创建Index Pattern时Kibana抛出429(请求过多)错误的原因排查
Alright, let's break down that frustrating 429 "Too Many Requests" error you're hitting when trying to create an index pattern—even with your tiny 150KB index and after restarting Elasticsearch and Kibana. Here are the most likely causes and fixes:
1. Kibana's Built-in Rate Limiting Triggered
Kibana comes with default rate limits on its API endpoints (especially the saved_objects ones used for index patterns) to prevent abuse. Even if you didn't intentionally spam requests, accidental repeated clicks, browser background retries, or a previous failed attempt could have tripped this limit.
Fix:
- Temporarily adjust the rate limit settings in your
kibana.ymlfile:# Option 1: Disable rate limiting entirely (for debugging only—re-enable in production!) xpack.security.rateLimit.enabled: false # Option 2: Increase the threshold (more production-friendly) xpack.security.rateLimit.limit: 1000 # Number of allowed requests xpack.security.rateLimit.window: 60000 # Time window in milliseconds (60 seconds here) - Save the file, then fully restart Kibana (make sure the old process is killed first, more on that below).
2. Browser-Side Request Spam or Caching
Sometimes your browser can get stuck sending repeated failed requests in the background, or cached failed requests can trigger the rate limit over and over.
Fix:
- Try opening Kibana in an incognito/private browsing window—this avoids cached data and background requests.
- Clear your browser's cache and cookies for the Kibana domain, then reload the page and try again.
- Check your browser's DevTools (Network tab) to see if there are multiple repeated requests to
/api/saved_objects/index-pattern—if so, stop those requests manually before retrying.
3. Unclean Kibana Restart
A simple restart might not have fully killed the old Kibana process, meaning the rate limit state is still being maintained by the leftover process.
Fix:
- For Linux/macOS:
# Find all Kibana processes ps aux | grep kibana # Kill each process (replace <PID> with the process ID) kill -9 <PID> - For Windows: Open Task Manager, find the Kibana process, end it, then restart Kibana.
4. Elasticsearch's Request Throttling (Less Likely, But Worth Checking)
While your index is small, Elasticsearch might have its own request throttling or security-related limits that are affecting Kibana's ability to fetch index metadata.
Fix:
- Check Elasticsearch's logs (usually in
logs/elasticsearch.log) for any entries about rejected requests or rate limiting. - Test the Kibana API directly with curl to isolate the issue:
If you get a 429 here too, the issue is definitely on the Kibana side. If you get a different error, it might point to an Elasticsearch permission or connectivity problem.curl -X GET http://localhost:5601/api/saved_objects/index-pattern
内容的提问来源于stack exchange,提问作者bcsta

