Hello Javior,
One more thing happen today during restoration data current dashboard logs showing stopped, pelase find the below reference logs
after check logs found error in in cluster logs
[2025-05-01T14:33:17,652][INFO ][o.o.n.Node ] [node-1] JVM arguments [-Xshare:auto, -Dopensearch.networkaddress.cache.ttl=60, -Dopensearch.networkaddress.cache.negative.ttl=10, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -XX:-OmitStackTraceInFastThrow, -XX:+ShowCodeDetailsInExceptionMessages, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dio.netty.allocator.numDirectArenas=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Djava.security.manager=allow, -Djava.locale.providers=SPI,COMPAT, -Xms4g, -Xmx4g, -XX:+UseG1GC, -XX:G1ReservePercent=25, -XX:InitiatingHeapOccupancyPercent=30, -Djava.io.tmpdir=/var/lib/wazuh-indexer/tmp, -XX:+HeapDumpOnOutOfMemoryError, -XX:HeapDumpPath=/var/lib/wazuh-indexer, -XX:ErrorFile=/var/log/wazuh-indexer/hs_err_pid%p.log, -Xlog:gc*,gc+age=trace,safepoint:file=/var/log/wazuh-indexer/gc.log:utctime,pid,tags:filecount=32,filesize=64m, -Djava.security.manager=allow, -Djava.util.concurrent.ForkJoinPool.common.threadFactory=org.opensearch.secure_sm.SecuredForkJoinWorkerThreadFactory, -Dclk.tck=100, -Djdk.attach.allowAttachSelf=true, -Djava.security.policy=file:///etc/wazuh-indexer/opensearch-performance-analyzer/opensearch_security.policy, --add-opens=jdk.attach/sun.tools.attach=ALL-UNNAMED, -XX:MaxDirectMemorySize=2147483648, -Dopensearch.path.home=/usr/share/wazuh-indexer, -Dopensearch.path.conf=/etc/wazuh-indexer, -Dopensearch.distribution.type=deb, -Dopensearch.bundled_jdk=true]
[2025-05-01T14:33:58,038][ERROR][o.o.s.a.s.SinkProvider ] [node-1] Default endpoint could not be created, auditlog will not work properly.
[2025-05-01T14:34:26,564][ERROR][o.o.s.l.BuiltinLogTypeLoader] [node-1] Failed loading builtin log types from disk!
at org.opensearch.cli.Command.mainWithoutErrorHandling(Command.java:138) [opensearch-cli-2.16.0.jar:2.16.0]
[2025-05-01T14:34:38,236][ERROR][o.o.s.a.BackendRegistry ] [node-1] Not yet initialized (you may need to run securityadmin)
[2025-05-01T14:34:38,265][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [node-1] Failure No shard available for [org.opensearch.action.get.MultiGetShardRequest@11c24699] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
[2025-05-01T14:34:38,265][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [node-1] Failure No shard available for [org.opensearch.action.get.MultiGetShardRequest@11c24699] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
[2025-05-01T14:34:38,265][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [node-1] Failure No shard available for [org.opensearch.action.get.MultiGetShardRequest@11c24699] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
[2025-05-01T14:34:38,265][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [node-1] Failure No shard available for [org.opensearch.action.get.MultiGetShardRequest@11c24699] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
[2025-05-01T14:34:38,265][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [node-1] Failure No shard available for [org.opensearch.action.get.MultiGetShardRequest@11c24699] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
I am getting similar errors in journalctl -u wazuh-dashboard
{"type":"log","@timestamp":"2025-05-01T00:15:01Z","tags":["error","plugins","wazuh","monitoring"],"pid":13207,"message":"validation_exception: [validation_exception] Reason: Validation Failed: 1: this action would add [0] total shards, but this cluster currently has [1004]/[1000] maximum shards open;"}
["error","opensearch","data"],"pid":851,"message":"[search_phase_execution_exception]: all shards failed"}
Cluster Health
{
"cluster_name" : "wazuh-cluster",
"status" : "yellow",
"timed_out" : false,
"number_of_nodes" : 1,
"number_of_data_nodes" : 1,
"discovered_master" : true,
"discovered_cluster_manager" : true,
"active_primary_shards" : 1001,
"active_shards" : 1001,
"relocating_shards" : 0,
"initializing_shards" : 0,
"unassigned_shards" : 3,
"delayed_unassigned_shards" : 0,
"number_of_pending_tasks" : 0,
"number_of_in_flight_fetch" : 0,
"task_max_waiting_in_queue_millis" : 0,
"active_shards_percent_as_number" : 99.7011952191235
}
shards count file attached
/usr/share/wazuh-indexer/bin/indexer-security-init.sh
**************************************************************************
** This tool will be deprecated in the next major release of OpenSearch **
**
https://github.com/opensearch-project/security/issues/1755 **
**************************************************************************
Security Admin v7
Will connect to
127.0.0.1:9200 ... done
Connected as "CN=admin,OU=Wazuh,O=Wazuh,L=California,C=US"
OpenSearch Version: 2.16.0
Contacting opensearch cluster 'opensearch' and wait for YELLOW clusterstate ...
