OpenShift Logging Sharding
Issue
- We are receiving hundreds of thousands of errors in the kibana-ops interface for OpenShift and don't understand the root cause.
HTTP InternalServerError: Internal Error: unable to find Docker container
- We see A lot of the following error in the Kibana interface:
Index: .operations.<DATE> Shard: 1 Reason: RemoteTransportException[[Bedlam II][inet[/<IP>:<PORT>]][indices:data/read/search[phase/query]]]; nested: ElasticsearchException[org.elasticsearch.common.breaker.CircuitBreakingException: [FIELDDATA] Data too large, data for [time] would be larger than limit of [2566520832/2.3gb]]; nested: UncheckedExecutionException[org.elasticsearch.common.breaker.CircuitBreakingException: [FIELDDATA] Data too large, data for [time] would be larger than limit of [2566520832/2.3gb]]; nested: CircuitBreakingException[[FIELDDATA] Data too large, data for [time] would be larger than limit of [2566520832/2.3gb]];
Environment
- OpenShift Enterprise 3.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.