# Elasticsearch after taking some logs passes the message "Attempted bulk request to the elasticsearch"

**URL:** <https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280>\
**Category:** Elasticsearch\
**Created:** [January 5, 2018, 11:59am UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280 "2018-01-05T11:59:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 5, 2018, 11:59am UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/1 "2018-01-05T11:59:55Z")

</div>

As after passing certain logs logstash is displaying a message  
[2018-01-05T12:57:50,735][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_message=\>"Elasticsearch Unreachable: [[http://IP:9200/](http://IP:9200/)][Manticore::SocketTimeout] Read timed out", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will\_retry\_in\_seconds=\>64}  
[2018-01-05T12:57:51,823][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://IP:9200/](http://IP:9200/), :path=\>"/"}  
[2018-01-05T12:57:51,826][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>#Java::JavaNet::URI:0x3b4c3c3e}  
[2018-01-05T12:58:08,067][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://IP:9200/](http://IP:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://IP:9200/](http://IP:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://IP:9200/](http://IP:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2018-01-05T12:58:08,067][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_message=\>"Elasticsearch Unreachable: [[http://IP:9200/](http://IP:9200/)][Manticore::SocketTimeout] Read timed out", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will\_retry\_in\_seconds=\>64}  
[2018-01-05T12:58:11,743][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://IP:9200/](http://IP:9200/), :path=\>"/"}  
[2018-01-05T12:58:11,746][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>#Java::JavaNet::URI:0x43fac989}

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [January 5, 2018, 12:09pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/2 "2018-01-05T12:09:10Z")

</div>

This is a sequence of logstash losing connection to the cluster then reconnecting repeatedly. There are a number of things that could cause this.

Can you provide your cluster layout, how many nodes, masters, network speed and other relevant information?

My cluster had this issue at one time. It was overloaded network.

Bryan Vest

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 5, 2018, 12:21pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/3 "2018-01-05T12:21:30Z")

</div>

I am having only one node and one cluster

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [January 5, 2018, 1:02pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/4 "2018-01-05T13:02:36Z")

</div>

If I interpret this correctly you are running Elasticsearch as a master and data node with logstash on a single server.

Is this correct?

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 5, 2018, 1:13pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/5 "2018-01-05T13:13:16Z")

</div>

Yes,  
I am running master and data on a same node

pls help how to improve

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [January 5, 2018, 1:36pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/6 "2018-01-05T13:36:49Z")

</div>

The minimum I would recommend is a 3 node cluster with all three nodes as master and data. In my setup logstash runs on a medium power VM and processes around 100 million log lines per day without issues.

Something similar to the attached image ![MinimumESLogstash](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a66ad3bbf25662305f5977607fbabe505ef868ea.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2018, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-after-taking-some-logs-passes-the-message-attempted-bulk-request-to-the-elasticsearch/114280/7 "2018-02-02T13:37:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
