# Elasticsearch + logstash : Message not fully read (request)

**URL:** <https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210>\
**Category:** Elasticsearch\
**Created:** [March 6, 2014, 9:48pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210 "2014-03-06T21:48:50Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [March 6, 2014, 9:48pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/1 "2014-03-06T21:48:50Z")

</div>

Hi

Im trying to run a server with elasticsearch and logstash,  
I did configure minimalistic settings, and still I can not get it running:

In ES log i see:  
[transport.netty] [lekNo1] Message not fully read (request) for  
[30] and action [], resetting

The elasticsearch.yml contains:

cluster.name: "elasticqa"  
network.host: 0.0.0.0  
node.data: true  
node.master: true  
node.name: "lekNo1"  
path.data: /home/elasticsearch/data  
path.logs: /home/elasticsearch/logs  
path.work: /home/elasticsearch/data/temp

root@szl:~# curl -s [http://10.13.201.103:9200/\_status?pretty=true](http://10.13.201.103:9200/_status?pretty=true)  
{  
"\_shards" : {  
"total" : 0,  
"successful" : 0,  
"failed" : 0  
},  
"indices" : { }  
}  
(reverse-i-search)`cu': apt-get install ^Crl  
root@szl:~# curl 'localhost:9200/\_nodes/jvm?pretty'  
{  
"cluster\_name" : "elasticqa",  
"nodes" : {  
"6yPHl-6ETL-XI0ht9ieFFA" : {  
"name" : "lekNo1",  
"transport\_address" : "inet[/10.13.201.103:9300]",  
"host" : "szl",  
"ip" : "10.13.201.103",  
"version" : "1.0.1",  
"build" : "5c03844",  
"http\_address" : "inet[/10.13.201.103:9200]",  
"attributes" : {  
"master" : "true"  
},  
"jvm" : {  
"pid" : 2636,  
"version" : "1.6.0\_27",  
"vm\_name" : "OpenJDK 64-Bit Server VM",  
"vm\_version" : "20.0-b12",  
"vm\_vendor" : "Sun Microsystems Inc.",  
"start\_time" : 1394139699953,  
"mem" : {  
"heap\_init\_in\_bytes" : 268435456,  
"heap\_max\_in\_bytes" : 1071579136,  
"non\_heap\_init\_in\_bytes" : 24313856,  
"non\_heap\_max\_in\_bytes" : 224395264,  
"direct\_max\_in\_bytes" : 1071579136  
},  
"gc\_collectors" : ["Copy", "ConcurrentMarkSweep"],  
"memory\_pools" : [ "Code Cache", "Eden Space", "Survivor Space",  
"CMS Old Gen", "CMS Perm Gen" ]  
}  
}  
}  
}

The logstash config file contains:

output {  
elasticsearch {  
host =\> "localhost"

# cluster =\> "elasticqa"

# port =\> 9300

# node\_name =\> "lekNo1"

```
            protocol => "transport"
    }

    #debuging
    file {
           path => "/root/test.log"
    }

```

I do start logstash as follows:  
/usr/bin/java -jar /usr/share/logstash/bin/logstash-1.3.3-flatjar.jar agent  
-f /etc/logstash.d/elasticsearch/

* * *

When I did switch protocol from transport to node

output {  
elasticsearch {

```
    }

```

}

It looks like discovery is failing:

ES  
java.io.IOException: No transport address mapped to [22369]  
at  
org.elasticsearch.common.transport.TransportAddressSerializers.addressFromStream(TransportAddressSerializers.java:71)  
at  
org.elasticsearch.cluster.node.DiscoveryNode.readFrom(DiscoveryNode.java:267)  
at  
org.elasticsearch.cluster.node.DiscoveryNode.readNode(DiscoveryNode.java:257)  
at  
org.elasticsearch.discovery.zen.ping.multicast.MulticastZenPing$Receiver.run(MulticastZenPing.java:410)  
at java.lang.Thread.run(Thread.java:679)

LS  
{:timestamp=\>"2014-03-06T22:22:58.537000+0100", :message=\>"Failed to flush  
outgoing items", :outgoing\_count=\>4,  
:exception=\>org.elasticsearch.discovery.MasterNotDiscoveredException:  
waited for [30s],  
:backtrace=\>["org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(TransportMasterNodeOperationAction.java:180)",  
"org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:483)",  
"java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)",  
"java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)",  
"java.lang.Thread.run(Thread.java:679)"], :level=\>:warn}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 6, 2014, 9:51pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/2 "2014-03-06T21:51:28Z")

</div>

I think this logstash version is not compatible with elasticsearch 1.0.1.  
You should try with another elasticsearch version I think.

