# Facing error and warning messages with ELK stack

**URL:** <https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889>\
**Category:** Elasticsearch\
**Created:** [September 19, 2014, 6:33pm UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889 "2014-09-19T18:33:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shriyansh\_jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shriyansh_jain/32/1035_2.png) [@shriyansh\_jain](https://discuss.elastic.co/u/shriyansh_jain)\
**Post date:** [September 19, 2014, 6:33pm UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889/1 "2014-09-19T18:33:25Z")

</div>

I have a setup of ELK stack with redis as a broker and a cluster of 2  
Elasticsearch Nodes. The stack was running good and suddenly I started  
facing the following error and warning messages at different levels of the  
stack.

[http://pastebin.com/eG7p0PCc](http://pastebin.com/eG7p0PCc)

If I restart the redis broker, Logstash and the Elasticsearch node showing  
error message, the stack comes back, with Redis-broker performing well,  
able to allocate memory but I have been seeing the same error messages for  
E.S and Logstash after the restart. Because of which the redis-broker start  
buffering the logs in memory and eventually goes out of memory as E.S and  
logstash stop indexing the data.  
I am trying out figure out what might be the possible cause of this, any  
help will be really appreciated. Please let me know if there is any  
confusion understanding the situation.

Thank you,  
Shriyansh

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 19, 2014, 9:16pm UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889/2 "2014-09-19T21:16:30Z")

</div>

It looks like networking issues, lots of connection reset/closed/timeout.

It might help if you can out your configs into a pastebin too.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 20 September 2014 04:33, shriyansh jain [shriyanshajain@gmail.com](mailto:shriyanshajain@gmail.com) wrote:

> I have a setup of ELK stack with redis as a broker and a cluster of 2  
> Elasticsearch Nodes. The stack was running good and suddenly I started  
> facing the following error and warning messages at different levels of the  
> stack.
> 
> [Errors with Logstash:{:timestamp=\>"2014-09-19T10:32:59.241000-0700", :messag - Pastebin.com](http://pastebin.com/eG7p0PCc)
> 
> If I restart the redis broker, Logstash and the Elasticsearch node showing  
> error message, the stack comes back, with Redis-broker performing well,  
> able to allocate memory but I have been seeing the same error messages for  
> E.S and Logstash after the restart. Because of which the redis-broker start  
> buffering the logs in memory and eventually goes out of memory as E.S and  
> logstash stop indexing the data.  
> I am trying out figure out what might be the possible cause of this, any  
> help will be really appreciated. Please let me know if there is any  
> confusion understanding the situation.
> 
> Thank you,  
> Shriyansh
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624YD7tqLU2%2BuufpvhO%2BgzSZA%3DLyMFods1o5g2JxHzr2%2B-Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624YD7tqLU2%2BuufpvhO%2BgzSZA%3DLyMFods1o5g2JxHzr2%2B-Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![shriyansh\_jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shriyansh_jain/32/1035_2.png) [@shriyansh\_jain](https://discuss.elastic.co/u/shriyansh_jain)\
**Post date:** [September 19, 2014, 9:53pm UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889/3 "2014-09-19T21:53:07Z")

</div>

Which configuration you will be interested to loo at.?

-Shriyansh

On Friday, September 19, 2014 2:17:16 PM UTC-7, Mark Walkom wrote:

> It looks like networking issues, lots of connection reset/closed/timeout.
> 
> It might help if you can out your configs into a pastebin too.
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 20 September 2014 04:33, shriyansh jain \<[shriyan...@gmail.com](mailto:shriyan...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I have a setup of ELK stack with redis as a broker and a cluster of 2  
> > Elasticsearch Nodes. The stack was running good and suddenly I started  
> > facing the following error and warning messages at different levels of the  
> > stack.
> > 
> > [Errors with Logstash:{:timestamp=\>"2014-09-19T10:32:59.241000-0700", :messag - Pastebin.com](http://pastebin.com/eG7p0PCc)
> > 
> > If I restart the redis broker, Logstash and the Elasticsearch node  
> > showing error message, the stack comes back, with Redis-broker performing  
> > well, able to allocate memory but I have been seeing the same error  
> > messages for E.S and Logstash after the restart. Because of which the  
> > redis-broker start buffering the logs in memory and eventually goes out of  
> > memory as E.S and logstash stop indexing the data.  
> > I am trying out figure out what might be the possible cause of this, any  
> > help will be really appreciated. Please let me know if there is any  
> > confusion understanding the situation.
> > 
> > Thank you,  
> > Shriyansh
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/624cd024-cc69-4eba-8bf9-d05b21f8d41a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/624cd024-cc69-4eba-8bf9-d05b21f8d41a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![shriyansh\_jain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shriyansh_jain/32/1035_2.png) [@shriyansh\_jain](https://discuss.elastic.co/u/shriyansh_jain)\
**Post date:** [September 19, 2014, 9:53pm UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889/4 "2014-09-19T21:53:53Z")

</div>

which configuration's you will be interested to look at.?

-Shriyansh

On Friday, September 19, 2014 2:17:16 PM UTC-7, Mark Walkom wrote:

> It looks like networking issues, lots of connection reset/closed/timeout.
> 
> It might help if you can out your configs into a pastebin too.
> 
> Regards,  
> Mark Walkom
> 
> Infrastructure Engineer  
> Campaign Monitor  
> email: [ma...@campaignmonitor.com](mailto:ma...@campaignmonitor.com) \<javascript:\>  
> web: [www.campaignmonitor.com](http://www.campaignmonitor.com)
> 
> On 20 September 2014 04:33, shriyansh jain \<[shriyan...@gmail.com](mailto:shriyan...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I have a setup of ELK stack with redis as a broker and a cluster of 2  
> > Elasticsearch Nodes. The stack was running good and suddenly I started  
> > facing the following error and warning messages at different levels of the  
> > stack.
> > 
> > [Errors with Logstash:{:timestamp=\>"2014-09-19T10:32:59.241000-0700", :messag - Pastebin.com](http://pastebin.com/eG7p0PCc)
> > 
> > If I restart the redis broker, Logstash and the Elasticsearch node  
> > showing error message, the stack comes back, with Redis-broker performing  
> > well, able to allocate memory but I have been seeing the same error  
> > messages for E.S and Logstash after the restart. Because of which the  
> > redis-broker start buffering the logs in memory and eventually goes out of  
> > memory as E.S and logstash stop indexing the data.  
> > I am trying out figure out what might be the possible cause of this, any  
> > help will be really appreciated. Please let me know if there is any  
> > confusion understanding the situation.
> > 
> > Thank you,  
> > Shriyansh
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/99ac902f-c183-4700-9d32-9d23ea0d7c3c%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ca66b25e-77ab-4339-820e-74e25f5e9e7e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ca66b25e-77ab-4339-820e-74e25f5e9e7e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:00am UTC](https://discuss.elastic.co/t/facing-error-and-warning-messages-with-elk-stack/19889/5 "2017-07-06T01:00:59Z")

</div>


