The "Limit of total fields [1000] in index [audit-0000XX] has been exceeded " messages in elasticsearch pod logs in OCP
Issue
-
The
elasticsearchpods are throwing error messages similar to:Limit of total fields [1000] in index [audit-000094] has been exceeded
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5
- Elasticsearch
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.