記一個elk異常處理

一、kibana現象一直沒看到有數據進來,懷疑是否是logstash掛了json

二、查看logstash日誌發現api

[INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})

三、查找、分析elasticsearch

報錯關鍵index read-only/allow delete,查閱相關資料是ES配置read_only_allow_delete設置爲true了,日誌

經過kibana dev tools GET _settings調用api看到每一個索引的read_only_allow_delete都是truecode

GET _settings

四、解決索引

PUT _settings 
{   
    "index": {
         "blocks": {
             "read_only_allow_delete": "false"
         }   
    } 
}
相關文章
相關標籤/搜索