# Elastiscsearch Output - Attempted to send a bulk request

**URL:** <https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703>\
**Category:** Logstash\
**Created:** [February 1, 2019, 9:41am UTC](https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703 "2019-02-01T09:41:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gochou](https://avatars.discourse-cdn.com/v4/letter/g/5f8ce5/32.png) [@Gochou](https://discuss.elastic.co/u/Gochou)\
**Post date:** [February 1, 2019, 9:41am UTC](https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703/1 "2019-02-01T09:41:14Z")

</div>

Hi,

So from time to time I get this error in my logstash logs:

```
[2019-02-01T01:35:18,762][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error_message=>"Elasticsearch Unreachable: [host:443/][Manticore::ClientProtocolException] host:443 failed to respond", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will_retry_in_seconds=>2}
[2019-02-01T01:35:20,771][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch, but no there are no living connections in the connection pool. Perhaps Elasticsearch is unreachable or down? {:error_message=>"No Available connections", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError", :will_retry_in_seconds=>4}
[2019-02-01T01:35:22,626][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"host:443/"}
[2019-02-01T03:11:02,517][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [host:443/][Manticore::ClientProtocolException] host:443 failed to respond {:url=>host:443/, :error_message=>"Elasticsearch Unreachable: [host:443/][Manticore::ClientProtocolException] host:443 failed to respond", :error_class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}
[2019-02-01T03:11:02,517][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error_message=>"Elasticsearch Unreachable: [host:443/][Manticore::ClientProtocolException] host:443 failed to respond", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will_retry_in_seconds=>2}
[2019-02-01T03:11:02,704][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"host:443/"}

```

It doesn't actually seem to affect my Elastic Stack (no missing logs in ES) but I would still like to resolve it if possible.  
I'm running Filebeat 6.5.4, Logstash 6.5.4 and Elasticsearch AWS 5.6.8.  
I know they aren't supposed to be compatible if you look a the compatibility matrix but it's working fine for me.

Do you have any idea what's causing this ?

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 4, 2019, 5:44pm UTC](https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703/2 "2019-02-04T17:44:47Z")

</div>

It is probably caused when AWS ES is too busy to accept a connection. The attempt is queued, retried and succeeds.

You might consider tuning your AWS ES for better performance.

---

<div class="post-metadata">

**Author:** ![Gochou](https://avatars.discourse-cdn.com/v4/letter/g/5f8ce5/32.png) [@Gochou](https://discuss.elastic.co/u/Gochou)\
**Post date:** [February 5, 2019, 8:33am UTC](https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703/3 "2019-02-05T08:33:56Z")

</div>

I don't have access to the AWS ES tuning, so if it retries and succeeds is it an error my cluster can live with temporarily without too many issues ? (For now I'm just doing testing so I'll see to tune it when I move on to something more serious)  
Or, if it is actually dangerous to keep, will tuning down Logstash help ?

Thanks again for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2019, 8:34am UTC](https://discuss.elastic.co/t/elastiscsearch-output-attempted-to-send-a-bulk-request/166703/4 "2019-03-05T08:34:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
