[ERROR][logstash.outputs.elasticsearch] An unknown error occurred sending a bulk request to Elasticsearch


(Nikhil Jaiswal) #1

Hi,

I am getting this error while running logstash, i am not able to rectify the issue from this log, after running configtest , i am getting Configuration Ok message in screen.

[2017-09-20T11:33:29,335][ERROR][logstash.outputs.elasticsearch] An unknown error occurred sending a bulk request to Ela
sticsearch. We will retry indefinitely {:error_message=>"Unrecognized token 'The': was expecting ('true', 'false' or 'nu
ll')\n at [Source: [B@2268bb96; line: 1, column: 5]", :error_class=>"LogStash::Json::ParserError", :backtrace=>["C:/SIEM
/logstash-5.5.1/logstash-core/lib/logstash/json.rb:41:in jruby_load'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logsta sh/json.rb:38:injruby_load'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7
-java/lib/logstash/outputs/elasticsearch/http_client.rb:143:in bulk_send'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby /1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasticsearch/http_client.rb:123:inbulk'", "C:
/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elastics
earch/common.rb:225:in safe_bulk'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch- 7.3.7-java/lib/logstash/outputs/elasticsearch/common.rb:123:insubmit'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.
9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasticsearch/common.rb:91:in retrying_submit'", " C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasti csearch/common.rb:42:inmulti_receive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/output_delegator_strategies
/shared.rb:13:in multi_receive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/output_delegator.rb:47:inmulti_r
eceive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/pipeline.rb:420:in output_batch'", "org/jruby/RubyHash.jav a:1342:ineach'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/pipeline.rb:419:in output_batch'", "C:/SIEM/logst ash-5.5.1/logstash-core/lib/logstash/pipeline.rb:365:inworker_loop'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logsta
sh/pipeline.rb:330:in `start_workers'"]}


(Mark Walkom) #2

Check your Elasticsearch logs for something as the same time, it will likely mention boolean and mapping.


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.