# Bad Gateway Errors in Discover in Kibana 6.4 on some indices

**URL:** <https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576>\
**Category:** Kibana\
**Created:** [August 29, 2018, 8:02pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576 "2018-08-29T20:02:54Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [August 29, 2018, 8:02pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/1 "2018-08-29T20:02:54Z")

</div>

After upgrading to 6.4 in Elastic Cloud, and using the Discover feature in Kibana, indices are now displaying "Bad Gateway" errors. If the timespan is short and there are no records, the "no records" correctly displays. After expanding the timespan, then the error appears.

User: "superadmin" role

 ![Screenshot_2018-08-29_13_54_40-2](https://us1.discourse-cdn.com/elastic/original/3X/8/2/827a5088f80abe8a69a62aa57ace874119cc70d5.jpeg)

```
The stacktrace of error:

 Fatal Error
Courier fetch: Unable to connect to the server.
Version: 6.4.0
Build: 17929
Error: Bad Gateway
    at respond (https://SNIP/bundles/vendors.bundle.js:313:149378)
    at checkRespForFailure (https://SNIP/bundles/vendors.bundle.js:313:148589)
    at https://SNIP/bundles/vendors.bundle.js:313:157823
    at processQueue (https://SNIP/bundles/vendors.bundle.js:197:199684)
    at https://SNIP/bundles/vendors.bundle.js:197:200647
    at Scope.$digest (https://SNIP/bundles/vendors.bundle.js:197:210409)
    at Scope.$apply (https://SNIP/bundles/vendors.bundle.js:197:213216)
    at done (https://SNIP/bundles/vendors.bundle.js:197:132715)
    at completeRequest (https://SNIP/bundles/vendors.bundle.js:197:136327)
    at XMLHttpRequest.requestLoaded (https://SNIP/bundles/vendors.bundle.js:197:135223)
```

---

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [August 29, 2018, 8:29pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/2 "2018-08-29T20:29:44Z")

</div>

I am seeing the same issue in our environment after it got upgraded to 6.4.0 in Elastic cloud. The most curious thing is that not all index patterns are affected. For me, the `logs-*` works fine but its subset `logs-app-*` does not.

I am really running out of explanations there. Probably worth mentioning that the broken one used to be set as default for Discover search.

---

<div class="post-metadata">

**Author:** ![Manfred.Kiener](https://avatars.discourse-cdn.com/v4/letter/m/49beb7/32.png) [@Manfred.Kiener](https://discuss.elastic.co/u/Manfred.Kiener)\
**Post date:** [August 31, 2018, 7:34am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/3 "2018-08-31T07:34:30Z")

</div>

Same problem for me. In my case I use an alias ("auftrag") which contains also indexnames with more then one dash: "auftrag-2017-20180831-092145-2291992359". Is it a problem with indexnames with more then one dash?  
(6.4.0 on centos)

---

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [August 31, 2018, 3:36pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/4 "2018-08-31T15:36:00Z")

</div>

It failed even for index without hyphens for us.

---

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [August 31, 2018, 5:03pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/5 "2018-08-31T17:03:59Z")

</div>

I just got response from Elastic Support and they somehow managed to fix the issue from their side. What they did is still a mystery but at least it is possible.

---

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [August 31, 2018, 5:08pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/6 "2018-08-31T17:08:32Z")

</div>

Mine hasn't been fixed yet, unfortunately. Also would be nice if recommendation is to post inquiries here, that someone at Elastic acknowledges and updates status here.

---

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [August 31, 2018, 5:12pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/7 "2018-08-31T17:12:16Z")

</div>

But of course! I did reference this discussion in my support ticket. I also asked what to do next time when upgrading to 6.4. This time, it was just Sandbox cluster for us. But one day Production cluster would need to be upgraded too. 🤔

---

<div class="post-metadata">

**Author:** ![vicpav](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vicpav](https://discuss.elastic.co/u/vicpav)\
**Post date:** [August 31, 2018, 7:43pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/8 "2018-08-31T19:43:47Z")

</div>

Some insight of the fix that was applied to our cluster by Elastic Support team (and was found successful in our case):

> Your issue is related to a recently discovered bug with no fix committed to a specific Kibana version yet. If you will be migrating data from your old cluster to a new one - **before** you go to prod, check the status of this [issue](https://github.com/elastic/kibana/issues/22484). If it is fixed by the time you go to prod, deploy on the version with the fix. If it is not fixed yet, then please open a new case and we will make the change necessary to your new cluster before you go live. Please be sure to give us a few days notice.