My 2 cents

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 6 mars 2014 à 22:48, sirkubax [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com) a écrit :

Hi

Im trying to run a server with elasticsearch and logstash,  
I did configure minimalistic settings, and still I can not get it running:

In ES log i see:  
[transport.netty] [lekNo1] Message not fully read (request) for [30] and action [], resetting

The elasticsearch.yml contains:

cluster.name: "elasticqa"  
network.host: 0.0.0.0  
node.data: true  
node.master: true  
node.name: "lekNo1"  
path.data: /home/elasticsearch/data  
path.logs: /home/elasticsearch/logs  
path.work: /home/elasticsearch/data/temp

root@szl:~# curl -s [http://10.13.201.103:9200/\_status?pretty=true](http://10.13.201.103:9200/_status?pretty=true)  
{  
"\_shards" : {  
"total" : 0,  
"successful" : 0,  
"failed" : 0  
},  
"indices" : { }  
}  
(reverse-i-search)`cu': apt-get install ^Crl  
root@szl:~# curl 'localhost:9200/\_nodes/jvm?pretty'  
{  
"cluster\_name" : "elasticqa",  
"nodes" : {  
"6yPHl-6ETL-XI0ht9ieFFA" : {  
"name" : "lekNo1",  
"transport\_address" : "inet[/10.13.201.103:9300]",  
"host" : "szl",  
"ip" : "10.13.201.103",  
"version" : "1.0.1",  
"build" : "5c03844",  
"http\_address" : "inet[/10.13.201.103:9200]",  
"attributes" : {  
"master" : "true"  
},  
"jvm" : {  
"pid" : 2636,  
"version" : "1.6.0\_27",  
"vm\_name" : "OpenJDK 64-Bit Server VM",  
"vm\_version" : "20.0-b12",  
"vm\_vendor" : "Sun Microsystems Inc.",  
"start\_time" : 1394139699953,  
"mem" : {  
"heap\_init\_in\_bytes" : 268435456,  
"heap\_max\_in\_bytes" : 1071579136,  
"non\_heap\_init\_in\_bytes" : 24313856,  
"non\_heap\_max\_in\_bytes" : 224395264,  
"direct\_max\_in\_bytes" : 1071579136  
},  
"gc\_collectors" : ["Copy", "ConcurrentMarkSweep"],  
"memory\_pools" : ["Code Cache", "Eden Space", "Survivor Space", "CMS Old Gen", "CMS Perm Gen"]  
}  
}  
}  
}

The logstash config file contains:

output {  
elasticsearch {  
host =\> "localhost"

# cluster =\> "elasticqa"

# port =\> 9300

# node\_name =\> "lekNo1"

```
            protocol => "transport"
    }

    #debuging
    file {
           path => "/root/test.log"
    }

```

I do start logstash as follows:  
/usr/bin/java -jar /usr/share/logstash/bin/logstash-1.3.3-flatjar.jar agent -f /etc/logstash.d/elasticsearch/

* * *

When I did switch protocol from transport to node

output {  
elasticsearch {

```
    }

```

}

It looks like discovery is failing:

ES  
java.io.IOException: No transport address mapped to [22369]  
at org.elasticsearch.common.transport.TransportAddressSerializers.addressFromStream(TransportAddressSerializers.java:71)  
at org.elasticsearch.cluster.node.DiscoveryNode.readFrom(DiscoveryNode.java:267)  
at org.elasticsearch.cluster.node.DiscoveryNode.readNode(DiscoveryNode.java:257)  
at org.elasticsearch.discovery.zen.ping.multicast.MulticastZenPing$Receiver.run(MulticastZenPing.java:410)  
at java.lang.Thread.run(Thread.java:679)

## LS {:timestamp=\>"2014-03-06T22:22:58.537000+0100", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>4, :exception=\>org.elasticsearch.discovery.MasterNotDiscoveredException: waited for [30s], :backtrace=\>["org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(TransportMasterNodeOperationAction.java:180)", "org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:483)", "java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)", "java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)", "java.lang.Thread.run(Thread.java:679)"], :level=\>:warn}

