Hi,
since some days ... nearly every day logsthash or elasticsearch keeps crashing. And events do not show up in that period in the
wazuh kibana app.
If I restart the service elasticsearch and logsthash everything is ok again, expect that events when the logsthash/elastic crashed.
The only thing I have found is this in the logsthas log (many times in that timeframe)
[2018-07-11T23:54:43,883][INFO ][logstash.outputs.elasticsearch] Retrying individual bulk actions that failed or were rejected by the previous bulk request. {:count=>1}
[2018-07-11T23:55:47,886][INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})
Any hints on this issue ?
Many Greetings
Erik