# Couldn't refresh index and now times out with "Bad Request"

**URL:** <https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220>\
**Category:** Kibana\
**Created:** [July 14, 2017, 4:40pm UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220 "2017-07-14T16:40:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gungazoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gungazoo/32/19972_2.png) [@gungazoo](https://discuss.elastic.co/u/gungazoo)\
**Post date:** [July 14, 2017, 4:40pm UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/1 "2017-07-14T16:40:19Z")

</div>

I believe this is an Elasticsearch problem although it manifests itself in Kibana.

I'll apologize upfront -- this is my first post. I'll try and provide what is needed.

We're using ELK to gather the logs of about 1,500 machines including F5s and ESXi. They are sorted into 8 different daily indexes totaling 6.6B documents over the 30 day retention. In monitoring everything is green. The indexes, nodes, and Kibana. I've been unable to refresh the index for our default index which is logstash. It is by far our largest index as well. At about 100m documents daily and a data size of around 220GB. There are 5 shards and one replica. We have 10 data nodes with 5 at each site and a fast pipe between them. When I would try to refresh it within Kibana it would timeout.

Yesterday I upgraded it via Puppet from version 5.4.1 to 5.5.0. Now I can't access the data in the logstash indexes either. When I hit Kibana it just spins and then errors. I can see the data in other indexes. The error looks like this:

Error: Request to Elasticsearch failed: "Bad Request"  
at [http://kibana.example.com/bundles/kibana.bundle.js?v=15382:229:4009](http://kibana.example.com/bundles/kibana.bundle.js?v=15382:229:4009)  
at processQueue ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:38:23621](http://kibana.example.com/bundles/commons.bundle.js?v=15382:38:23621))  
at [http://kibana.example.com/bundles/commons.bundle.js?v=15382:38:23888](http://kibana.example.com/bundles/commons.bundle.js?v=15382:38:23888)  
at Scope.$eval ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:4619](http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:4619))  
at Scope.$digest ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:2359](http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:2359))  
at Scope.$apply ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:5037](http://kibana.example.com/bundles/commons.bundle.js?v=15382:39:5037))  
at done ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:25027](http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:25027))  
at completeRequest ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:28702](http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:28702))  
at XMLHttpRequest.xhr.onload ([http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:29634](http://kibana.example.com/bundles/commons.bundle.js?v=15382:37:29634))

The Kibana node is also an Elasticsearch node but doesn't hold data. I don't see anything of significance in either the Kibana log or the ES log with log level set to info. Here is a Kibana timeout log message:

```
{
    "type":"response",
    "@timestamp":"2017-07-14T15:35:07Z",
    "tags":[],
    "pid":22484,
    "method":"post",
    "statusCode":400,
    "req":{
        "url":"/api/console/proxy?path=_mapping&method=GET",
        "method":"post",
        "headers":{
            "host":"kibana.example.com",
            "connection":"keep-alive",
            "content-length":"0",
            "accept":"text/plain, */*; q=0.01",
            "origin":"http://kibana.example.com",
            "kbn-version":"5.4.1",
            "user-agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) AppleWebKit /537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36",
            "referer":"http://kibana.example.com/app/kibana",
            "accept-encoding":"gzip, deflate",
            "accept-language":"en-US,en;q=0.8"
        },
        "remoteAddress":"192.168.59.3",
        "userA gent":"192.168.59.3",
        "referer":"http://kibana.example.com/app/kibana"
    },
    "res":{
        "statusCode":400,
        "responseTime":39,
        "contentLength":9
    },
    "message":"POST /api/console/proxy?path=_mapping&method=GET 400 39ms - 9.0B"
}

```

The entire ELK stack is at 5.5.0.

Thanks,

Peter

---

<div class="post-metadata">

**Author:** ![Chen\_Jian](https://avatars.discourse-cdn.com/v4/letter/c/c89c15/32.png) [@Chen\_Jian](https://discuss.elastic.co/u/Chen_Jian)\
**Post date:** [July 20, 2017, 2:54am UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/2 "2017-07-20T02:54:25Z")

</div>

I have encounter the same issue after upgrading to ES 5.5 ☹.

---

<div class="post-metadata">

**Author:** ![0utlaw](https://avatars.discourse-cdn.com/v4/letter/0/b782af/32.png) [@0utlaw](https://discuss.elastic.co/u/0utlaw)\
**Post date:** [August 3, 2017, 9:00am UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/3 "2017-08-03T09:00:14Z")

</div>

HI

Was there a fix for this? It seems to have happened with our upgrade from 5.2.1 to 5.5.1.

Terry

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 3, 2017, 9:16am UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/4 "2017-08-03T09:16:22Z")

</div>

I moved it to #kibana in case anyone there has an idea.

---

<div class="post-metadata">

**Author:** ![blsonne](https://avatars.discourse-cdn.com/v4/letter/b/ccd318/32.png) [@blsonne](https://discuss.elastic.co/u/blsonne)\
**Post date:** [August 11, 2017, 5:11pm UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/5 "2017-08-11T17:11:37Z")

</div>

Happening to me as well... upgraded from 5.3.1 to 5.5.1 and now nothing I do allows me to configure a default index pattern without getting the following error:

Error: Request to Elasticsearch failed: "Bad Request"  
at [http://elasticsearch-05:5601/bundles/kibana.bundle.js?v=15405:229:4009](http://elasticsearch-05:5601/bundles/kibana.bundle.js?v=15405:229:4009)  
at processQueue ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:38:23621](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:38:23621))  
at [http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:38:23888](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:38:23888)  
at Scope.$eval ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:4619](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:4619))  
at Scope.$digest ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:2359](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:2359))  
at Scope.$apply ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:5037](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:39:5037))  
at done ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:25027](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:25027))  
at completeRequest ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:28702](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:28702))  
at XMLHttpRequest.xhr.onload ([http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:29634](http://elasticsearch-05:5601/bundles/commons.bundle.js?v=15405:37:29634))

Elasticsearch has been nothing but a fight over the last couple years, and I'm ready to give up on this nonsense.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 5:11pm UTC](https://discuss.elastic.co/t/couldnt-refresh-index-and-now-times-out-with-bad-request/93220/6 "2017-09-08T17:11:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
