# Attempted to send a bulk request to Elasticsearch configured at

**URL:** <https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671>\
**Category:** Logstash\
**Created:** [August 10, 2016, 8:52am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671 "2016-08-10T08:52:44Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 8:52am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/1 "2016-08-10T08:52:45Z")

</div>

hi I have an issue with logstash -\>searchguard (elasticserach) ?  
works fine without searchguard

output {  
elasticsearch {  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
ssl =\> true  
ssl\_certificate\_verification =\> true  
keystore =\> '/opt/logstash/localhost.jks'  
keystore\_password =\> '\*\*\*\*\*\*\*'  
truststore =\> '/opt/logstash/truststore.jks'  
truststore\_password =\> '\*\*\*\*\*\*\*\*'  
}  
stdout { codec =\> rubydebug }  
}

{:timestamp=\>"2016-08-09T23:15:42.650000+0100", :message=\>"[401] ",  
:class=\>"Elasticsearch::Transport::Transport::Errors::Unauthorized",  
:backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/base.rb:201  
:in `\_\_raise\_transport\_error'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-

{:timestamp=\>"2016-08-09T23:15:44.667000+0100", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[https://127.0.0.1:9200](https://127.0.0.1:9200)"]', but an error occurred and it failed! Are you sure you can reach elasticsearch from this machine using the configuration provided?", :error\_message=\>"[401] ", :error\_class=\>"Elasticsearch::Transport::Transport::Errors::Unauthorized", :backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/base.rb:201:in `__raise_transport_error'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/base.rb:312 :in`perform\_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/http/manticore.rb:67  
:in `perform_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/client.rb:128 :in`perform\_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.18/lib/elasticsearch/api/actions/bulk.rb:90:in `bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:53 :in`non\_threadsafe\_bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:38:in `bulk'", "org/jruby/ext/thread/Mutex.java:149 :in`synchronize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:38:in `bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:172:in`safe\_bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:101  
:in `submit'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:86 :in`retrying\_submit'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:29  
:in `multi_receive'", "org/jruby/RubyArray.java:1653:in`each\_slice'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:28

please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 9:07am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/2 "2016-08-10T09:07:47Z")

</div>

It looks like your ES server requires you to authenticate but you haven't provided any username and password.

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 9:41am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/3 "2016-08-10T09:41:34Z")

</div>

cool thanks magnusbaeck :=), that error is fixed but I see now nothing happening in Logstash or Elasticsearch when I push logs from filebeat

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

output {  
elasticsearch {  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
user =\> logstash  
password =\> \*\*\*\*\*  
ssl =\> true  
ssl\_certificate\_verification =\> true  
keystore =\> '/opt/logstash/localhost-keystore.jks'  
keystore\_password =\> '**'  
truststore =\> '/opt/logstash/truststore.jks'  
truststore\_password =\> '**\*'  
}  
stdout { codec =\> rubydebug }  
}

Logstash  
{:timestamp=\>"2016-08-10T01:23:46.135000+0100", :message=\>"Pipeline main started"}

Elasticsearch  
[2016-08-09 23:09:54,784][INFO][node] [Typhoid Mary] started  
[2016-08-09 23:09:54,936][INFO][gateway] [Typhoid Mary] recovered [1] indices into cluster\_state  
[2016-08-09 23:09:55,754][INFO][cluster.routing.allocation] [Typhoid Mary] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[.kibana][2], [.kibana][2]] ...]).  
[2016-08-09 23:10:00,200][INFO][cluster.metadata] [Typhoid Mary] [searchguard] creating index, cause [api], templates [], shards [1]/[0], mappings []  
[2016-08-09 23:10:00,609][INFO][cluster.routing.allocation] [Typhoid Mary] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[searchguard][0]] ...]).  
[2016-08-09 23:10:01,181][INFO][cluster.metadata] [Typhoid Mary] [searchguard] create\_mapping [config]  
[2016-08-09 23:10:01,685][INFO][cluster.metadata] [Typhoid Mary] [searchguard] create\_mapping [roles]  
[2016-08-09 23:10:01,826][INFO][cluster.metadata] [Typhoid Mary] [searchguard] create\_mapping [rolesmapping]  
[2016-08-09 23:10:01,979][INFO][cluster.metadata] [Typhoid Mary] [searchguard] create\_mapping [internalusers]  
[2016-08-09 23:10:02,100][INFO][cluster.metadata] [Typhoid Mary] [searchguard] create\_mapping [actiongroups]

