Good afternoon searching the elasticshare logs, find the following :
[2021-03-15T00: 00: 01,828] [ERROR] [caosasInternalESSink] [node-1] Unable to index audit log {"audit_cluster_name": "elasticsearch", "audit_transport_headers ": {" _ system_index_access_allowed ":" false "}," audit_node_name ":" node-1 "," audit_trace_task_id ":" ELClQUgNRLCsOj76o2GQtw: 53535900 "," audit_transport_request_type ":" audit_transport_request_type ":" Audit_transport_request_type ":" Create "" auditIndexRequest_type, "audit_transport_request_type": "audit_transport_request_type": "CreateIndexReque ":" REST "," audit_request_body ":" {} "," audit_node_id ":" ELClQUgNRLCsOj76o2GQtw "," audit_request_layer ":" TRANSPORT "," @ timestamp ":" 2021-03-15T05: 00: 01.827 + 00: 00 "," audit_format_version ": 4," audit_request_remote_address ":" 127.0.0.1 "," audit_request_privilege ":" indices: admin / auto_create "," audit_node_host_address ":" 127.0.0.1 "," audit_request_effective_user ":" audit_traindices "audit_traindices" audit_traindices ", audit_traindices ": [" <wazuh-alerts-4.x- {2021.03.15 || / d {yyyy.MM.dd | UTC}}> "]," audit_node_host_name ":" 127.0.0.1 "} due to org.elasticsearch .common.ValidationException: Validation Failed : 1: this action would add [2] total shards, but this cluster currently has [999] / [1000] maximum shards open;
Note that the error could be because I had reached the limit in my node of [999] / [1000] maximum shards open, search and I found the following post:Wazuh doesn't show events on Web app (google.com) and I started to investigate the error, then I ran the command that enlarged my node from 1000 to 2000 (which is not recommended according to what they indicate) and finally it worked.
I have read the documentation but it is still not clear to me that maximum capacity per node that you have and I would like to please if you could solve the following questions:
1) This that indicates the error (limit [999] / [1000] maximum shards open), is it because of the amount of information that I have stored, that is, the indexes? Or is it because of the agents that I currently have? or what do you mean? currently I have only 51 agents in 01 node and I use opendistroforelasticsearch and wazuh 4.1.0
3) The Database that Wazuh uses is that of opendistroforelasticsearch? or use another like mysql, mariadb, etc.