# Error in logstash logs: " retrying failed action with response code: 429

**URL:** <https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212>\
**Category:** Elasticsearch\
**Created:** [September 12, 2019, 9:25am UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212 "2019-09-12T09:25:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilayda\_Akinalan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilayda_akinalan/32/54058_2.png) [@Ilayda\_Akinalan](https://discuss.elastic.co/u/Ilayda_Akinalan)\
**Post date:** [September 12, 2019, 9:25am UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/1 "2019-09-12T09:25:52Z")

</div>

Hi,  
I keep getting the below error in my logstash logs - im assuming the problem is with elasticsearch rather than logstash itself. My understanding of this is that elasticsearch cannot cope with the amount of data that is being sent from logstash.  
Could someone assist me regarding this issue please?

`[2019-09-11T00:03:09,966][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 429 ({"type"=>"es_rejected_execution_exception", "reason"=>"rejected execution of processing of [1643093099][indices:data/write/bulk[s][p]]: request: BulkShardRequest [[logstash-2019.09.11][2]] containing [26] requests, target allocation id: Hp2yfFaZQ2qEHULsOkHpig, primary term: 1 on EsThreadPoolExecutor[name = elastic2/write, queue capacity = 200, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@411ee1d1[Running, pool size = 7, active threads = 7, queued tasks = 334, completed tasks = 907271405]]"})`

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [September 12, 2019, 9:52am UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/2 "2019-09-12T09:52:49Z")

</div>

As your understanding, your Elasticsearch cluster is unable to cope with current load. You must investigate why cluster is overload? not enough capacity, too many indexing, or uneven load?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 12, 2019, 11:13am UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/3 "2019-09-12T11:13:20Z")

</div>

How many indices and shards are you actively indexing into?

---

<div class="post-metadata">

**Author:** ![Ilayda\_Akinalan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilayda_akinalan/32/54058_2.png) [@Ilayda\_Akinalan](https://discuss.elastic.co/u/Ilayda_Akinalan)\
**Post date:** [September 17, 2019, 8:23am UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/4 "2019-09-17T08:23:20Z")

</div>

Currently I have 3 nodes, 330 indices and 1,640 shards to be specific.  
As a solution to this problem we were considering to add an extra elasticsearch node as it seems that the load on the nodes always seem quite high.

Is there any problem with having 4 elasticsearch nodes with 1 master node?

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [September 17, 2019, 12:44pm UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/6 "2019-09-17T12:44:32Z")

</div>

@Ilayda_Akinalan,

> [@Ilayda\_Akinalan](#):
>
> Is there any problem with having 4 elasticsearch nodes with 1 master node?

Yes..its not good practice having only single master node in cluster. What will you do if your master node goes down? Your cluster will be down. So you must have at least 3 master node in cluster to keep cluster up and running and to avoid from split brain problem.

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 17, 2019, 1:04pm UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/7 "2019-09-17T13:04:08Z")

</div>

Are you indexing into all these shards actively? I would recommend reading [this blog post](https://www.elastic.co/blog/why-am-i-seeing-bulk-rejections-in-my-elasticsearch-cluster).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2019, 1:04pm UTC](https://discuss.elastic.co/t/error-in-logstash-logs-retrying-failed-action-with-response-code-429/199212/8 "2019-10-15T13:04:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