Clustername: wazuh-cluster
Clusterstate: YELLOW
Number of nodes: 1
Number of data nodes: 1
.opendistro_security index already exists, so we do not need to create one.
Populate config from /etc/wazuh-indexer/opensearch-security/
Will update '/config' with /etc/wazuh-indexer/opensearch-security/config.yml
SUCC: Configuration for 'config' created or updated
Will update '/roles' with /etc/wazuh-indexer/opensearch-security/roles.yml
SUCC: Configuration for 'roles' created or updated
Will update '/rolesmapping' with /etc/wazuh-indexer/opensearch-security/roles_mapping.yml
SUCC: Configuration for 'rolesmapping' created or updated
Will update '/internalusers' with /etc/wazuh-indexer/opensearch-security/internal_users.yml
SUCC: Configuration for 'internalusers' created or updated
Will update '/actiongroups' with /etc/wazuh-indexer/opensearch-security/action_groups.yml
SUCC: Configuration for 'actiongroups' created or updated
Will update '/tenants' with /etc/wazuh-indexer/opensearch-security/tenants.yml
SUCC: Configuration for 'tenants' created or updated
Will update '/nodesdn' with /etc/wazuh-indexer/opensearch-security/nodes_dn.yml
SUCC: Configuration for 'nodesdn' created or updated
Will update '/whitelist' with /etc/wazuh-indexer/opensearch-security/whitelist.yml
SUCC: Configuration for 'whitelist' created or updated
Will update '/audit' with /etc/wazuh-indexer/opensearch-security/audit.yml
SUCC: Configuration for 'audit' created or updated
Will update '/allowlist' with /etc/wazuh-indexer/opensearch-security/allowlist.yml
SUCC: Configuration for 'allowlist' created or updated
SUCC: Expected 10 config types for node {"updated_config_types":["allowlist","tenants","rolesmapping","nodesdn","audit","roles","whitelist","actiongroups","config","internalusers"],"updated_config_size":10,"message":null} is 10 (["allowlist","tenants","rolesmapping","nodesdn","audit","roles","whitelist","actiongroups","config","internalusers"]) due to: null
Done with success
Wazuh Dasbhoard service status
● wazuh-dashboard.service - wazuh-dashboard
Loaded: loaded (/etc/systemd/system/wazuh-dashboard.service; enabled; preset: enabled)
Active: active (running) since Thu 2025-05-01 14:32:59 UTC; 3h 39min ago
Main PID: 851 (node)
Tasks: 11 (limit: 19147)
Memory: 220.8M (peak: 1.2G)
CPU: 57.589s
CGroup: /system.slice/wazuh-dashboard.service
└─851 /usr/share/wazuh-dashboard/node/bin/node --no-warnings --max-http-header-size=65536 --unhandled-rejections=warn /usr/share/wazuh-dashboard/src/cli/dist
May 01 17:41:39 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:41:37Z","tags":[],"pid":851,"method":"post","statusCode":200,"req":{"url":"/internal/search/opensearch-with-long-numerals","method":"post","headers":{"host":"
siem.citixsys.co.in","connection":"keep-alive","osd-version":"2.16.0","sec-ch-ua-platform":"\"Windows\"","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","sec-ch-ua":"\"Google Chrome\";v=\"135\", \"Not-A.Brand\";v=\"8\", \"Chromium\";v=\"135\"","content-type":"application/json","sec-ch-ua-mobile":"?0","osd-xsrf":"osd-fetch","accept":"*/*","origin":"
https://siem.citixsys.co.in","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover","accept-language":"en-US,en;q=0.9","accept-encoding":"gzip, deflate, zstd","content-length":"2698"},"remoteAddress":"40.88.32.228","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover"},"res":{"statusCode":200,"responseTime":2088,"contentLength":9},"message":"POST /internal/search/opensearch-with-long-numerals 200 2088ms - 9.0B"}
May 01 17:41:50 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:41:47Z","tags":[],"pid":851,"method":"post","statusCode":200,"req":{"url":"/internal/search/opensearch-with-long-numerals","method":"post","headers":{"host":"
siem.citixsys.co.in","connection":"keep-alive","osd-version":"2.16.0","sec-ch-ua-platform":"\"Windows\"","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","sec-ch-ua":"\"Google Chrome\";v=\"135\", \"Not-A.Brand\";v=\"8\", \"Chromium\";v=\"135\"","content-type":"application/json","sec-ch-ua-mobile":"?0","osd-xsrf":"osd-fetch","accept":"*/*","origin":"
https://siem.citixsys.co.in","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover","accept-language":"en-US,en;q=0.9","accept-encoding":"gzip, deflate, zstd","content-length":"2698"},"remoteAddress":"40.88.32.228","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover"},"res":{"statusCode":200,"responseTime":2421,"contentLength":9},"message":"POST /internal/search/opensearch-with-long-numerals 200 2421ms - 9.0B"}
May 01 17:41:54 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:41:52Z","tags":[],"pid":851,"method":"post","statusCode":200,"req":{"url":"/internal/search/opensearch-with-long-numerals","method":"post","headers":{"host":"
