# Elasticsearch and Kibana not communicating

**URL:** <https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532>\
**Category:** Elasticsearch\
**Created:** [July 14, 2016, 2:40pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532 "2016-07-14T14:40:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![brandonmcgrath1](https://avatars.discourse-cdn.com/v4/letter/b/ebca7d/32.png) [@brandonmcgrath1](https://discuss.elastic.co/u/brandonmcgrath1)\
**Post date:** [July 14, 2016, 2:40pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/1 "2016-07-14T14:40:39Z")

</div>

Our Elastic Searcnd Kibana has suddenly stopped working after two new servers were added to send winlog events. On start up the kibana status is red for a long time saying "Elasticsearch is still initialising the kibana index" and eventually it times out with "request time out after 30000ms".  
After a few minutes it will load but no data will be in there from the servers. CURL XGET displays this:

sudo curl -XGET "[http://192.168.60.90:9200/\_cluster/health?pretty](http://192.168.60.90:9200/_cluster/health?pretty)"{ "cluster\_name" : "elasticsearch", "status" : "red", "timed\_out" : false, "number\_of\_nodes" : 1, "number\_of\_data\_nodes" : 1, "active\_primary\_shards" : 2946, "active\_shards" : 2946, "relocating\_shards" : 0, "initializing\_shards" : 0, "unassigned\_shards" : 3016, "delayed\_unassigned\_shards" : 0, "number\_of\_pending\_tasks" : 0, "number\_of\_in\_flight\_fetch" : 0, "task\_max\_waiting\_in\_queue\_millis" : 0, "active\_shards\_percent\_as\_number" : 49.41294867494129}

Elasticsearch.log displays the following:

> <http://pastebin.com/raw/gUAUfJfQ>

Would it be the amount of information that is being sent from ES to KB?

---

<div class="post-metadata">

**Author:** ![jettro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jettro/32/3418_2.png) [@jettro](https://discuss.elastic.co/u/jettro)\
**Post date:** [July 14, 2016, 3:55pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/2 "2016-07-14T15:55:16Z")

</div>

I would first try to fix your cluster. Your cluster state is red. You have just one node with almost 3000 active shards and even more unassigned shards. How many indexes do you have? Based on the log this is 597. And how are these indexes configured? How many shards, how many replicas? It looks like the default which is 5 shards and 1 replica. Not all primary shards are allocated, it should have 5 times 597 = 2985 active shards. Which means you are missing 39 shards. I also see you have just 1 Gb of memory, also the default I guess. I would start with more memory and see if the cluster can become yellow. And if you have only one node, disable replicas. Also check if you need 5 shards, what is the size of your shards?

A lot of info and questions, but in short, I think your cluster is not stable. First fix you cluster, then start Kibana again.

---

<div class="post-metadata">

**Author:** ![brandonmcgrath1](https://avatars.discourse-cdn.com/v4/letter/b/ebca7d/32.png) [@brandonmcgrath1](https://discuss.elastic.co/u/brandonmcgrath1)\
**Post date:** [July 18, 2016, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/3 "2016-07-18T08:30:02Z")

</div>

To be honest, I'm knew to this and I have left everything to pretty much default. We have roughly 150 servers which needs winlogbeat installed so thats alot of data. In terms of indexes and nodes, I don't know how many. Would the first step be to increase the memory?

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [July 18, 2016, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/4 "2016-07-18T10:59:17Z")

</div>

If you are using RedHat stop your ES node first. After that

> [@jettro](#):
>
> I would start with more memory

` export ES_HEAP_SIZE=4g` It will increase to Elastic search heap to 4Gb. As per this half of the total memory is recommended. [Heap: Sizing and Swapping | Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/heap-sizing.html)

> [@jettro](#):
>
> And if you have only one node, disable replicas.

`curl -XPUT 'localhost:9200/<your_index_name>/_settings' -d ' { "index" : { "number_of_replicas" : 0 } }'`

It will disable the replicas

Then start your node.

**Note:** This heap setting works only for current terminal. Hope this will fix your cluster

---

<div class="post-metadata">

**Author:** ![Ravi\_Shanker\_Reddy](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Post date:** [July 19, 2016, 4:43am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/6 "2016-07-19T04:43:11Z")

</div>

I assumed you are using your winlog beat template. Replace this with your template and try.

**Note:** Works only for new indeces  
`{ "mappings": { "_default_": { "_all": { "enabled": true, "norms": { "enabled": false } }, "dynamic_templates": [{ "template1": { "mapping": { "doc_values": true, "ignore_above": 1024, "index": "not_analyzed", "type": "{dynamic_type}" }, "match": "*" } }], "properties": { "@timestamp": { "type": "date" }, "message": { "index": "analyzed", "type": "string" } } } }, "settings": { "index.refresh_interval": "5s", "number_of_replicas": 0 }, "template": "winlogbeat-*" }`

To modify the replicas for old one use

`curl -XPUT 'localhost:9200/winlogbeat_*/_settings' -d '{"index" : {"number_of_replicas" : 0}}'`

If you dont have curl available in windows please install and try.

---

<div class="post-metadata">

**Author:** ![brandonmcgrath1](https://avatars.discourse-cdn.com/v4/letter/b/ebca7d/32.png) [@brandonmcgrath1](https://discuss.elastic.co/u/brandonmcgrath1)\
**Post date:** [July 20, 2016, 9:09am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/7 "2016-07-20T09:09:22Z")

</div>

I did that but i get the following: [http://www.pastebin.com/EHDYprQv](http://www.pastebin.com/EHDYprQv)  
I replaced the template like you suggested but when I go to [http://192.168.60.90:9200/winlogbeat?pretty](http://192.168.60.90:9200/winlogbeat?pretty) I just get:  
{  
"winlogbeat" : {  
"aliases" : { },  
"mappings" : { },  
"settings" : {  
"index" : {  
"creation\_date" : "1468851642631",  
"number\_of\_shards" : "5",  
"number\_of\_replicas" : "1",  
"uuid" : "2Eb-f\_L8RGS0tUSuv1NrMA",  
"version" : {  
"created" : "2030199"  
}  
}  
},  
"warmers" : { }  
}

so the replica hasn't changed.

---

<div class="post-metadata">

**Author:** ![jettro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jettro/32/3418_2.png) [@jettro](https://discuss.elastic.co/u/jettro)\
**Post date:** [July 22, 2016, 7:27am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/8 "2016-07-22T07:27:31Z")

</div>

please edit the link pastbin should be pastebin

---

<div class="post-metadata">

**Author:** ![jettro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jettro/32/3418_2.png) [@jettro](https://discuss.elastic.co/u/jettro)\
**Post date:** [July 22, 2016, 7:29am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/9 "2016-07-22T07:29:18Z")

</div>

> [@Ravi\_Shanker\_Reddy](#):
>
> winlogbeat\_

Replace the "\_" with a "-", the error mentions an unknown index, if you look closely you can see the names of the indexes are slightly different.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:33pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-not-communicating/55532/10 "2017-07-05T22:33:31Z")

</div>


