This was the best resource I have used myself : 
https://stackoverflow.com/questions/19967472/elasticsearch-unassigned-shards-how-to-fix

It has several solutions which might work; Ultimately, i like Splanger's 
edit of W. Andrew Loe III's script which i edited a copy to accept server & 
node as parameters )

On Tuesday, March 8, 2016 at 11:03:57 AM UTC-6, Francois Franck wrote:
>
> Hi all,
>
> My question is about the elasticsearch cluster. Its state is RED whith 32 
> shards unassigned. This happened after upgrading from 1.0.1 to 1.3.3.
> As I could'nt upgrade with dpkg, I renamed the /var/opt/graylog folder, 
> uninstalled the old version then installed the v.1.3.3 and renamed back the 
> /var/opt/graylog folder.
> Except the admin password, all data were right there but I'm now facing 
> this shards issue.
> Any idea would be helpfull. Thanks.
>
>
> *curl -XGET http://172.16.10.116:9200/_cluster/health?pretty 
> <http://172.16.10.116:9200/_cluster/health?pretty>*
> {
>   "cluster_name" : "graylog2",
>   "status" : "yellow",
>   "timed_out" : false,
>   "number_of_nodes" : 2,
>   "number_of_data_nodes" : 1,
>   "active_primary_shards" : 32,
>   "active_shards" : 32,
>   "relocating_shards" : 0,
>   "initializing_shards" : 0,
>   "unassigned_shards" : 32,
>   "delayed_unassigned_shards" : 0,
>   "number_of_pending_tasks" : 0,
>   "number_of_in_flight_fetch" : 0
> }
>
>
> *curl -XGET http://172.16.10.116:9200/_cat/shards 
> <http://172.16.10.116:9200/_cat/shards>*
> graylog_7 0 p STARTED      84139  29.9mb 127.0.1.1 Kurt Wagner
> graylog_7 0 r UNASSIGNED
> graylog_7 3 p STARTED      84685  30.2mb 127.0.1.1 Kurt Wagner
> graylog_7 3 r UNASSIGNED
> graylog_7 1 p STARTED      85301  30.6mb 127.0.1.1 Kurt Wagner
> graylog_7 1 r UNASSIGNED
> graylog_7 2 p STARTED      85776  31.1mb 127.0.1.1 Kurt Wagner
> graylog_7 2 r UNASSIGNED
> graylog_6 0 p STARTED    1103201 305.2mb 127.0.1.1 Kurt Wagner
> graylog_6 0 r UNASSIGNED
> graylog_6 3 p STARTED    1103568 304.7mb 127.0.1.1 Kurt Wagner
> graylog_6 3 r UNASSIGNED
> graylog_6 1 p STARTED    1103055 304.8mb 127.0.1.1 Kurt Wagner
> graylog_6 1 r UNASSIGNED
> graylog_6 2 p STARTED    1106266 305.9mb 127.0.1.1 Kurt Wagner
> graylog_6 2 r UNASSIGNED
> graylog_1 0 p STARTED    4988006   1.3gb 127.0.1.1 Kurt Wagner
> graylog_1 0 r UNASSIGNED
> graylog_1 3 p STARTED    4999403   1.3gb 127.0.1.1 Kurt Wagner
> graylog_1 3 r UNASSIGNED
> graylog_1 1 p STARTED    4997523   1.3gb 127.0.1.1 Kurt Wagner
> graylog_1 1 r UNASSIGNED
> graylog_1 2 p STARTED    5015069   1.3gb 127.0.1.1 Kurt Wagner
> graylog_1 2 r UNASSIGNED
> graylog_0 0 p STARTED    5064441   1.8gb 127.0.1.1 Kurt Wagner
> graylog_0 0 r UNASSIGNED
> graylog_0 3 p STARTED    4999405   1.8gb 127.0.1.1 Kurt Wagner
> graylog_0 3 r UNASSIGNED
> graylog_0 1 p STARTED    5002816   1.8gb 127.0.1.1 Kurt Wagner
> graylog_0 1 r UNASSIGNED
> graylog_0 2 p STARTED    4933353   1.7gb 127.0.1.1 Kurt Wagner
> graylog_0 2 r UNASSIGNED
> graylog_5 0 p STARTED    5083502   1.3gb 127.0.1.1 Kurt Wagner
> graylog_5 0 r UNASSIGNED
> graylog_5 3 p STARTED    5001965   1.3gb 127.0.1.1 Kurt Wagner
> graylog_5 3 r UNASSIGNED
> graylog_5 1 p STARTED    5001476   1.3gb 127.0.1.1 Kurt Wagner
> graylog_5 1 r UNASSIGNED
> graylog_5 2 p STARTED    4913141   1.3gb 127.0.1.1 Kurt Wagner
> graylog_5 2 r UNASSIGNED
> graylog_4 0 p STARTED    5016352   1.3gb 127.0.1.1 Kurt Wagner
> graylog_4 0 r UNASSIGNED
> graylog_4 3 p STARTED    4996719   1.3gb 127.0.1.1 Kurt Wagner
> graylog_4 3 r UNASSIGNED
> graylog_4 1 p STARTED    5000815   1.3gb 127.0.1.1 Kurt Wagner
> graylog_4 1 r UNASSIGNED
> graylog_4 2 p STARTED    4986236   1.3gb 127.0.1.1 Kurt Wagner
> graylog_4 2 r UNASSIGNED
> graylog_3 0 p STARTED    5041163   1.3gb 127.0.1.1 Kurt Wagner
> graylog_3 0 r UNASSIGNED
> graylog_3 3 p STARTED    5001123   1.3gb 127.0.1.1 Kurt Wagner
> graylog_3 3 r UNASSIGNED
> graylog_3 1 p STARTED    4999923   1.3gb 127.0.1.1 Kurt Wagner