Hopefully, that could help others who did not start their upgrade yet.

---

<div class="post-metadata">

**Author:** ![cparmar](https://avatars.discourse-cdn.com/v4/letter/c/d26b3c/32.png) [@cparmar](https://discuss.elastic.co/u/cparmar)\
**Post date:** [September 5, 2018, 3:08pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/9 "2018-09-05T15:08:50Z")

</div>

We are also seeing the same issue on our Production instance. I hope there's a fix soon!

---

<div class="post-metadata">

**Author:** ![Chris\_Overton](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@Chris\_Overton](https://discuss.elastic.co/u/Chris_Overton)\
**Post date:** [September 6, 2018, 2:39am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/10 "2018-09-06T02:39:26Z")

</div>

Thanks for posting. If you're having trouble, you can contact our Support for help.

[https://www.elastic.co/support/welcome/cloud](https://www.elastic.co/support/welcome/cloud)

See the "How do I open a case?" section on that page.

---

<div class="post-metadata">

**Author:** ![cparmar](https://avatars.discourse-cdn.com/v4/letter/c/d26b3c/32.png) [@cparmar](https://discuss.elastic.co/u/cparmar)\
**Post date:** [September 6, 2018, 7:30am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/11 "2018-09-06T07:30:57Z")

</div>

We are running a self-hosted solution with a Basic license, will we still be able to receive support?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 6, 2018, 11:21pm UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/12 "2018-09-06T23:21:03Z")

</div>

If you have a support subscription, yes.

The comment from Chris was for anyone using Elastic Cloud.

---

<div class="post-metadata">

**Author:** ![suyograo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suyograo/32/44898_2.png) [@suyograo](https://discuss.elastic.co/u/suyograo)\
**Post date:** [September 7, 2018, 2:21am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/13 "2018-09-07T02:21:54Z")

</div>

This issue has been fixed on Elastic Cloud Service.

This issue manifests only when running Kibana/ES behind a HTTP proxy. As such, this is not specifically a Cloud issue, but since we use a proxy, our users are definitely seeing this.

The underlying issue is that a Kibana \_msearch query is [generating](https://github.com/elastic/kibana/issues/22484) deprecation warnings in ES, which is returned via the HTTP Warning header. ES does not set a cap for the number of warning headers in a HTTP response. The flood of deprecation messages overwhelms the proxy resulting in a 502.

As I mentioned before, this bug can affect all users running ES/Kibana in the context of a proxy, so we're [discussing](https://github.com/elastic/elasticsearch/issues/33479) an ES patch. To mitigate this issue, Cloud has set a limit on the number of HTTP warning messages ES can generate.

---

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [September 11, 2018, 3:17am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/15 "2018-09-11T03:17:12Z")

</div>

This is not fixed on Elastic Cloud Service for me yet. I can click Discover tab in Kibana and navigate to several indices and the error as illustrated in screenshot still appears.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 11, 2018, 3:21am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/16 "2018-09-11T03:21:35Z")

</div>

Can you create a support ticket with the cluster ID and index name so we can dig into it?

---

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [September 11, 2018, 3:22am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/17 "2018-09-11T03:22:48Z")

</div>

I did and no response from anyone since last week: Case #00257241

---

<div class="post-metadata">

**Author:** ![mikesparr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mikesparr/32/4619_2.png) [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Post date:** [September 11, 2018, 4:07am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/18 "2018-09-11T04:07:43Z")

</div>

Now solved for my instance too. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2018, 4:08am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576/19 "2018-10-09T04:08:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
