Sometimes Could not execute search after 14 days

Hi All, I am opening the same ticket again because I am not able to find the solution. Please help me with this.

I am able to search logs till 14 days in graylog but if I search for 30 days or 60 days it prompt could not execute search error. Please help me to solve this problem. Also sometimes working for 30 days or 60 days but not always. Not able to understand the exact reason why it’s happening. Also not getting any index specific error.

Details message only print: Unable to perform search query.

What to do in this case?

Thanks

  1. This is not a ticket system - it is a forum. That is why you post here and not opening a ticket.
  2. Why you did not reference your already written posting when you mention it in the text?

I guess that you tamper the ES indices outside of Graylog direct with the Elasticsearch API, Curator or any other tool. In the end, the result is that Graylog is not away what is possible to search in what indices.

Should you modify any Index outside of Graylog, or have your above mentioned issues. Re-calculate the index range in System > indices > index name > maintanance

1 Like

Yup it is a forum. By mistake written ticket.

Reference to already written post: Unable to perform search query after 14 days

Here is my Index Set settings

43%20PM

Did you read my last posting till the end?

Should you modify any Index outside of Graylog, or have your above mentioned issues. Re-calculate the index range in System > indices > index name > maintanance

1 Like

Four shards, zero replicas.

  • Silly question, but could it be you run an Elastic cluster and that one or more nodes are down?
  • Or could it be that someone has manually mucked around in Elastic or even worse: with its files on the file system?
  • What are your retention policies on the index?

What are your retention policies on the index?

You see in the image - 360 indices, every 6 hours rotation what makes 90 days.

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.