ELK5.4 modifies the number of fragments and the way they are allocated
1. Modify the number of fragments
The default number of fragments for elasticsearch is 5 and the number of copies is 1. If you need to modify the number of fragments, there are two ways
1. Modify the index settings
View index status: curl-GET "http://localhost:9200/index/__settings"
Modify index status information:
Curl-XPUT 'localhost:9200/index/_settings'-d' {"index": {"number_of_replicas": 6, "number_of_replicas": 2}}'
This approach can only be modified individually for an index. If you need to modify all indexes uniformly, you need to modify the template information
2. Modify the template
# get default template information
Curl-XGET http://localhost:9200/_template/logstash
# Delete default template
Curl-XDELETE http://localhost:9200/_template/logstash
# upload the modified default template
Curl-XPUT http://localhost:9200/_template/logstash-d'{"template": "logstash-*", "settings": {"index": {"number_of_replicas": "2", "number_of_shards": "6", "refresh_interval": "5s"}} "mappings": {"_ default_": {"dynamic_templates": [{"message_field": {"path_match": "message" "mapping": {"norms": false, "type": "text"} "match_mapping_type": "string"}, {"string_fields": {"mapping": {"norms": false "type": "text" "fields": {"keyword": {"type": "keyword"} "match_mapping_type": "string", "match": "*"}}], "_ all": {"norms": false "enabled": true}, "properties": {"@ timestamp": {"include_in_all": false, "type": "date"} "geoip": {"dynamic": true, "properties": {"ip": {"type": "ip"} "latitude": {"type": "half_float"}, "location": {"type": "geo_point"} "longitude": {"type": "half_float"}}, "@ version": {"include_in_all": false "type": "keyword"}, "aliases": {}}'
II. Slice distribution
By default, shard shards are roughly balanced, but the allocation of primary main shards is uneven (an ES restart or cluster node change)
Shard Allocation Settingsedit
The following dynamic settings may be used to control shard allocation and recovery:
Cluster.routing.allocation.enable
Enable or disable allocation for specific kinds of shards:
All-(default) Allows shard allocation for all kinds of shards.
Primaries-Allows shard allocation only for primary shards.
New_primaries-Allows shard allocation only for primary shards for new indices.
None-No shard allocations of any kind are allowed for any indices.
The above parameter sets the way in which parts are allocated.
PUT _ cluster/settings {"transient": {"cluster.routing.allocation.enable": primaries}}