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 6, 2014, 10:17pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/3 "2014-03-06T22:17:13Z")

</div>

Or use the elasticsearch\_http output and not worry about version  
compatibility 🙂

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 7 March 2014 08:51, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> I think this logstash version is not compatible with elasticsearch 1.0.1.  
> You should try with another elasticsearch version I think.
> 
> My 2 cents
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 6 mars 2014 à 22:48, sirkubax [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com) a  
> écrit :
> 
> Hi
> 
> Im trying to run a server with elasticsearch and logstash,  
> I did configure minimalistic settings, and still I can not get it running:
> 
> In ES log i see:  
> [transport.netty] [lekNo1] Message not fully read (request) for  
> [30] and action , resetting
> 
> The elasticsearch.yml contains:
> 
> cluster.name: "elasticqa"  
> network.host: 0.0.0.0  
> node.data: true  
> node.master: true  
> node.name: "lekNo1"  
> path.data: /home/elasticsearch/data  
> path.logs: /home/elasticsearch/logs  
> path.work: /home/elasticsearch/data/temp
> 
> root@szl:~# curl -s [http://10.13.201.103:9200/\_status?pretty=true](http://10.13.201.103:9200/_status?pretty=true)  
> {  
> "\_shards" : {  
> "total" : 0,  
> "successful" : 0,  
> "failed" : 0  
> },  
> "indices" : { }  
> }  
> (reverse-i-search)`cu': apt-get install ^Crl  
> root@szl:~# curl 'localhost:9200/\_nodes/jvm?pretty'  
> {  
> "cluster\_name" : "elasticqa",  
> "nodes" : {  
> "6yPHl-6ETL-XI0ht9ieFFA" : {  
> "name" : "lekNo1",  
> "transport\_address" : "inet[/10.13.201.103:9300]",  
> "host" : "szl",  
> "ip" : "10.13.201.103",  
> "version" : "1.0.1",  
> "build" : "5c03844",  
> "http\_address" : "inet[/10.13.201.103:9200]",  
> "attributes" : {  
> "master" : "true"  
> },  
> "jvm" : {  
> "pid" : 2636,  
> "version" : "1.6.0\_27",  
> "vm\_name" : "OpenJDK 64-Bit Server VM",  
> "vm\_version" : "20.0-b12",  
> "vm\_vendor" : "Sun Microsystems Inc.",  
> "start\_time" : 1394139699953,  
> "mem" : {  
> "heap\_init\_in\_bytes" : 268435456,  
> "heap\_max\_in\_bytes" : 1071579136,  
> "non\_heap\_init\_in\_bytes" : 24313856,  
> "non\_heap\_max\_in\_bytes" : 224395264,  
> "direct\_max\_in\_bytes" : 1071579136  
> },  
> "gc\_collectors" : ["Copy", "ConcurrentMarkSweep"],  
> "memory\_pools" : [ "Code Cache", "Eden Space", "Survivor Space",  
> "CMS Old Gen", "CMS Perm Gen" ]  
> }  
> }  
> }  
> }
> 
> The logstash config file contains:
> 
> output {  
> elasticsearch {  
> host =\> "localhost"
> 
> # cluster =\> "elasticqa"
> 
> # port =\> 9300
> 
> # node\_name =\> "lekNo1"
> 
> ```
> protocol => "transport"
> }
> 
> #debuging
> file {
> path => "/root/test.log"
> }
> 
> ```
> 
> I do start logstash as follows:  
> /usr/bin/java -jar /usr/share/logstash/bin/logstash-1.3.3-flatjar.jar  
> agent -f /etc/logstash.d/elasticsearch/
> 
> * * *
> 
> When I did switch protocol from transport to node
> 
> output {  
> elasticsearch {
> 
> ```
> }
> 
> ```
> 
> }
> 
> It looks like discovery is failing:
> 
> ES  
> java.io.IOException: No transport address mapped to [22369]  
> at  
> org.elasticsearch.common.transport.TransportAddressSerializers.addressFromStream(TransportAddressSerializers.java:71)  
> at  
> org.elasticsearch.cluster.node.DiscoveryNode.readFrom(DiscoveryNode.java:267)  
> at  
> org.elasticsearch.cluster.node.DiscoveryNode.readNode(DiscoveryNode.java:257)  
> at  
> org.elasticsearch.discovery.zen.ping.multicast.MulticastZenPing$Receiver.run(MulticastZenPing.java:410)  
> at java.lang.Thread.run(Thread.java:679)
> 
> LS  
> {:timestamp=\>"2014-03-06T22:22:58.537000+0100", :message=\>"Failed to flush  
> outgoing items", :outgoing\_count=\>4,  
> :exception=\>org.elasticsearch.discovery.MasterNotDiscoveredException:  
> waited for [30s],  
> :backtrace=\>["org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(TransportMasterNodeOperationAction.java:180)",  
> "org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:483)",  
> "java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)",  
> "java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)",  
> "java.lang.Thread.run(Thread.java:679)"], :level=\>:warn}
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr)[https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CE1F3F62-2F6A-4911-B6EE-FDB72B6BE7A6%40pilato.fr?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624aTkkv-TTLC7aApEi8QWj9Qa-Zjg3vCL6dzTB7yX%2Bb%3D%3Dw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624aTkkv-TTLC7aApEi8QWj9Qa-Zjg3vCL6dzTB7yX%2Bb%3D%3Dw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [March 6, 2014, 10:54pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/4 "2014-03-06T22:54:26Z")

