# Facing Rate limiting issue in my elastic search cluster

**URL:** <https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435>\
**Category:** Elasticsearch\
**Created:** [October 8, 2024, 11:01am UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435 "2024-10-08T11:01:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rajat\_Jainwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajat_jainwal/32/138173_2.png) [@Rajat\_Jainwal](https://discuss.elastic.co/u/Rajat_Jainwal)\
**Post date:** [October 8, 2024, 11:01am UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/1 "2024-10-08T11:01:41Z")

</div>

I have a k8s cluster which as 3 ES nodes deployed & this es cluster is used by another pod

In the logs of my pod I see logs like

```auto
Node <Urllib3HttpNode(http://es.elastic-system.svc:9200)> has failed for 1 times in a row, putting on 1 second

```

Retrying request after non-successful status 429

But in the elasticsearch cluster there is no log related to any request getting rejected.  
Even in the thread\_pool API i see count as 0 rejected

```auto
_cat/thread_pool?v&s=t,n&h=type,name,node_name,active,queue,rejected,completed

```

Can someone please help me with the next steps to debug this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 8, 2024, 11:33am UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/2 "2024-10-08T11:33:24Z")

</div>

Which version of Elasticsearch are you using?

What type of operation/request is resulting in the 429?

What is the size and specification of the cluster (CPU, RAM, type of storage used)?

What load is the cluster under? What is the use case?

As outlined [in this old blog post](https://www.elastic.co/blog/why-am-i-seeing-bulk-rejections-in-my-elasticsearch-cluster) (not sure how applicable it is in newer versions) 429s generally mean that you are overloading the cluster. This can be due to a spike in traffic or lack of resources.

---

<div class="post-metadata">

**Author:** ![Rajat\_Jainwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajat_jainwal/32/138173_2.png) [@Rajat\_Jainwal](https://discuss.elastic.co/u/Rajat_Jainwal)\
**Post date:** [October 8, 2024, 11:53am UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/3 "2024-10-08T11:53:00Z")

</div>

We are using version 8.14.3

Cpu for each node is set to 12 & RAM is set to 22Gib

I'm not sure about operation at the moment.

It is possible that it might be due to cpu and memory load but the thread pool api show rejected count as 0. So i'm not sure if resource usage load is the definite reason

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 8, 2024, 12:06pm UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/4 "2024-10-08T12:06:14Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> What load is the cluster under? What is the use case?

Can you provide some details around this?

> [@Christian\_Dahlqvist](#):
>
> What is the size and specification of the cluster (CPU, RAM, type of storage used)?

What type of storage are you using? Elasticsearch can be very I/O intensive and storage performance is often the limiting factor rather than CPU or RAM.

---

<div class="post-metadata">

**Author:** ![Rajat\_Jainwal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajat_jainwal/32/138173_2.png) [@Rajat\_Jainwal](https://discuss.elastic.co/u/Rajat_Jainwal)\
**Post date:** [October 8, 2024, 12:36pm UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/5 "2024-10-08T12:36:59Z")

</div>

Storage class is standard-rwo by gcp and it is having 50gb for each node

For the load, I used this API & got following output

```auto
{{baseUrl}}/_cat/nodes?v=true&s=cpu:desc&h=ram.current,ram.max,ram.percent,name,disk.used,cpu

```

I can derive following values  
ram.current ram.max ram.percent name disk.used cpu  
20.1gb 21.4gb 94 elasticsearch-2 290.5mb 7  
20.1gb 21.4gb 94 elasticsearch-0 307.6mb 5  
16gb 21.4gb 74 elasticsearch-1 167.2mb 5

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 8, 2024, 12:53pm UTC](https://discuss.elastic.co/t/facing-rate-limiting-issue-in-my-elastic-search-cluster/368435/6 "2024-10-08T12:53:47Z")

</div>

> [@Rajat\_Jainwal](#):
>
> Storage class is standard-rwo by gcp and it is having 50gb for each node

I am not very familiar with GCP storage classes, but based on quick search that seems like very slow storage. If it is it could explain the poor performance.

> [@Rajat\_Jainwal](#):
>
> For the load, I used this API

I was more referring to indexing and search load. How many indexing and update operations do you perform per second (includes deletes)? How heavy is the search load?

How many indices and shards is you data distributed across? What is the average shard size?
