# Elasticsearch node unresponsive, high active\_opens, CLOSE\_WAIT

**URL:** <https://discuss.elastic.co/t/elasticsearch-node-unresponsive-high-active-opens-close-wait/28996>\
**Category:** Elasticsearch\
**Created:** [September 10, 2015, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-node-unresponsive-high-active-opens-close-wait/28996 "2015-09-10T08:37:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sinneduy](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@sinneduy](https://discuss.elastic.co/u/sinneduy)\
**Post date:** [September 10, 2015, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-node-unresponsive-high-active-opens-close-wait/28996/1 "2015-09-10T08:37:53Z")

</div>

Received an alert saying that one of my nodes was down, when I tried to curl / it just hung.

Checked on the health of the cluster and the node and noted something very strange:

```
        "network": {
            "tcp": {
                "active_opens": 102188,
                "passive_opens": 7133683,
                "curr_estab": 205,
                "in_segs": 1483621255,
                "out_segs": 2405602124,
                "retrans_segs": 569006,
                "estab_resets": 9251,
                "attempt_fails": 3252,
                "in_errs": 11,
                "out_rsts": 23640
            }
        },

```

```auto
# sudo netstat -tupn |grep CLOSE_WAIT | wc -l
11711
# sudo netstat -tupn | wc -l
11940

```

shows a ton of CLOSE\_WAIT

The active opens were about 10x more on this node than any other one. What are active opens vs passive opens, and what is the expected number of active/passive opens, and how can I make elasticsearch close these connections more aggressively?

I'm running `1.7.1` on Java 1.8

```auto
{
  "status" : 200,
  "name" : <redacted>,
  "cluster_name" : <redacted>,
  "version" : {
    "number" : "1.7.1",
    "build_hash" : "b88f43fc40b0bcd7f173a1f9ee2e97816de80b19",
    "build_timestamp" : "2015-07-29T09:54:16Z",
    "build_snapshot" : false,
    "lucene_version" : "4.10.4"
  },
  "tagline" : "You Know, for Search"
}

```

[http://elasticsearch-users.115913.n3.nabble.com/Increasing-CLOSE-WAIT-connections-and-HTTP-current-open-metric-td4019752.html](http://elasticsearch-users.115913.n3.nabble.com/Increasing-CLOSE-WAIT-connections-and-HTTP-current-open-metric-td4019752.html)

seems to be related, but it doesn't to have a conclusive solution or understanding of what is happening

---

<div class="post-metadata">

**Author:** ![Jason\_Wee](https://avatars.discourse-cdn.com/v4/letter/j/7ea924/32.png) [@Jason\_Wee](https://discuss.elastic.co/u/Jason_Wee)\
**Post date:** [November 11, 2016, 5:25am UTC](https://discuss.elastic.co/t/elasticsearch-node-unresponsive-high-active-opens-close-wait/28996/2 "2016-11-11T05:25:20Z")

</div>

i encounter the same situation as similar as your yesterday. today when i check again on the system monitoring history, have high number of passive\_opens just before this node become unresponsive. usual passive open hang around 2,500,000 and because i written a multithreading script with 2 threads, the passive open goes to approximately 3,500,000 just before this node become unresponsive and detach from the cluster.

other metrics were also check like higher than usage for cpu usage on %user , index rate , translog operations , merge requests, cms gc activities and jvm direct pool mem usage

from these empirically, i guess the node is just too busy due to gc , merge and index and it timed out.. i can see several timeout of ping request in the log too.

hth

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:05pm UTC](https://discuss.elastic.co/t/elasticsearch-node-unresponsive-high-active-opens-close-wait/28996/3 "2017-07-05T22:05:55Z")

</div>


