[ERROR][logstash.outputs.elasticsearch] An unknown error occurred sending a bulk request to Elasticsearch

Hi,

I am getting this error while running logstash, i am not able to rectify the issue from this log, after running configtest , i am getting Configuration Ok message in screen.

[2017-09-20T11:33:29,335][ERROR][logstash.outputs.elasticsearch] An unknown error occurred sending a bulk request to Ela
sticsearch. We will retry indefinitely {:error_message=>"Unrecognized token 'The': was expecting ('true', 'false' or 'nu
ll')\n at [Source: [B@2268bb96; line: 1, column: 5]", :error_class=>"LogStash::Json::ParserError", :backtrace=>["C:/SIEM
/logstash-5.5.1/logstash-core/lib/logstash/json.rb:41:in jruby_load'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logsta sh/json.rb:38:injruby_load'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7
-java/lib/logstash/outputs/elasticsearch/http_client.rb:143:in bulk_send'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby /1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasticsearch/http_client.rb:123:inbulk'", "C:
/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elastics
earch/common.rb:225:in safe_bulk'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch- 7.3.7-java/lib/logstash/outputs/elasticsearch/common.rb:123:insubmit'", "C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.
9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasticsearch/common.rb:91:in retrying_submit'", " C:/SIEM/logstash-5.5.1/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.7-java/lib/logstash/outputs/elasti csearch/common.rb:42:inmulti_receive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/output_delegator_strategies
/shared.rb:13:in multi_receive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/output_delegator.rb:47:inmulti_r
eceive'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/pipeline.rb:420:in output_batch'", "org/jruby/RubyHash.jav a:1342:ineach'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logstash/pipeline.rb:419:in output_batch'", "C:/SIEM/logst ash-5.5.1/logstash-core/lib/logstash/pipeline.rb:365:inworker_loop'", "C:/SIEM/logstash-5.5.1/logstash-core/lib/logsta
sh/pipeline.rb:330:in `start_workers'"]}

Check your Elasticsearch logs for something as the same time, it will likely mention boolean and mapping.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.