# Failed to execute bulk item (update) BulkShardRequest

**URL:** <https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687>\
**Category:** Elasticsearch\
**Created:** [July 27, 2020, 5:52am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687 "2020-07-27T05:52:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![devinderpal](https://avatars.discourse-cdn.com/v4/letter/d/45deac/32.png) [@devinderpal](https://discuss.elastic.co/u/devinderpal)\
**Post date:** [July 27, 2020, 5:52am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687/1 "2020-07-27T05:52:35Z")

</div>

I am facing Live server problem on elastisearch.  
My RAM is 32 GB and Heap Memory is 8GB. But still i am facing the problem in elastisearch. Bellow are the logs

// Error Log  
[2020-07-26T20:15:05,456][DEBUG][o.e.a.b.TransportShardBulkAction] [ISu\_GIR] [vue\_storefront\_catalog\_1\_1595322631][0] failed to execute bulk item (update) BulkShardRequest [[vue\_storefront\_catalog\_1\_1595322631][0]] containing [146] requests  
org.elasticsearch.index.engine.DocumentMissingException: [product][9796]: document missing  
at org.elasticsearch.action.update.UpdateHelper.prepare(UpdateHelper.java:93) ~[elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.update.UpdateHelper.prepare(UpdateHelper.java:82) ~[elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.executeUpdateRequest(TransportShardBulkAction.java:276) ~[elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.executeBulkItemRequest(TransportShardBulkAction.java:161) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:114) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:69) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryShardReference.perform(TransportReplicationAction.java:975) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryShardReference.perform(TransportReplicationAction.java:944) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.ReplicationOperation.execute(ReplicationOperation.java:113) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.onResponse(TransportReplicationAction.java:345) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.onResponse(TransportReplicationAction.java:270) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$1.onResponse(TransportReplicationAction.java:924) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$1.onResponse(TransportReplicationAction.java:921) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.index.shard.IndexShardOperationsLock.acquire(IndexShardOperationsLock.java:151) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.index.shard.IndexShard.acquirePrimaryOperationLock(IndexShard.java:1659) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction.acquirePrimaryShardReference(TransportReplicationAction.java:933) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction.access$500(TransportReplicationAction.java:92) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.doRun(TransportReplicationAction.java:291) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryOperationTransportHandler.messageReceived(TransportReplicationAction.java:266) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryOperationTransportHandler.messageReceived(TransportReplicationAction.java:248) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.transport.RequestHandlerRegistry.processMessageReceived(RequestHandlerRegistry.java:69) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.transport.TransportService$7.doRun(TransportService.java:662) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:675) [elasticsearch-5.6.16.jar:5.6.16]  
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-5.6.16.jar:5.6.16]  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0\_252]  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0\_252]  
at java.lang.Thread.run(Thread.java:748) [?:1.8.0\_252]  
[2020-07-26T21:07:52,138][INFO][o.e.c.m.MetaDataCreateIndexService] [ISu\_GIR] [t19hfzgnp7-meow] creating index, cause [api], templates , shards [5]/[1], mappings

This issue will breaks the whole functionality of site.  
So can any one help me to fix this problem?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 27, 2020, 6:29am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687/2 "2020-07-27T06:29:17Z")

</div>

The last line in the log is worrysome:

> [2020-07-26T21:07:52,138][INFO][o.e.c.m.MetaDataCreateIndexService] [ISu\_GIR] [t19hfzgnp7-meow] creating index, cause [api], templates , shards [5]/[1], mappings

See the `t19hfzgnp7-meow` index? Your cluster has been compromised by the [Meow attack](https://www.bleepingcomputer.com/news/security/new-meow-attack-has-deleted-almost-4-000-unsecured-databases/), which randomly deletes data from unsecured clusters.

I would urge you to properly [secure your cluster](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-cluster.html) very quickly, especially since [Elasticsearch Security is FREE](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free) as of 6.8.0 and 7.1.0.

---

<div class="post-metadata">

**Author:** ![devinderpal](https://avatars.discourse-cdn.com/v4/letter/d/45deac/32.png) [@devinderpal](https://discuss.elastic.co/u/devinderpal)\
**Post date:** [July 27, 2020, 7:17am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687/3 "2020-07-27T07:17:05Z")

</div>

Thanks @val for your response.  
How i can secure the elasticsearch for 5.6.16? Because this the version that i m using.

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 27, 2020, 7:20am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687/4 "2020-07-27T07:20:04Z")

</div>

You should consider upgrading to 6.8.0 if that's possible. If not, you really need to at least make sure that your cluster is not publicly accessible anymore.

Also I hope you have snapshots/backups of your data that was deleted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2020, 7:20am UTC](https://discuss.elastic.co/t/failed-to-execute-bulk-item-update-bulkshardrequest/242687/5 "2020-08-24T07:20:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
