--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/dc9b1e13-6a54-dbe6-f153-b50bc23696b5%40null.co.in.
For more options, visit https://groups.google.com/d/optout.
Hello Utkarsh and Simon,
Just like Javier told you, the error could happen because of several reasons. The log error indicates that you’ve got 1000 search requests that have queued up waiting to run, and once the limit is reached, Elasticsearch just starts aborting new requests.
We could do several things in order to fix this:
/etc/elasticsearch/elasticsearch.yml) and pasting the following configuration:thread_pool:
search:
queue_size: 10000
Be careful with the indentations (2 spaces).
After modifying the file, you have to restart Elasticsearch:
systemctl restart elasticsearch
Make sure Elasticsearch is up and running before opening Kibana with the following command:
curl localhost:9200?pretty
And make sure you get a response like the following:
{
"name" : "bXQ_XEr",
"cluster_name" : "elasticsearch",
"cluster_uuid" : "jt7nCsLrTQuVtsMbnOGIeQ",
"version" : {
"number" : "6.3.2",
"build_flavor" : "default",
"build_type" : "deb",
"build_hash" : "053779d",
"build_date" : "2018-07-20T05:20:23.451332Z",
"build_snapshot" : false,
"lucene_version" : "7.3.1",
"minimum_wire_compatibility_version" : "5.6.0",
"minimum_index_compatibility_version" : "5.0.0"
},
"tagline" : "You Know, for Search"
}
After that, you can open Kibana and try again to use the app to see if the error persists.
Let us know if this helps.
Regards,
Juanjo
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/95cd2325-fb0f-454f-8e60-6f4b28ebd17b%40googlegroups.com.