</div>

Hi David,

This is what I've been wondering about  
I have copierd elasticsearch 0.90.9 from my virtual machine I've been  
testing with a month ago, but no luck (it was installed  
with [https://github.com/valentinogagliardi/ansible-logstash](https://github.com/valentinogagliardi/ansible-logstash) ansible play)  
There is logstash 1.3.2, I will copy it too, and check again.

Current config is now:

cluster.name: "elasticqa"  
node.master: true  
node.name: "lekNo1"  
path.data: /home/elasticsearch/data  
path.logs: /home/elasticsearch/logs  
path.work: /home/elasticsearch/data/temp

output {  
elasticsearch {}  
}

ES LOG

[2014-03-06 23:35:21,215][INFO][node] [lekNo1]  
stopping ...  
[2014-03-06 23:35:21,234][INFO][node] [lekNo1] stopped  
[2014-03-06 23:35:21,234][INFO][node] [lekNo1]  
closing ...  
[2014-03-06 23:35:21,239][INFO][node] [lekNo1] closed  
[2014-03-06 23:36:31,040][INFO][node] [lekNo1]  
version[0.90.9], pid[4186], build[a968646/2013-12-23T10:35:28Z]  
[2014-03-06 23:36:31,040][INFO][node] [lekNo1]  
initializing ...  
[2014-03-06 23:36:31,048][INFO][plugins] [lekNo1] loaded  
, sites   
[2014-03-06 23:36:33,600][INFO][node] [lekNo1]  
initialized  
[2014-03-06 23:36:33,600][INFO][node] [lekNo1]  
starting ...  
[2014-03-06 23:36:33,730][INFO][transport] [lekNo1]  
bound\_address {inet[/0:0:0:0:0:0:0:0:9300]}, publish\_address  
{inet[/10.13.201.103:9300]}  
[2014-03-06 23:36:36,768][INFO][cluster.service] [lekNo1]  
new\_master  
[lekNo1][SgnO9OG-RP23lftg5h5E4w][inet[/10.13.201.103:9300]]{master=true},  
reason: zen-disco-join (elected\_as\_master)  
[2014-03-06 23:36:36,799][INFO][discovery] [lekNo1]  
elasticqa/SgnO9OG-RP23lftg5h5E4w  
[2014-03-06 23:36:36,836][INFO][http] [lekNo1]  
bound\_address {inet[/0:0:0:0:0:0:0:0:9200]}, publish\_address  
{inet[/10.13.201.103:9200]}  
[2014-03-06 23:36:36,837][INFO][node] [lekNo1] started  
[2014-03-06 23:36:36,857][INFO][gateway] [lekNo1]  
recovered [0] indices into cluster\_state

