Thanks for the reply. Every time i restart the elk cluster nodes, is the SG needs to be initialized or is the SG index gets intialized automatically. What i found is , if the master node changes in ELK, the SG Intialization doesnt happen or take a long time to initialize .
@amalk12 The SG is initialized once by executing sgadmin.sh script and uploading an initial configuration. SG won’t initialize again after each restart. However, if you’re using a docker or Kubernetes solution where you delete all the storage after stopping all containers then SG will be initialized at every new deployment.
Once the SG is initialized you should see searchguard index in the Elasticsearch cluster.
How big is your cluster?
Do you assign specific roles to your ES nodes? If yes, could you share how many nodes of each role you have in the cluster?