# Courier fetch: Bad Gateway (6.4.0)

**URL:** <https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068>\
**Category:** Kibana\
**Created:** [August 26, 2018, 2:33pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068 "2018-08-26T14:33:45Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![mimo74](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimo74/32/34818_2.png) [@mimo74](https://discuss.elastic.co/u/mimo74)\
**Post date:** [August 26, 2018, 2:33pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/1 "2018-08-26T14:33:45Z")

</div>

Hi there,

i am fairly new to this... and i am stuck... just installed my ELK stack... filebeat seems to working fine... but i moved on to metricbeat i get this error in Kibana when trying for example to select "metricbeat-\*" under "discover"

Fatal Error:  
Courier fetch: Bad Gateway

Version: 6.4.0  
Build: 17929

when i load the  
[[Metricbeat System] Overview]  
Dashboard it starts to visualise and then switches to the same Fatal Error.

what might be the problem? where can i try to find out more about it?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 27, 2018, 12:29am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/2 "2018-08-27T00:29:56Z")

</div>

Can you check your Kibana and Elasticsearch logs for anything further?

---

<div class="post-metadata">

**Author:** ![mimo74](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimo74/32/34818_2.png) [@mimo74](https://discuss.elastic.co/u/mimo74)\
**Post date:** [August 27, 2018, 5:00am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/3 "2018-08-27T05:00:24Z")

</div>

Elasticsearch isn't logging anything when this happens  
I tink there is no Kibana log ... I'll have to look for that later today...

---

<div class="post-metadata">

**Author:** ![mimo74](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimo74/32/34818_2.png) [@mimo74](https://discuss.elastic.co/u/mimo74)\
**Post date:** [August 27, 2018, 5:09am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/4 "2018-08-27T05:09:59Z")

</div>

I found this in the Nginx error log... may that has something to do with it... (I am sure it has)...

2018/08/27 07:08:36 [error] 27876#0: \*193227 upstream sent too big header while reading response header from upstream, client: xx.xx.xx.xx, server: xxxx.xx, request: "POST /elasticsearch/\_msearch HTTP/1.1", upstream: "[http://127.0.0.1:5601/elasticsearch/\_msearch](http://127.0.0.1:5601/elasticsearch/_msearch)", host: "xxxxx.xx:5601", referrer: "[http://xxxx.xx:5601/app/kibana](http://xxxx.xx:5601/app/kibana)"

---

<div class="post-metadata">

**Author:** ![arlen](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@arlen](https://discuss.elastic.co/u/arlen)\
**Post date:** [August 27, 2018, 3:09pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/5 "2018-08-27T15:09:38Z")

</div>

I'm getting that, too. I just updated metricbeat to 6.4 and I'm only getting this from the metricbeat index. I can view other indexes (audit beat, filebeat, etc.) fine.

This makes the second consecutive metricbeat update that's broken my system...I think I'm going to stop updating for a while until things settle down with it.

---

<div class="post-metadata">

**Author:** ![mimo74](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimo74/32/34818_2.png) [@mimo74](https://discuss.elastic.co/u/mimo74)\
**Post date:** [August 27, 2018, 4:07pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/6 "2018-08-27T16:07:57Z")

</div>

I found something about the "upstream sent too big header"  
i had to add

```
    proxy_buffer_size 128k;
    proxy_buffers 4 256k;
    proxy_busy_buffers_size 256k;

```

to my nginx configuration. that helps.

```
server {
  listen xxx.xxx.xxx.xxx:5601;

  server_name xxx.de;

  auth_basic "Restricted Access";
  auth_basic_user_file /etc/nginx/htpasswd.users;

  location / {
      proxy_pass http://localhost:5601;
      proxy_http_version 1.1;
      proxy_set_header Upgrade $http_upgrade;
      proxy_set_header Connection 'upgrade';
      proxy_set_header Host $host;
      proxy_cache_bypass $http_upgrade;
      proxy_buffer_size 128k;
      proxy_buffers 4 256k;
      proxy_busy_buffers_size 256k;
  }
}
```

---

<div class="post-metadata">

**Author:** ![Faktu4noCaM](https://avatars.discourse-cdn.com/v4/letter/f/71c47a/32.png) [@Faktu4noCaM](https://discuss.elastic.co/u/Faktu4noCaM)\
**Post date:** [August 29, 2018, 6:48am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/7 "2018-08-29T06:48:04Z")

</div>

Its really works! Thanks!

---

<div class="post-metadata">

**Author:** ![sevenfourk](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@sevenfourk](https://discuss.elastic.co/u/sevenfourk)\
**Post date:** [August 30, 2018, 7:13am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/8 "2018-08-30T07:13:42Z")

</div>

Sir, that was it!

---

<div class="post-metadata">

**Author:** ![erickgnavar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erickgnavar/32/35324_2.png) [@erickgnavar](https://discuss.elastic.co/u/erickgnavar)\
**Post date:** [September 8, 2018, 12:36am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/9 "2018-09-08T00:36:58Z")

</div>

That was the problem. Thanks a lot

---

<div class="post-metadata">

**Author:** ![SA010](https://avatars.discourse-cdn.com/v4/letter/s/57b2e6/32.png) [@SA010](https://discuss.elastic.co/u/SA010)\
**Post date:** [September 11, 2018, 8:38am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/10 "2018-09-11T08:38:33Z")

</div>

This works. Than you!

---

<div class="post-metadata">

**Author:** ![Sushimaster](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@Sushimaster](https://discuss.elastic.co/u/Sushimaster)\
**Post date:** [October 1, 2018, 10:12am UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/11 "2018-10-01T10:12:12Z")

</div>

**This should be mentioned in the docs!**

---

<div class="post-metadata">

**Author:** ![inlikefletch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inlikefletch/32/4834_2.png) [@inlikefletch](https://discuss.elastic.co/u/inlikefletch)\
**Post date:** [October 4, 2018, 6:23pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/12 "2018-10-04T18:23:19Z")

</div>

I'm experiencing the same issue 'Courier fetch: Bad Gateway' as well as just with querying my metricbeat index, but I am not using nginx. I am using haproxy. Anyone know how I can set those limits in haproxy?

---

<div class="post-metadata">

**Author:** ![inlikefletch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inlikefletch/32/4834_2.png) [@inlikefletch](https://discuss.elastic.co/u/inlikefletch)\
**Post date:** [October 4, 2018, 7:02pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/13 "2018-10-04T19:02:17Z")

</div>

I found how to resolve for those using haproxy. In the global section of your config, add the following:  
tune.bufsize 128000

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2018, 7:05pm UTC](https://discuss.elastic.co/t/courier-fetch-bad-gateway-6-4-0/146068/14 "2018-11-01T19:05:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