LS

un(ThreadPoolExecutor.java:615)", "java.lang.Thread.run(Thread.java:679)"],  
:level=\>:warn}  
{:timestamp=\>"2014-03-06T23:53:36.961000+0100", :message=\>"Failed to flush  
outgoing items", :outgoing\_count=\>1,  
:exception=\>org.elasticsearch.discovery.MasterNotDiscoveredException:  
waited for [30s],  
:backtrace=\>["org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(TransportMasterNodeOperationAction.java:180)",  
"org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:483)",  
"java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)",  
"java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)",  
"java.lang.Thread.run(Thread.java:679)"], :level=\>:warn}

W dniu czwartek, 6 marca 2014 22:51:28 UTC+1 użytkownik David Pilato  
napisał:

> I think this logstash version is not compatible with elasticsearch 1.0.1.  
> You should try with another elasticsearch version I think.
> 
> My 2 cents
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 6 mars 2014 à 22:48, sirkubax \<[jakubxm...@googlemail.com](mailto:jakubxm...@googlemail.com) \<javascript:\>\>  
> a écrit :
> 
> Hi
> 
> Im trying to run a server with elasticsearch and logstash,  
> I did configure minimalistic settings, and still I can not get it running:
> 
> In ES log i see:  
> [transport.netty] [lekNo1] Message not fully read (request) for  
> [30] and action , resetting
> 
> The elasticsearch.yml contains:
> 
> cluster.name: "elasticqa"  
> network.host: 0.0.0.0  
> node.data: true  
> node.master: true  
> node.name: "lekNo1"  
> path.data: /home/elasticsearch/data  
> path.logs: /home/elasticsearch/logs  
> path.work: /home/elasticsearch/data/temp
> 
> root@szl:~# curl -s [http://10.13.201.103:9200/\_status?pretty=true](http://10.13.201.103:9200/_status?pretty=true)  
> {  
> "\_shards" : {  
> "total" : 0,  
> "successful" : 0,  
> "failed" : 0  
> },  
> "indices" : { }  
> }  
> (reverse-i-search)`cu': apt-get install ^Crl  
> root@szl:~# curl 'localhost:9200/\_nodes/jvm?pretty'  
> {  
> "cluster\_name" : "elasticqa",  
> "nodes" : {  
> "6yPHl-6ETL-XI0ht9ieFFA" : {  
> "name" : "lekNo1",  
> "transport\_address" : "inet[/10.13.201.103:9300]",  
> "host" : "szl",  
> "ip" : "10.13.201.103",  
> "version" : "1.0.1",  
> "build" : "5c03844",  
> "http\_address" : "inet[/10.13.201.103:9200]",  
> "attributes" : {  
> "master" : "true"  
> },  
> "jvm" : {  
> "pid" : 2636,  
> "version" : "1.6.0\_27",  
> "vm\_name" : "OpenJDK 64-Bit Server VM",  
> "vm\_version" : "20.0-b12",  
> "vm\_vendor" : "Sun Microsystems Inc.",  
> "start\_time" : 1394139699953,  
> "mem" : {  
> "heap\_init\_in\_bytes" : 268435456,  
> "heap\_max\_in\_bytes" : 1071579136,  
> "non\_heap\_init\_in\_bytes" : 24313856,  
> "non\_heap\_max\_in\_bytes" : 224395264,  
> "direct\_max\_in\_bytes" : 1071579136  
> },  
> "gc\_collectors" : ["Copy", "ConcurrentMarkSweep"],  
> "memory\_pools" : [ "Code Cache", "Eden Space", "Survivor Space",  
> "CMS Old Gen", "CMS Perm Gen" ]  
> }  
> }  
> }  
> }
> 
> The logstash config file contains:
> 
> output {  
> elasticsearch {  
> host =\> "localhost"
> 
> # cluster =\> "elasticqa"
> 
> # port =\> 9300
> 
> # node\_name =\> "lekNo1"
> 
> ```
> protocol => "transport"
> }
> 
> #debuging
> file {
> path => "/root/test.log"
> }
> 
> ```
> 
> I do start logstash as follows:  
> /usr/bin/java -jar /usr/share/logstash/bin/logstash-1.3.3-flatjar.jar  
> agent -f /etc/logstash.d/elasticsearch/
> 
> * * *
> 
> When I did switch protocol from transport to node
> 
> output {  
> elasticsearch {
> 
> ```
> }
> 
> ```
> 
> }
> 
> It looks like discovery is failing:
> 
> ES  
> java.io.IOException: No transport address mapped to [22369]  
> at  
> org.elasticsearch.common.transport.TransportAddressSerializers.addressFromStream(TransportAddressSerializers.java:71)  
> at  
> org.elasticsearch.cluster.node.DiscoveryNode.readFrom(DiscoveryNode.java:267)  
> at  
> org.elasticsearch.cluster.node.DiscoveryNode.readNode(DiscoveryNode.java:257)  
> at  
> org.elasticsearch.discovery.zen.ping.multicast.MulticastZenPing$Receiver.run(MulticastZenPing.java:410)  
> at java.lang.Thread.run(Thread.java:679)
> 
> LS  
> {:timestamp=\>"2014-03-06T22:22:58.537000+0100", :message=\>"Failed to flush  
> outgoing items", :outgoing\_count=\>4,  
> :exception=\>org.elasticsearch.discovery.MasterNotDiscoveredException:  
> waited for [30s],  
> :backtrace=\>["org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(TransportMasterNodeOperationAction.java:180)",  
> "org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(InternalClusterService.java:483)",  
> "java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)",  
> "java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)",  
> "java.lang.Thread.run(Thread.java:679)"], :level=\>:warn}
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b0a4d2de-fe0a-42f8-98c8-9e3ea4ea1b26%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/67747cab-32cf-439a-af44-e8a351a9bd51%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/67747cab-32cf-439a-af44-e8a351a9bd51%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [March 6, 2014, 11:22pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/5 "2014-03-06T23:22:51Z")

