Elasticsearch 7.5.2集群默认仅创建1个分片问题排查求助
Hey there, let's figure out why your new Elasticsearch 7.5.2 cluster is creating indexes with only 1 primary shard by default, even with your 5-node setup. Let's break down the possible causes and how to check them:
First: Check Elasticsearch 7.x Default Behavior
A key detail you might have missed: Elasticsearch 7.x changed the default number of primary shards from 5 to 1 for all new indexes. This is an intentional design choice—modern Elasticsearch shards are more efficient, and 1 shard is sufficient for most small-to-medium datasets. So this could just be the out-of-the-box behavior, not an issue with your cluster architecture or missing settings.
1. Verify Index Templates
Index templates can override default index configurations, including shard counts. Even if you didn't create custom templates, Elasticsearch has built-in templates that might be influencing this:
- Run this command to list all existing templates:
GET _template - Look for any template (especially those with a
patternmatching all indexes, like*) that includes this setting:"settings": { "index": { "number_of_shards": 1 } }
If such a template exists, it’s confirming the default (though in 7.x, this is already the default value).
2. Check Cluster-Level Default Settings
Even if you don’t remember setting it, double-check for cluster-wide persistent/transient settings that enforce 1 shard:
- Run this command to retrieve cluster settings:
GET _cluster/settings - Look for entries under
persistent.index.number_of_shardsortransient.index.number_of_shards. If either is set to 1, that’s enforcing the default. Note: A fresh 7.x cluster won’t have these settings unless you explicitly added them.
3. Your Cluster Architecture Isn’t the Problem
Your node setup (2 dedicated masters, 1 master+data, 2 dedicated data nodes) doesn’t impact the default shard count. Shard count is an index-level configuration, and the cluster will easily allocate 1 shard across your data nodes regardless of node count or roles. Your architecture is valid and not causing the 1-shard default.
How to Change the Default Shard Count (If Needed)
If you want new indexes to use more primary shards by default, you have two reliable options:
Option 1: Set a Cluster-Wide Default
Update the persistent cluster settings to override the default:
PUT _cluster/settings { "persistent": { "index.number_of_shards": 3 # Adjust to your desired number } }
Option 2: Create a Global Index Template
Make a template that matches all new indexes and defines the shard count:
PUT _template/default_shard_template { "index_patterns": ["*"], "priority": 1, "settings": { "index.number_of_shards": 3 } }
Note: Use a priority higher than any existing conflicting templates to ensure this one takes effect.
Final Note
Before increasing the default shard count, confirm you actually need it. Elasticsearch 7.x’s default of 1 shard works well for most use cases—extra shards add unnecessary overhead if your dataset is small. Only adjust the count if you’re handling multi-GB+ datasets or have specific query performance requirements.
内容的提问来源于stack exchange,提问作者Damacharla Ashok Kumar

