--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ac1e3b63-9ca0-4c24-b709-39aa710d3b4bn%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/CAFVXG3z7m-APDt0zsVYMuntDsvkuk9Y8659uBn0aWRpC35JW4A%40mail.gmail.com.
Hello Dhruvin
Sorry for the late reply. The ECONNREFUSED error should mean that the Wazuh indexer is not working. Please check the Wazuh indexer state by running systemctl status wazuh-indexer. If it’s not running, check the reason on the logs /var/log/wazuh-indexer/wazuh-cluster.log (or similar, depending on your configuration file defined cluster name). If you need help with that, please share the logs.
Regards,
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/453cbd7c-30c1-48a8-b8d1-8af4aac4016fn%40googlegroups.com.
Hello Dhruvin
You run on an out-of-memory issue. Please, check the /etc/wazuh-indexer/jvm.options, the values Xmx and Xms should have about a half of your total host RAM, and restart the wazuh indexer. If those values are correct, you must check why an out-of-memory occurred, maybe other processes?
Regarding your log, the only ERROR message you have is this one:
[2022-05-26T11:24:26,757][ERROR][o.o.i.i.MetadataService ] [node-1] failed reason: {"index":".opendistro-ism-config","type":"_doc","id":"4YNzC-k0S4SuStIlEVrK4w#metadata","cause":{"type":"unavailable_shards_exception","reason":"[.opendistro-ism-config][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[.opendistro-ism-config][0]] containing [330] requests]"},"status":503}, UnavailableShardsException[[.opendistro-ism-config][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[.opendistro-ism-config][0]] containing [330] requests]]
which means that one of your indices resulted orphaned because of an out of memory. You probably need to delete the index .opendistro-ism-config, used for ISM configuration, and re-configure the plugin settings.
Regards,
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/5d63762f-1e6f-445c-ab91-68d6b8581271n%40googlegroups.com.