog2", > "status" : "yellow", > "timed_out" : false, > "number_of_nodes" : 2, > "number_of_data_nodes" : 1, > "active_primary_shards" : 32, > "active_shards" : 32, > "relocating_shards" : 0, > "initializing_shards" : 0, > "unassigned_shards" : 32, > "delayed_unassigned_shards" : 0, > "number_of_pending_tasks" : 0, > "number_of_in_flight_fetch" : 0 > } > > > *curl -XGET http://172.16.10.116:9200/_cat/shards > <http://172.16.10.116:9200/_cat/shards>* > graylog_7 0 p STARTED 84139 29.9mb 127.0.1.1 Kurt Wagner > graylog_7 0 r UNASSIGNED > graylog_7 3 p STARTED 84685 30.2mb 127.0.1.1 Kurt Wagner > graylog_7 3 r UNASSIGNED > graylog_7 1 p STARTED 85301 30.6mb 127.0.1.1 Kurt Wagner > graylog_7 1 r UNASSIGNED > graylog_7 2 p STARTED 85776 31.1mb 127.0.1.1 Kurt Wagner > graylog_7 2 r UNASSIGNED > graylog_6 0 p STARTED 1103201 305.2mb 127.0.1.1 Kurt Wagner > graylog_6 0 r UNASSIGNED > graylog_6 3 p STARTED 1103568 304.7mb 127.0.1.1 Kurt Wagner > graylog_6 3 r UNASSIGNED > graylog_6 1 p STARTED 1103055 304.8mb 127.0.1.1 Kurt Wagner > graylog_6 1 r UNASSIGNED > graylog_6 2 p STARTED 1106266 305.9mb 127.0.1.1 Kurt Wagner > graylog_6 2 r UNASSIGNED > graylog_1 0 p STARTED 4988006 1.3gb 127.0.1.1 Kurt Wagner > graylog_1 0 r UNASSIGNED > graylog_1 3 p STARTED 4999403 1.3gb 127.0.1.1 Kurt Wagner > graylog_1 3 r UNASSIGNED > graylog_1 1 p STARTED 4997523 1.3gb 127.0.1.1 Kurt Wagner > graylog_1 1 r UNASSIGNED > graylog_1 2 p STARTED 5015069 1.3gb 127.0.1.1 Kurt Wagner > graylog_1 2 r UNASSIGNED > graylog_0 0 p STARTED 5064441 1.8gb 127.0.1.1 Kurt Wagner > graylog_0 0 r UNASSIGNED > graylog_0 3 p STARTED 4999405 1.8gb 127.0.1.1 Kurt Wagner > graylog_0 3 r UNASSIGNED > graylog_0 1 p STARTED 5002816 1.8gb 127.0.1.1 Kurt Wagner > graylog_0 1 r UNASSIGNED > graylog_0 2 p STARTED 4933353 1.7gb 127.0.1.1 Kurt Wagner > graylog_0 2 r UNASSIGNED > graylog_5 0 p STARTED 5083502 1.3gb 127.0.1.1 Kurt Wagner > graylog_5 0 r UNASSIGNED > graylog_5 3 p STARTED 5001965 1.3gb 127.0.1.1 Kurt Wagner > graylog_5 3 r UNASSIGNED > graylog_5 1 p STARTED 5001476 1.3gb 127.0.1.1 Kurt Wagner > graylog_5 1 r UNASSIGNED > graylog_5 2 p STARTED 4913141 1.3gb 127.0.1.1 Kurt Wagner > graylog_5 2 r UNASSIGNED > graylog_4 0 p STARTED 5016352 1.3gb 127.0.1.1 Kurt Wagner > graylog_4 0 r UNASSIGNED > graylog_4 3 p STARTED 4996719 1.3gb 127.0.1.1 Kurt Wagner > graylog_4 3 r UNASSIGNED > graylog_4 1 p STARTED 5000815 1.3gb 127.0.1.1 Kurt Wagner > graylog_4 1 r UNASSIGNED > graylog_4 2 p STARTED 4986236 1.3gb 127.0.1.1 Kurt Wagner > graylog_4 2 r UNASSIGNED > graylog_3 0 p STARTED 5041163 1.3gb 127.0.1.1 Kurt Wagner > graylog_3 0 r UNASSIGNED > graylog_3 3 p STARTED 5001123 1.3gb 127.0.1.1 Kurt Wagner > graylog_3 3 r UNASSIGNED > graylog_3 1 p STARTED 4999923 1.3gb 127.0.1.1 Kurt Wagner > graylog_3 1 r UNASSIGNED > graylog_3 2 p STARTED 4957923 1.3gb 127.0.1.1 Kurt Wagner > graylog_3 2 r UNASSIGNED > graylog_2 0 p STARTED 5080370 1.3gb 127.0.1.1 Kurt Wagner > graylog_2 0 r UNASSIGNED > graylog_2 3 p STARTED 5000460 1.3gb 127.0.1.1 Kurt Wagner > graylog_2 3 r UNASSIGNED > graylog_2 1 p STARTED 5002158 1.3gb 127.0.1.1 Kurt Wagner > graylog_2 1 r UNASSIGNED > graylog_2 2 p STARTED 4917285 1.3gb 127.0.1.1 Kurt Wagner > graylog_2 2 r UNASSIGNED > > > sudo tail -f */var/log/graylog/elasticsearch/current* > 2016-03-08_16:16:22.79471 