# ES 8.18.3 - ruby api: getting "\<Elastic::Transport::Transport::Error: Net::ReadTimeout with #\<TCPSocket:(closed)\>\>"

**URL:** https://discuss.elastic.co/t/es-8-18-3-ruby-api-getting-elastic-net-readtimeout-with-tcpsocket-closed/383662
**Category:** Elasticsearch
**Created:** [November 25, 2025, 11:54pm UTC](https://discuss.elastic.co/t/es-8-18-3-ruby-api-getting-elastic-net-readtimeout-with-tcpsocket-closed/383662 "2025-11-25T23:54:11Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)
#### Post date: [November 25, 2025, 11:54pm UTC](https://discuss.elastic.co/t/es-8-18-3-ruby-api-getting-elastic-net-readtimeout-with-tcpsocket-closed/383662/1 "2025-11-25T23:54:11Z")

</div>

I have a ruby program that ingests data into ES (using bulk)

I am seeing periodic failures on bulk uploads which raise exception `<Elastic::Transport::Transport::Error: Net::ReadTimeout with #<TCPSocket:(closed)>> `

These come in cluster so I assume they are trigged by load on the clusters.

We recently upgraded to version 8 which does not have a separate elasticsearch-transport gem. I had code that handled these but now there are no exception constants for `Elastic::Transport`.

How can I trap these errors?

current code:

```auto
    index_params= { index: index_n, body: batch } # timeout: 10,K body: batch }                                                                                                                                                 
    begin
      r = @conn.perform_api_request(:bulk, index_params, true )
# rescue Elasticsearch::Transport::Transport::Errors => e                                                                                                                                                                     
# $logger.warn "bulk error #{e.message}"                                                                                                                                                                                    
# @transport_failure = true                                                                                                                                                                                                 
    rescue => e
      $logger.warn "bulk error #{e.inspect}" # .message}"                                                                                                                                                                        
      if e.message == 'execution expired' or e.message.match(/^Failed to open/) # timeout                                                                                                                                       
        @transport_failure = true
      end
    end

```

with the pre version 8 code commented.

now outputs

```auto
[2025-11-26T10:50:32] WARN : bulk error #<Elastic::Transport::Transport::Error: Net::ReadTimeout with #<TCPSocket:(closed)>>
[2025-11-26T10:50:42] WARN : bulk error #<Elastic::Transport::Transport::Error: Net::ReadTimeout with #<TCPSocket:(closed)>>

```

Also and ideas about what is causing the problem at the ES end

Grasping at straws I have reduced the batch size to 1000 from 5000. docs are small - order of 1KB with less than a dozen fields

---

<div class="post-metadata">

### Author: ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)
#### Post date: [December 1, 2025, 9:02pm UTC](https://discuss.elastic.co/t/es-8-18-3-ruby-api-getting-elastic-net-readtimeout-with-tcpsocket-closed/383662/2 "2025-12-01T21:02:42Z")

</div>

tracked this down to the fact that the ES host did not have enough memory and the garbage collection was triggering swapping. doubling the memory and turning of swapping fixed the issues.

There were warning in the logs but they were not easy to interpret.

---

<div class="post-metadata">

### Author: ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)
#### Post date: [December 1, 2025, 9:35pm UTC](https://discuss.elastic.co/t/es-8-18-3-ruby-api-getting-elastic-net-readtimeout-with-tcpsocket-closed/383662/3 "2025-12-01T21:35:37Z")

</div>

“Swapping is very bad for performance, for node stability, and _should be avoided at all costs_”

Cut and paste straight from the [documentation](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/setup-configuration-memory).
