You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Kibana Discover模块使用时遭遇search_phase_execution_exception错误

解决Kibana Discover查看Filebeat同步索引时的search_phase_execution_exception错误

问题描述

在Linux服务器部署Filebeat后,已完成索引、索引模板、索引模式的创建,Filebeat也成功将文档同步到Elasticsearch,但在Kibana Discover模块查看该索引日志时触发search_phase_execution_exception错误,提示所有分片失败。当前Elasticsearch分片状态全绿,内存和存储空间充足,且Discover对其他索引正常,删除重建索引后问题依旧。

错误信息

search_phase_execution_exception
all shards failed

Error
    at Fetch._callee3$ (https://demo.business.com/logs/36136/bundles/core/core.entry.js:6:59535)
    at l (https://demo.business.com/logs/36136/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:982071)
    at Generator._invoke (https://demo.business.com/logs/36136/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:981824)
    at forEach.e.<computed> [as next] (https://demo.business.com/logs/36136/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:380:982428)
    at fetch_asyncGeneratorStep (https://demo.business.com/logs/36136/bundles/core/core.entry.js:6:52652)
    at _next (https://demo.business.com/logs/36136/bundles/core/core.entry.js:6:52968)

排查与解决步骤

1. 调用Elasticsearch API获取详细错误

直接通过_search接口测试索引,获取分片失败的具体原因:

curl -X GET "http://<es-host>:<port>/<你的索引名>/_search?q=*&size=1"

常见触发原因是字段类型冲突(如同一字段在不同文档中同时存在字符串、数值类型),或@timestamp字段不是date类型。

2. 检查索引字段映射

查看索引的字段类型配置,重点确认Kibana依赖的核心字段:

curl -X GET "http://<es-host>:<port>/<你的索引名>/_mapping"

确保@timestamp字段类型为date,自定义字段无类型冲突。

3. 验证Filebeat索引模板

确认索引模板是否正确应用,且映射配置无错误:

curl -X GET "http://<es-host>:<port>/_index_template/<filebeat模板名>"

若模板存在问题,重新生成默认模板:

filebeat setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["<es-host>:<port>"]'

4. 重新配置Kibana索引模式

  • 删除现有索引模式,重新创建时确保时间字段选择正确(通常为@timestamp),且该字段在索引中确实是date类型。
  • 检查索引模式的字段过滤规则,避免误隐藏关键字段导致Discover加载失败。

5. 查看Elasticsearch底层日志

从Elasticsearch Pod日志中搜索该索引的分片错误,获取更底层的失败细节:

kubectl logs -f <es-pod名称> -n <命名空间>

6. 测试单文档搜索

从索引中取一个文档ID,单独搜索验证文档本身是否正常:

curl -X GET "http://<es-host>:<port>/<你的索引名>/_doc/<文档ID>"

若单文档能正常返回,问题大概率出在批量搜索或字段聚合逻辑上,需重点排查字段异常值或类型冲突。

内容的提问来源于stack exchange,提问作者vishal mehra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 08:31:02