at > org.elasticsearch.cluster.routing.allocation.command.AllocateAllocationCommand.execute(AllocateAllocationCommand.java:222) > 2016-03-08_16:16:22.79609 at > org.elasticsearch.cluster.routing.allocation.command.AllocationCommands.execute(AllocationCommands.java:119) > 2016-03-08_16:16:22.79659 at > org.elasticsearch.cluster.routing.allocation.AllocationService.reroute(AllocationService.java:132) > 2016-03-08_16:16:22.79828 at > org.elasticsearch.action.admin.cluster.reroute.TransportClusterRerouteAction$1.execute(TransportClusterRerouteAction.java:99) > 2016-03-08_16:16:22.79925 at > org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run(InternalClusterService.java:374) > 2016-03-08_16:16:22.79961 at > > org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:204) > 2016-03-08_16:16:22.80147 at > org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:167) > 2016-03-08_16:16:22.80148 at > java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) > 2016-03-08_16:16:22.80198 at > java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) > 2016-03-08_16:16:22.80368 at java.lang.Thread.run(Thread.java:745) > > *ubuntu@rhlog:~$ sudo tail -f /var/log/graylog/server/current* > 2016-03-08_16:08:39.12313 INFO [InputStateListener] Input [Syslog > UDP/54ec637ae4b0c57f14beeec9] is now STARTING > 2016-03-08_16:08:39.13574 INFO [InputStateListener] Input [GELF > UDP/56deb7afe4b04408ec5a3f19] is now STARTING > 2016-03-08_16:08:39.15662 INFO [InputStateListener] Input [Syslog > TCP/5538eafde4b035a184a12987] is now STARTING > 2016-03-08_16:08:39.23902 WARN [NettyTransport] receiveBufferSize > (SO_RCVBUF) for input SyslogTCPInput{title=syslog_tcp, > type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, > nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is > 212992. > 2016-03-08_16:08:39.24093 WARN [NettyTransport] receiveBufferSize > (SO_RCVBUF) for input SyslogUDPInput{title=syslog_udp, > type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, > nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is > 212992. > 2016-03-08_16:08:39.24233 WARN [NettyTransport] receiveBufferSize > (SO_RCVBUF) for input GELFUDPInput{title=appliance-gelf-udp, > type=org.graylog2.inputs.gelf.udp.GELFUDPInput, > nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is > 212992. > 2016-03-08_16:08:39.24843 INFO [InputStateListener] Input [Syslog > TCP/5538eafde4b035a184a12987] is now RUNNING > 2016-03-08_16:08:39.25005 INFO [InputStateListener] Input [Syslog > UDP/54ec637ae4b0c57f14beeec9] is now RUNNING > 2016-03-08_16:08:39.25110 INFO [InputStateListener] Input [GELF > UDP/56deb7afe4b04408ec5a3f19] is now RUNNING > 2016-03-08_16:08:56.31175 INFO [AbstractValidatingSessionManager] > Enabling session validation scheduler... > > > In my *graylog.conf:* > is_master = true > elasticsearch_shards = 4 > elasticsearch_replicas = 1 > elasticsearch_cluster_name = graylog2 > > In my *elasticsearch.yml*: > cluster.name: graylog2 > node.master: true > node.data: true > index.number_of_shards: 5 > index.number_of_replicas: 0 > discovery.zen.ping.multicast.enabled: false > discovery.zen.ping.unicast.hosts: ["172.16.10.116:9300"] > -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/2810d8fa-c440-4bc9-8d3f-46cc42ad319b%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