siem.citixsys.co.in","connection":"keep-alive","osd-version":"2.16.0","sec-ch-ua-platform":"\"Windows\"","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","sec-ch-ua":"\"Google Chrome\";v=\"135\", \"Not-A.Brand\";v=\"8\", \"Chromium\";v=\"135\"","content-type":"application/json","sec-ch-ua-mobile":"?0","osd-xsrf":"osd-fetch","accept":"*/*","origin":"
https://siem.citixsys.co.in","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover","accept-language":"en-US,en;q=0.9","accept-encoding":"gzip, deflate, zstd","content-length":"2698"},"remoteAddress":"40.88.32.228","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover"},"res":{"statusCode":200,"responseTime":2047,"contentLength":9},"message":"POST /internal/search/opensearch-with-long-numerals 200 2047ms - 9.0B"}
May 01 17:42:01 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:41:59Z","tags":[],"pid":851,"method":"post","statusCode":200,"req":{"url":"/internal/search/opensearch-with-long-numerals","method":"post","headers":{"host":"
siem.citixsys.co.in","connection":"keep-alive","osd-version":"2.16.0","sec-ch-ua-platform":"\"Windows\"","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","sec-ch-ua":"\"Google Chrome\";v=\"135\", \"Not-A.Brand\";v=\"8\", \"Chromium\";v=\"135\"","content-type":"application/json","sec-ch-ua-mobile":"?0","osd-xsrf":"osd-fetch","accept":"*/*","origin":"
https://siem.citixsys.co.in","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover","accept-language":"en-US,en;q=0.9","accept-encoding":"gzip, deflate, zstd","content-length":"2698"},"remoteAddress":"40.88.32.228","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover"},"res":{"statusCode":200,"responseTime":2053,"contentLength":9},"message":"POST /internal/search/opensearch-with-long-numerals 200 2053ms - 9.0B"}
May 01 17:42:08 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:42:06Z","tags":[],"pid":851,"method":"post","statusCode":200,"req":{"url":"/internal/search/opensearch-with-long-numerals","method":"post","headers":{"host":"
siem.citixsys.co.in","connection":"keep-alive","osd-version":"2.16.0","sec-ch-ua-platform":"\"Windows\"","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","sec-ch-ua":"\"Google Chrome\";v=\"135\", \"Not-A.Brand\";v=\"8\", \"Chromium\";v=\"135\"","content-type":"application/json","sec-ch-ua-mobile":"?0","osd-xsrf":"osd-fetch","accept":"*/*","origin":"
https://siem.citixsys.co.in","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover","accept-language":"en-US,en;q=0.9","accept-encoding":"gzip, deflate, zstd","content-length":"2698"},"remoteAddress":"40.88.32.228","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
135.0.0.0 Safari/537.36","referer":"
https://siem.citixsys.co.in/app/data-explorer/discover"},"res":{"statusCode":200,"responseTime":2034,"contentLength":9},"message":"POST /internal/search/opensearch-with-long-numerals 200 2034ms - 9.0B"}
May 01 17:45:00 SIEM opensearch-dashboards[851]: {"type":"log","@timestamp":"2025-05-01T17:45:00Z","tags":["error","opensearch","data"],"pid":851,"message":"[validation_exception]: Validation Failed: 1: this action would add [0] total shards, but this cluster currently has [1004]/[1000] maximum shards open;"}
May 01 17:45:00 SIEM opensearch-dashboards[851]: {"type":"log","@timestamp":"2025-05-01T17:45:00Z","tags":["error","plugins","wazuh","monitoring"],"pid":851,"message":"validation_exception: [validation_exception] Reason: Validation Failed: 1: this action would add [0] total shards, but this cluster currently has [1004]/[1000] maximum shards open;"}
May 01 17:48:45 SIEM opensearch-dashboards[851]: {"type":"response","@timestamp":"2025-05-01T17:48:45Z","tags":[],"pid":851,"method":"get","statusCode":401,"req":{"url":"/.git/index","method":"get","headers":{"host":"172.178.15.120","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36","accept-charset":"utf-8","accept-encoding":"gzip","connection":"close"},"remoteAddress":"196.251.70.87","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36"},"res":{"statusCode":401,"responseTime":3,"contentLength":9},"message":"GET /.git/index 401 3ms - 9.0B"}
May 01 18:00:00 SIEM opensearch-dashboards[851]: {"type":"log","@timestamp":"2025-05-01T18:00:00Z","tags":["error","opensearch","data"],"pid":851,"message":"[validation_exception]: Validation Failed: 1: this action would add [0] total shards, but this cluster currently has [1004]/[1000] maximum shards open;"}
May 01 18:00:00 SIEM opensearch-dashboards[851]: {"type":"log","@timestamp":"2025-05-01T18:00:00Z","tags":["error","plugins","wazuh","monitoring"],"pid":851,"message":"validation_exception: [validation_exception] Reason: Validation Failed: 1: this action would add [0] total shards, but this cluster currently has [1004]/[1000] maximum shards open;"}