记一个elk异常处理

一、kibana现象一直没看到有数据进来,怀疑是否是logstash挂了json

二、查看logstash日志发现api

[INFO ][logstash.outputs.elasticsearch] retrying failed action with response code: 403 ({"type"=>"cluster_block_exception", "reason"=>"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"})

三、查找、分析elasticsearch

报错关键index read-only/allow delete,查阅相关资料是ES配置read_only_allow_delete设置为true了,日志

经过kibana dev tools GET _settings调用api看到每一个索引的read_only_allow_delete都是truecode

GET _settings

四、解决索引

PUT _settings 
{   
    "index": {
         "blocks": {
             "read_only_allow_delete": "false"
         }   
    } 
}
相关文章
相关标签/搜索