</div>

W dniu czwartek, 6 marca 2014 23:54:26 UTC+1 użytkownik sirkubax napisał:

> Hi David,
> 
> This is what I've been wondering about  
> I have copierd elasticsearch 0.90.9 from my virtual machine I've been  
> testing with a month ago, but no luck (it was installed with  
> [https://github.com/valentinogagliardi/ansible-logstash](https://github.com/valentinogagliardi/ansible-logstash) ansible play)  
> There is logstash 1.3.2, I will copy it too, and check again.
> 
> >

Nothing, no luck with 1.3.2

Some differences between my test virtual machine "A", and current machine B  
are:  
A debian 7 vs B debian6  
A java 7 vs B java 6

different network settings (firewals, dns, hosts)

any ideas?

@MARK

I think I made it work with :

output {  
elasticsearch\_http {  
host =\> "localhost"  
}

Is there any drawback using elasticsearch\_http vs elasticsearch?

I'm not happy with current state "working on test, failing to work on  
"production" environment", Since it worked on test, it should to work on  
new env too...

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2014, 3:08am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/6 "2014-03-07T03:08:47Z")

</div>

Mixing JVM versions won't work for sure.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 7 mars 2014 à 00:22, sirkubax [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com) a écrit :

W dniu czwartek, 6 marca 2014 23:54:26 UTC+1 użytkownik sirkubax napisał:

> Hi David,
> 
> This is what I've been wondering about  
> I have copierd elasticsearch 0.90.9 from my virtual machine I've been testing with a month ago, but no luck (it was installed with [https://github.com/valentinogagliardi/ansible-logstash](https://github.com/valentinogagliardi/ansible-logstash) ansible play)  
> There is logstash 1.3.2, I will copy it too, and check again.
> 
> >

Nothing, no luck with 1.3.2

Some differences between my test virtual machine "A", and current machine B are:  
A debian 7 vs B debian6  
A java 7 vs B java 6

different network settings (firewals, dns, hosts)

any ideas?

@MARK

I think I made it work with :

output {  
elasticsearch\_http {  
host =\> "localhost"  
}

Is there any drawback using elasticsearch\_http vs elasticsearch?

## I'm not happy with current state "working on test, failing to work on "production" environment", Since it worked on test, it should to work on new env too...

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 7, 2014, 3:13am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/7 "2014-03-07T03:13:00Z")

</div>

I think there is a small performance hit with using the http output, but I  
haven't tested that so don't take it as definitive.  
And the removal of dependencies between ES and LS is worth it to me anyway.

