Hi,
When are you getting this error exactly? when opening a dashboard? at "Discover" tab?
It is a very generic error, there are different approaches to solve this:
- What specs have your machine?
- Are you creating a daily index? how many index have your cluster now?
- How many shards per index?
- Are you using a lot of wildcards (*)?
The point is Elasticsearch can't handle the request on time, one solution is edit your elasticsearch.yml and change the following parameters:
threadpool.search.type: fixed
threadpool.search.size: 20
threadpool.search.queue_size: 10000
BE AWARE! Increasing queue_size will create so many threads on your machine, the best solution is try to find what is causing the error and not just increase queue_size, or if you prefer, use a browser debuger and inspect HTTP error responses from Elastic, you will see something like: "EsRejectedExecutionException[rejected execution (queue capacity 1000) on org.elasticsearch.search.action...", try to adjust queue_size as low as possible.