Replies: 1 comment
-
That is becuase the manager has the data role. In distributed grids, it is necessary as the grid is installed, but once installation is completed, you can |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Version
2.4.40
Installation Method
Security Onion ISO image
Description
configuration
Installation Type
Distributed
Location
on-prem with Internet access
Hardware Specs
Exceeds minimum requirements
CPU
60
RAM
120
Storage for /
500BG
Storage for /nsm
7TB
Network Traffic Collection
tap
Network Traffic Speeds
Less than 1Gbps
Status
Yes, all services on all nodes are running OK
Salt Status
Yes, there are salt failures (please provide detail below)
Logs
No, there are no additional clues
Detail
In a new installation with 4 nodes (1 separate manager, 2 forward, 1 search), Elasticsearch shards are allocated to the manager.
looks like incorrect Elasticsearch cluster configuration?

If the manager's address is excluded from routing allocation, the shards are stored where they are needed (on the search node).
Guidelines
Beta Was this translation helpful? Give feedback.
All reactions