Java 6 isn't recommended, and if I recall correctly isn't supported with  
LS, you want 7.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 7 March 2014 14:08, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Mixing JVM versions won't work for sure.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 7 mars 2014 à 00:22, sirkubax [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com) a  
> écrit :
> 
> W dniu czwartek, 6 marca 2014 23:54:26 UTC+1 użytkownik sirkubax napisał:
> 
> > Hi David,
> > 
> > This is what I've been wondering about  
> > I have copierd elasticsearch 0.90.9 from my virtual machine I've been  
> > testing with a month ago, but no luck (it was installed with  
> > [https://github.com/valentinogagliardi/ansible-logstash](https://github.com/valentinogagliardi/ansible-logstash) ansible play)  
> > There is logstash 1.3.2, I will copy it too, and check again.
> > 
> > >
> 
> Nothing, no luck with 1.3.2
> 
> Some differences between my test virtual machine "A", and current machine  
> B are:  
> A debian 7 vs B debian6  
> A java 7 vs B java 6
> 
> different network settings (firewals, dns, hosts)
> 
> any ideas?
> 
> @MARK
> 
> I think I made it work with :
> 
> output {  
> elasticsearch\_http {  
> host =\> "localhost"  
> }
> 
> Is there any drawback using elasticsearch\_http vs elasticsearch?
> 
> I'm not happy with current state "working on test, failing to work on  
> "production" environment", Since it worked on test, it should to work on  
> new env too...
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/abb86a4b-d288-485b-83cd-4b377dd76783%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr](https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr)[https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/59D71AFE-B1DA-49C7-8F6E-0DE82C21A873%40pilato.fr?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624abU2caAGbXC79DF\_NM3Sm6q%3DuzoJdSBHYgX8-NRpnsGA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624abU2caAGbXC79DF_NM3Sm6q%3DuzoJdSBHYgX8-NRpnsGA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [March 7, 2014, 7:35am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/8 "2014-03-07T07:35:57Z")

</div>

On Fri, Mar 7, 2014 at 4:08 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Mixing JVM versions won't work for sure.

Just to clarify for future debuging:

- Some differences between my test virtual machine "A", and current machine  
B are:\*
- A debian 7 vs B debian6\*
- A java 7 vs B java 6\*

I have java 7, amd debian 7 on machine "A", where elasticsearch  
0.90.9 + logstash 1.3.2 were _working_ without any problem.

Now I have installed new machine "B", as a new environment (not related or  
connected with machine "A"), where is debian 6 and java 6.

Configurations and versions of ES and LS are the same  
(with one not related difference

- on machine A I was capturing events from file localy, LS+redis -\> LS+ES
- on machine "B" I will use logstash-forwarder for logs from remote hosts  
-\> LS+ES)

I am going to install 3 new machines, to make ES cluster, so I will make  
sure they are debian7

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 7, 2014, 7:38am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/9 "2014-03-07T07:38:27Z")

</div>

And Java 7 as well!

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 7 March 2014 18:35, Jakub Muszynski [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com)wrote:

> On Fri, Mar 7, 2014 at 4:08 AM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > Mixing JVM versions won't work for sure.
> 
> Just to clarify for future debuging:
> 
> - Some differences between my test virtual machine "A", and current  
> machine B are:\*
> - A debian 7 vs B debian6\*
> - A java 7 vs B java 6\*
> 
> I have java 7, amd debian 7 on machine "A", where elasticsearch  
> 0.90.9 + logstash 1.3.2 were _working_ without any problem.
> 
> Now I have installed new machine "B", as a new environment (not related or  
> connected with machine "A"), where is debian 6 and java 6.
> 
> Configurations and versions of ES and LS are the same  
> (with one not related difference
> 
> - on machine A I was capturing events from file localy, LS+redis -\> LS+ES
> - on machine "B" I will use logstash-forwarder for logs from remote hosts  
> -\> LS+ES)
> 
> I am going to install 3 new machines, to make ES cluster, so I will make  
> sure they are debian7
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com)[https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/CAGqkPEiketsU0dufcdxha-t0Fi19eEmtJZ9A3SgRNyP%2BGZ96pQ%40mail.gmail.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624Y%3DqjNPJT\_RSBzHJEeNZgdCkWYaTUKGJ7x46tUfnXYsdA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624Y%3DqjNPJT_RSBzHJEeNZgdCkWYaTUKGJ7x46tUfnXYsdA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-message-not-fully-read-request/16210/10 "2017-07-06T01:45:07Z")

</div>


