# An unknown error occurred sending a bulk request to Elasticsearch. We will retry indefinitely {:error\_message=\>"\\"\\\\xB0\\" from ASCII-8BIT to UTF-8"

**URL:** <https://discuss.elastic.co/t/an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch-we-will-retry-indefinitely-error-message-xb0-from-ascii-8bit-to-utf-8/220906>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [February 25, 2020, 6:22pm UTC](https://discuss.elastic.co/t/an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch-we-will-retry-indefinitely-error-message-xb0-from-ascii-8bit-to-utf-8/220906 "2020-02-25T18:22:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![m.a\_farazuddin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m.a_farazuddin/32/57923_2.png) [@m.a\_farazuddin](https://discuss.elastic.co/u/m.a_farazuddin)\
**Post date:** [February 25, 2020, 6:22pm UTC](https://discuss.elastic.co/t/an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch-we-will-retry-indefinitely-error-message-xb0-from-ascii-8bit-to-utf-8/220906/1 "2020-02-25T18:22:13Z")

</div>

I am trying to query v$active\_session\_history table from logstash with below config file and I bump into the error due to column XID of RAW Type - I am also using container to set up my ELK configuration

I am trying to replicate this set up [https://www.elastic.co/blog/visualising-oracle-performance-data-with-the-elastic-stack](https://www.elastic.co/blog/visualising-oracle-performance-data-with-the-elastic-stack)

The XID column is defined as RAW type in it's description - RAW type converts to byte type while using JDBC - [https://docs.oracle.com/cd/B19306\_01/java.102/b14188/datamap.htm](https://docs.oracle.com/cd/B19306_01/java.102/b14188/datamap.htm)

I am pretty sure I need to convert this particular column to a datatype elastic search understand

But I am not sure how it is done - Appreciate help

input {  
jdbc {  
jdbc\_validate\_connection =\> true  
jdbc\_connection\_string =\> "jdbc:oracle:thin:@[//16.16.16.16:1621/DB](https://16.16.16.16:1621/DB)"  
jdbc\_user =\> "username"  
jdbc\_password =\> "password"  
jdbc\_driver\_library =\> "/opt/ojdbc7.jar"  
jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver"  
statement =\> "SELECT XID FROM V$ACTIVE\_SESSION\_HISTORY WHERE SAMPLE\_TIME \> :sql\_last\_value"  
codec =\> plain { charset =\> "ASCII-8BIT" }  
last\_run\_metadata\_path =\> "/tmp/logstash-oradb.lastrun"  
record\_last\_run =\> true  
schedule =\> "\*/2 \* \* \* \*"  
}  
}

filter {

```
     mutate { convert => ["sample_time" , "string"]}
     date { match => ["sample_time", "ISO8601"]}
     mutate { remove_field => ["force_matching_signature"] }
    }

```

output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
index=\> "logstash-%{+dd.MM.YYYY}"  
}  
}

Full Error Logs

An unknown error occurred sending a bulk request to Elasticsearch. We will retry indefinitely  
{:error\_message=\>""\x87" from ASCII-8BIT to UTF-8", :error\_class=\>"LogStash::Json::GeneratorError",  
:backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/json.rb:27:in `jruby_dump'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/http_client.rb:119:in `block in bulk'",  
"org/jruby/RubyArray.java:2580:in `map'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/http_client.rb:119:in `block in bulk'",  
"org/jruby/RubyArray.java:1814:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/http_client.rb:117:in `bulk'",  
"/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/common.rb:365:in `safe_bulk'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/common.rb:268:in `submit'",  
"/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/common.rb:236:in `retrying_submit'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.0-java/lib/logstash/outputs/elasticsearch/common.rb:40:in `multi\_receive'",  
"org/logstash/config/ir/compiler/OutputStrategyExt.java:118:in `multi_receive'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:101:in `multi\_receive'",  
"/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:262:in `block in start\_workers'"]}

---

<div class="post-metadata">

**Author:** ![m.a\_farazuddin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m.a_farazuddin/32/57923_2.png) [@m.a\_farazuddin](https://discuss.elastic.co/u/m.a_farazuddin)\
**Post date:** [February 26, 2020, 9:42pm UTC](https://discuss.elastic.co/t/an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch-we-will-retry-indefinitely-error-message-xb0-from-ascii-8bit-to-utf-8/220906/2 "2020-02-26T21:42:07Z")

</div>

I understood this as the Blob object of Oracle is causing it

{  
"xid" =\> #\<Sequel::SQL::Blob:0xea1c0 bytes=8 content="K\x00\e\x003\xBC\x00\x00"\>,  
"@version" =\> "1",  
"@timestamp" =\> 2020-02-26T20:10:14.105Z  
}

I came across a blog that there is a patch to this - I will update if I learn anything by applying the patch

> [@Jdbc input for oracle blob field error](https://discuss.elastic.co/t/jdbc-input-for-oracle-blob-field-error/139861/7):
>
> I've pushed a fix to the codec, but am waiting for a teammate to review before we publish the updated Gem. If you want, you can edit your local gem to apply the patch manually, which will circumvent the bundler issues (we can chase those down in a separate thread if they continue to get in the way). change into the current plugin's directory, likely something like:cd ${LOGSTASH\_HOME}/vendor/bundle/jruby/2.3.0/gems/logstash-input-jdbc-4.3.9 download the .patch from [logstash-plugins/logstash-…](https://github.com/logstash-plugins/logstash-input-jdbc/pull/291)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2020, 9:42pm UTC](https://discuss.elastic.co/t/an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch-we-will-retry-indefinitely-error-message-xb0-from-ascii-8bit-to-utf-8/220906/3 "2020-03-25T21:42:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
