Checking filebeat, I get the follwing:
filebeat test output
elasticsearch: https://127.0.0.1:9200...
parse url... OK
connection...
parse host... OK
dns lookup... OK
addresses: 127.0.0.1
dial up... ERROR dial tcp
127.0.0.1:9200: connect: connection refused
Looking at journal -xe
journalctl -xe
Sep 18 21:25:45 wazuh-server opensearch-dashboards[449]: {"type":"log","@timestamp":"2023-09-18T21:25:45Z","tags":["error","opensearch","data"],"pid":449,"message":"[ConnectionError]: connect ECONNREFUSED
127.0.0.1:9200"}
Sep 18 21:25:48 wazuh-server opensearch-dashboards[449]: {"type":"log","@timestamp":"2023-09-18T21:25:48Z","tags":["error","opensearch","data"],"pid":449,"message":"[ConnectionError]: connect ECONNREFUSED
127.0.0.1:9200"}
Sep 18 21:25:50 wazuh-server opensearch-dashboards[449]: {"type":"log","@timestamp":"2023-09-18T21:25:50Z","tags":["error","opensearch","data"],"pid":449,"message":"[ConnectionError]: connect ECONNREFUSED
127.0.0.1:9200"}
Sep 18 21:25:53 wazuh-server opensearch-dashboards[449]: {"type":"log","@timestamp":"2023-09-18T21:25:53Z","tags":["error","opensearch","data"],"pid":449,"message":"[ConnectionError]: connect ECONNREFUSED
127.0.0.1:9200"}
Sep 18 21:25:55 wazuh-server opensearch-dashboards[449]: {"type":"log","@timestamp":"2023-09-18T21:25:55Z","tags":["error","opensearch","data"],"pid":449,"message":"[ConnectionError]: connect ECONNREFUSED
127.0.0.1:9200"
And if I look in the cluster logs, I get a bunch of these errors:
[2023-09-18T00:01:54,535][INFO ][o.o.j.s.JobSweeper ] [node-1] Running full sweep
[2023-09-18T00:01:55,569][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.5gb[4.3%], all indices on this node will be marked read-only
[2023-09-18T00:02:25,577][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.5gb[4.3%], all indices on this node will be marked read-only
[2023-09-18T00:02:55,586][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.4gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:03:25,593][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.3gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:03:55,599][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.3gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:04:25,608][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.2gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:04:55,614][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21.1gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:05:25,622][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21gb[4.2%], all indices on this node will be marked read-only
[2023-09-18T00:05:55,627][WARN ][o.o.c.r.a.DiskThresholdMonitor] [node-1] flood stage disk watermark [95%] exceeded on [Rc_D7aKbS3qQZ9_KGRU7PQ][node-1][/var/lib/wazuh-indexer/nodes/0] free: 21gb[4.2%], all indices on this node will be marked read-only
Looking in that directory, everything is from today, so I have no clue what I can delete, or if this will help at all:
ncdu /var/lib/wazuh-indexer/nodes/0
ncdu 1.18 ~ Use the arrow keys to navigate, press ? for help
--- /var/lib/wazuh-indexer/nodes/0 ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
385.9 GiB [#######################################] /indices
944.0 KiB [ ] /_state
0.0 B [ ] node.lock
So looking in indices, as I mentioned, everything is from today:
drwxr-xr-x. 6 wazuh-indexer wazuh-indexer 47 Sep 18 19:32 KhKMpzEDRzmrynVtpWCNhA
drwxr-xr-x. 6 wazuh-indexer wazuh-indexer 47 Sep 18 19:32 kSYxoyy_Q_yjsInjKEyBtQ
drwxr-xr-x. 4 wazuh-indexer wazuh-indexer 29 Sep 18 19:32 dvOJ5XDATMaLmHRbRqaSDw
drwxr-xr-x. 4 wazuh-indexer wazuh-indexer 29 Sep 18 19:32 dfv0kggqQ1GCrszwDbck9w
drwxr-xr-x. 4 wazuh-indexer wazuh-indexer 29 Sep 18 19:32 WulL98N3T2SyvQ3C-vMkDQ
drwxr-xr-x. 6 wazuh-indexer wazuh-indexer 47 Sep 18 19:32 fOVO0HtqSyayavjRvf7iBg
drwxr-xr-x. 4 wazuh-indexer wazuh-indexer 29 Sep 18 19:32 z1h755jOQA2oPBHpiYcjSg
drwxr-xr-x. 4 wazuh-indexer wazuh-indexer 29 Sep 18 19:32 bl7jywZ0ScW7eoMDq9vfrQ
drwxr-xr-x. 6 wazuh-indexer wazuh-indexer 47 Sep 18 19:32 pEYzQRh9Q3SuMYEKpI22fA
Any advice would be helpful, we're pretty new at using wazuh and I can't find anything that has solved this issue.
Thanks,
Vaughn Hawk