> graylog_3 1 r UNASSIGNED
> graylog_3 2 p STARTED    4957923   1.3gb 127.0.1.1 Kurt Wagner
> graylog_3 2 r UNASSIGNED
> graylog_2 0 p STARTED    5080370   1.3gb 127.0.1.1 Kurt Wagner
> graylog_2 0 r UNASSIGNED
> graylog_2 3 p STARTED    5000460   1.3gb 127.0.1.1 Kurt Wagner
> graylog_2 3 r UNASSIGNED
> graylog_2 1 p STARTED    5002158   1.3gb 127.0.1.1 Kurt Wagner
> graylog_2 1 r UNASSIGNED
> graylog_2 2 p STARTED    4917285   1.3gb 127.0.1.1 Kurt Wagner
> graylog_2 2 r UNASSIGNED
>
>
> sudo tail -f */var/log/graylog/elasticsearch/current*
> 2016-03-08_16:16:22.79471       at 
> org.elasticsearch.cluster.routing.allocation.command.AllocateAllocationCommand.execute(AllocateAllocationCommand.java:222)
> 2016-03-08_16:16:22.79609       at 
> org.elasticsearch.cluster.routing.allocation.command.AllocationCommands.execute(AllocationCommands.java:119)
> 2016-03-08_16:16:22.79659       at 
> org.elasticsearch.cluster.routing.allocation.AllocationService.reroute(AllocationService.java:132)
> 2016-03-08_16:16:22.79828       at 
> org.elasticsearch.action.admin.cluster.reroute.TransportClusterRerouteAction$1.execute(TransportClusterRerouteAction.java:99)
> 2016-03-08_16:16:22.79925       at 
> org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run(InternalClusterService.java:374)
> 2016-03-08_16:16:22.79961       at
>
> org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:204)
> 2016-03-08_16:16:22.80147       at 
> org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:167)
> 2016-03-08_16:16:22.80148       at 
> java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
> 2016-03-08_16:16:22.80198       at 
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
> 2016-03-08_16:16:22.80368       at java.lang.Thread.run(Thread.java:745)
>
> *ubuntu@rhlog:~$ sudo tail -f /var/log/graylog/server/current*
> 2016-03-08_16:08:39.12313 INFO  [InputStateListener] Input [Syslog 
> UDP/54ec637ae4b0c57f14beeec9] is now STARTING
> 2016-03-08_16:08:39.13574 INFO  [InputStateListener] Input [GELF 
> UDP/56deb7afe4b04408ec5a3f19] is now STARTING
> 2016-03-08_16:08:39.15662 INFO  [InputStateListener] Input [Syslog 
> TCP/5538eafde4b035a184a12987] is now STARTING
> 2016-03-08_16:08:39.23902 WARN  [NettyTransport] receiveBufferSize 
> (SO_RCVBUF) for input SyslogTCPInput{title=syslog_tcp, 
> type=org.graylog2.inputs.syslog.tcp.SyslogTCPInput, 
> nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is 
> 212992.
> 2016-03-08_16:08:39.24093 WARN  [NettyTransport] receiveBufferSize 
> (SO_RCVBUF) for input SyslogUDPInput{title=syslog_udp, 
> type=org.graylog2.inputs.syslog.udp.SyslogUDPInput, 
> nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is 
> 212992.
> 2016-03-08_16:08:39.24233 WARN  [NettyTransport] receiveBufferSize 
> (SO_RCVBUF) for input GELFUDPInput{title=appliance-gelf-udp, 
> type=org.graylog2.inputs.gelf.udp.GELFUDPInput, 
> nodeId=728c8254-885a-4c03-a92f-0daa5197d26b} should be 1048576 but is 
> 212992.
> 2016-03-08_16:08:39.24843 INFO  [InputStateListener] Input [Syslog 
> TCP/5538eafde4b035a184a12987] is now RUNNING
> 2016-03-08_16:08:39.25005 INFO  [InputStateListener] Input [Syslog 
> UDP/54ec637ae4b0c57f14beeec9] is now RUNNING
> 2016-03-08_16:08:39.25110 INFO  [InputStateListener] Input [GELF 
> UDP/56deb7afe4b04408ec5a3f19] is now RUNNING
> 2016-03-08_16:08:56.31175 INFO  [AbstractValidatingSessionManager] 
> Enabling session validation scheduler...
>
>
> In my *graylog.conf:*
> is_master = true
> elasticsearch_shards = 4
> elasticsearch_replicas = 1
> elasticsearch_cluster_name = graylog2
>
> In my *elasticsearch.yml*:
> cluster.name: graylog2
> node.master: true
> node.data: true
> index.number_of_shards: 5
> index.number_of_replicas: 0
> discovery.zen.ping.multicast.enabled: false
> discovery.zen.ping.unicast.hosts: ["172.16.10.116:9300"]
>

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/2810d8fa-c440-4bc9-8d3f-46cc42ad319b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to