filebeat:  
2016/08/10 09:35:59.023799 prospector.go:143: INFO Starting prospector of type: log  
2016/08/10 09:35:59.024135 crawler.go:78: INFO All prospectors initialised with 1 states to persist  
2016/08/10 09:35:59.024156 registrar.go:87: INFO Starting Registrar  
2016/08/10 09:35:59.024190 publish.go:88: INFO Start sending events to output  
2016/08/10 09:35:59.024249 spooler.go:77: INFO Starting spooler: spool\_size: 2048; idle\_timeout: 5s  
2016/08/10 09:35:59.024419 log.go:113: INFO Harvester started for file: /Users/BUJAR/IdeaProjects/dropwizard-metrices-example/myapplication.log  
2016/08/10 09:36:21.528929 publish.go:109: DBG Publish: {  
"@timestamp": "2016-08-10T09:36:14.028Z",  
"beat": {  
"hostname": "Bujars-MacBook-Pro.local",  
"name": "Bujars-MacBook-Pro.local"  
},  
"count": 1,  
"input\_type": "log",  
"message": "INFO [2016-08-10 09:36:12,882] com.metrices.example.resource.ExampleResource: value='Hello, 2312313!",  
"offset": 248140,  
"service": "my example service",  
"source": "/Users/BUJAR/IdeaProjects/dropwizard-metrices-example/myapplication.log",  
"type": "log"  
}  
2016/08/10 09:36:21.529044 publish.go:109: DBG Publish: {  
"@timestamp": "2016-08-10T09:36:14.028Z",  
"beat": {  
"hostname": "Bujars-MacBook-Pro.local",  
"name": "Bujars-MacBook-Pro.local"  
},  
"count": 1,  
"input\_type": "log",  
"message": "INFO [2016-08-10 09:36:12,882] com.metrices.example.resource.ExampleResource: counter='6",  
"offset": 248242,  
"service": "my example service",  
"source": "/Users/BUJAR/IdeaProjects/dropwizard-metrices-example/myapplication.log",  
"type": "log"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 9:43am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/4 "2016-08-10T09:43:57Z")

</div>

Does Logstash's stdout output produce any output, i.e. is there any evidence that Logstash is receiving any data?

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 10:06am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/5 "2016-08-10T10:06:52Z")

</div>

I believe it's working

{  
"message" =\> "INFO [2016-08-10 10:02:20,591] org.eclipse.jetty.server.ServerConnector: Started admin@5fcacc0{HTTP/1.1}{0.0.0.0:8081}",  
"@version" =\> "1",  
"@timestamp" =\> "2016-08-10T10:03:35.612Z",  
"beat" =\> {  
"hostname" =\> "Bujars-MacBook-Pro.local",  
"name" =\> "Bujars-MacBook-Pro.local"  
},  
"offset" =\> 260003,  
"type" =\> "log",  
"service" =\> "my example service",  
"input\_type" =\> "log",  
"count" =\> 1,  
"source" =\> "/Users/BUJAR/IdeaProjects/dropwizard-metrices-example/myapplication.log",  
"host" =\> "Bujars-MacBook-Pro.local",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
]  
}  
{  
"message" =\> "INFO [2016-08-10 10:02:20,591] org.eclipse.jetty.server.Server: Started @4208ms",  
"@version" =\> "1",  
"@timestamp" =\> "2016-08-10T10:03:35.612Z",  
"source" =\> "/Users/BUJAR/IdeaProjects/dropwizard-metrices-example/myapplication.log",  
"type" =\> "log",  
"input\_type" =\> "log",  
"count" =\> 1,  
"service" =\> "my example service",  
"beat" =\> {  
"hostname" =\> "Bujars-MacBook-Pro.local",  
"name" =\> "Bujars-MacBook-Pro.local"  
},  
"offset" =\> 260123,  
"host" =\> "Bujars-MacBook-Pro.local",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
]  
}

this is the output from logstash.stdout

thank you very much magnusbaeck 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 10:42am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/6 "2016-08-10T10:42:28Z")

</div>

And how do you conclude that there's nothing happening on the ES side? Where are you looking?

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 11:02am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/7 "2016-08-10T11:02:48Z")

</div>

i am checking elasticsearch.log and I see no activity

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 11:04am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/8 "2016-08-10T11:04:37Z")

</div>

when I connect with Kibana I can see that I am hitting elasticsearch from elasticsearch.log but I am getting perm issue  
[2016-08-10 12:00:25,420][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:00:32,414][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:00:39,413][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:00:46,421][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:00:53,424][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:00,437][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:07,423][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:14,446][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:21,416][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:28,543][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:35,411][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]  
[2016-08-10 12:01:41,796][INFO][com.floragunn.searchguard.configuration.PrivilegesEvaluator] No perm match for indices:data/read/field\_stats and [sg\_kibana4\_server, sg\_public]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 11:12am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/9 "2016-08-10T11:12:58Z")

</div>

> i am checking elasticsearch.log and I see no activity

That's not a very good test since Elasticsearch doens't log that much during normal operations. I suggest you use the [cat indices](https://www.elastic.co/guide/en/elasticsearch/reference/current/cat-indices.html) API to see which indices you have, how many documents they contain, etc.

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 12:04pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/10 "2016-08-10T12:04:04Z")

</div>

thanks magnusbaeck but i get nothing when I do

curl -k [https://localhost:9200/\_cat/indices/twi\*?v](https://localhost:9200/_cat/indices/twi*?v)  
curl --cacert /tmp/example-pki-scripts/ca/root-ca.pem [https://localhost:9200/\_cat/indices/twi\*?v](https://localhost:9200/_cat/indices/twi*?v)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2016, 12:05pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/11 "2016-08-10T12:05:48Z")

</div>

The "twi" part of the documentation was an example. Remove it.

---

<div class="post-metadata">

**Author:** ![bujar\_metaj](https://avatars.discourse-cdn.com/v4/letter/b/a9a28c/32.png) [@bujar\_metaj](https://discuss.elastic.co/u/bujar_metaj)\
**Post date:** [August 10, 2016, 12:31pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/12 "2016-08-10T12:31:11Z")

</div>

still nothing  
curl --cacert /tmp/example-pki-scripts/ca/root-ca.pem [https://localhost:9200/\_cat/indices](https://localhost:9200/_cat/indices)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-configured-at/57671/13 "2017-07-06T04:44:02Z")

</div>


