# ElasticsearchError error=“400 - Rejected by Elasticsearch

**URL:** <https://discuss.elastic.co/t/elasticsearcherror-error-400-rejected-by-elasticsearch/247477>\
**Category:** Elasticsearch\
**Created:** [September 4, 2020, 4:20am UTC](https://discuss.elastic.co/t/elasticsearcherror-error-400-rejected-by-elasticsearch/247477 "2020-09-04T04:20:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![akhinair](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@akhinair](https://discuss.elastic.co/u/akhinair)\
**Post date:** [September 4, 2020, 4:20am UTC](https://discuss.elastic.co/t/elasticsearcherror-error-400-rejected-by-elasticsearch/247477/1 "2020-09-04T04:20:07Z")

</div>

I am using EFK stack in my GKE cluster and recently i observed below errors in my fluentd logs. This has started after adding new data point for geopoint in the fluentd. can somebody please help on this?

`2020-09-03 16:51:10 +0000 [warn]: dump an error event: error_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="kubernetes.var.log.containers.nginx-ingress-controller-6cf5b5865b-42tk7_default_nginx-ingress-controller-86366553c82ed2b467adb8ce32302bdf1560b2083d2224aa51097f778acea172.log" time=2020-09-03 16:50:55.689944289 +0000 record`

http\_geohash is the new datapoint added in the fluentd config map.

fluent\_elastic\_mapping.template: |-  
{  
"template": "fluentd-\*",  
"mappings": {  
"_default_": {  
"properties" : {  
"geoip\_location": { "type": "geo\_point" },  
"http\_geohash": { "type": "geo\_point" }  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 4, 2020, 5:37am UTC](https://discuss.elastic.co/t/elasticsearcherror-error-400-rejected-by-elasticsearch/247477/2 "2020-09-04T05:37:25Z")

</div>

What does the data look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2020, 5:37am UTC](https://discuss.elastic.co/t/elasticsearcherror-error-400-rejected-by-elasticsearch/247477/3 "2020-10-02T05:37:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
