Links: https://www.twblogs.net/a/5db3634abd9eee310da04462
Ta thấy lỗi tương tư như dưới
[WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>[“index”, {:_id=>nil, :_index=>”logstash-2019.10.14″, :_type=>”doc”, :_routing=>nil}, #<LogStash::Event:0x390305bb>], :response=>{“index”=>{“_index”=>”logstash-2019.10.14”, “_type”=>”doc”, “_id”=>”S-f0yG0BAZNQsWN8qxcz”, “status”=>400, “error”=>{“type”=>”illegal_argument_exception”, “reason”=>”Limit of total fields [1000] in index [logstash-2019.10.14] has been exceeded”}}}}
Sử lý lỗi tạm thời:
$ curl -X PUT -H "Content-Type: application/json" -d '{"index.mapping.total_fields.limit":2000}' http://elasticserver:9200/logstash-2019.10.14/_settings
{"acknowledged":true}
Giải quyết vấn đề vĩnh viễn,
curl -X PUT -H "Content-Type: application/json" -d '{"template": "logstash-*","settings":{"index.mapping.total_fields.limit":2000}}' http://elasticserver:9200/_template/logstash
logstash-2019.10.14: đây là index đang bị báo vượt ngưỡng nhé
curl -X PUT -u user:pass -H "Content-Type: application/json" -d '{"index.mapping.total_fields.limit":2000}' http://localhost:9200/logstash-2021.05.30-000002/_settings {"acknowledged":true}