# Attempted to send a bulk request to Elasticsearch failed ClientProtocolException

**URL:** <https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720>\
**Category:** Logstash\
**Created:** [October 26, 2021, 5:21pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720 "2021-10-26T17:21:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![makinda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/makinda/32/79805_2.png) [@makinda](https://discuss.elastic.co/u/makinda)\
**Post date:** [October 26, 2021, 5:21pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720/1 "2021-10-26T17:21:55Z")

</div>

I am using Elasticsearch-2.3.1 and logstash-2.3.4 since quite long. Today I found a following warning in Elastic Search. I was trying to copy the logs but I think I press Ctrl+C and then an option appear to stop a job, I forgot the detail/name but I choose No/n. Then I also restarted the elasticsearch but thereafter I am getting following logstash errors.

Can you kindly guide me what is the issue?

**NOTE** : elasticsearch url [http://localhost:9200/](http://localhost:9200/) is active and search is also working. Logstash and Elasticsearch both are running on same server. No changes are made on server including java version etc.

**Elasticsearch Warning** :

> [2021-10-11 21:25:33,048][WARN][cluster.routing.allocation.decider] [Quentin Quire] high disk watermark [90%] exceeded on [MSVQqunPRa2EwaDl03eGlw][Quentin Quire][C:\elasticsearch-2.3.1\data\elasticsearch\nodes\0] free: 2.6gb[8.8%], shards will be relocated away from this node

**Logstash error** :

> [31mAttempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200](http://localhost:9200)", "[http://localhost:9300](http://localhost:9300)"]', but an error occurred and it failed! Are you sure you can reach elasticsearch from this machine using the configuration provided? {:error\_message=\>"The server failed to respond with a valid HTTP response", :error\_class=\>"Manticore::ClientProtocolException", :backtrace=\>["C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/manticore-0.6.0-java/lib/manticore/response.rb:37:in `initialize'", "org/jruby/RubyProc.java:281:in `call'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/manticore-0.6.0-java/lib/manticore/response.rb:79:in `call'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/manticore-0.6.0-java/lib/manticore/response.rb:256:in `call\_once'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/manticore-0.6.0-java/lib/manticore/response.rb:153:in `code'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/http/manticore.rb:84:in `perform\_request'", "org/jruby/RubyProc.java:281:in `call'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/base.rb:257:in `perform\_request'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/transport/http/manticore.rb:67:in `perform_request'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/transport/client.rb:128:in `perform\_request'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.18/lib/elasticsearch/api/actions/bulk.rb:90:in `bulk'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:53:in `non\_threadsafe\_bulk'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:38:in `bulk'", "org/jruby/ext/thread/Mutex.java:149:in `synchronize'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:38:in `bulk'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:172:in `safe\_bulk'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:101:in `submit'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:86:in `retrying\_submit'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:29:in `multi_receive'", "org/jruby/RubyArray.java:1653:in `each\_slice'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:28:in `multi_receive'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/output_delegator.rb:130:in `worker\_multi\_receive'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/output\_delegator.rb:114:in `multi_receive'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:301:in `output\_batch'", "org/jruby/RubyHash.java:1342:in `each'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:301:in `output\_batch'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:232:in `worker_loop'", "C:/elasticsearch-2.3.1/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:201:in `start\_workers'"], :level=\>:error}[0m

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2021, 10:37pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720/2 "2021-10-26T22:37:13Z")

</div>

Welcome to our community! 😃

Elasticsearch 2.X is very, very old and long past [EOL](https://www.elastic.co/support/eol). As such it's no longer supported and you need to upgrade.

> [@makinda](#):
>
> high disk watermark [90%] exceeded

You've run out of disk space on the node, so you should check that.

---

<div class="post-metadata">

**Author:** ![makinda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/makinda/32/79805_2.png) [@makinda](https://discuss.elastic.co/u/makinda)\
**Post date:** [October 27, 2021, 1:00pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720/3 "2021-10-27T13:00:05Z")

</div>

Thank you very much for your reply and welcome message.

From logs it looks like that the disk has less storage but 4.88 GB is free for usage.

The update of Elasticsearch is planned but cannot be done immediately.

Do you know why I get the error in Logstash console? How can it can be resolved?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 27, 2021, 1:43pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720/4 "2021-10-27T13:43:05Z")

</div>

You need to free some space, Elasticsearch won't allow any writtings until you free up some space in the disk, so when Logstash tries to index some data, it will get an error.  
  
You will need to delete some indices or delete something else in your `C:\` drive that will free up some space.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2021, 1:43pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720/5 "2021-11-24T13:43:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
