I have a rather large deployment that seems to have difficulty identifying the indices required to open in order to perform a search. When I run a search on the last 5 mins I expect the current indice to be the only indice opened in order to fulfill the query (if the indice holds more than 5mins which it does), is that not a correct assumption?
I have rerun the maintenance job a few times to recalculate the ranges but it doesn’t seem to have helped. I can’t see any errors in the logs, is there anything I should be investigating further?
I have 700+ indices, replicated 3 times at 50GB each across 25+ ES nodes storing about ~40TB of data for reference. Ingestion rate is about 7500 msgs/sec. 3 Graylog nodes, about to be expanded to 4 possibly 5. ES 2.3.4 Centos 7.2 Graylog 2.2.0-11 java 22.214.171.124-2