# Failed to perform any bulk index operations: Post "http://my\_elastic\_ip/\_bulk": EOF

**URL:** <https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 22, 2024, 10:16pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582 "2024-01-22T22:16:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [January 22, 2024, 10:16pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582/1 "2024-01-22T22:16:04Z")

</div>

Hi, Im getting this errors in filebeat

```auto
Jan 22 18:56:38 proxy-120 filebeat[15099]: 2024-01-22T18:56:38.420-0300 ERROR [elasticsearch] elasticsearch/client.go:226 failed to perform any bulk index operations: Post "http://my_elastic_ip:9200/_bulk": EOF
Jan 22 18:56:38 proxy-120 filebeat[15099]: 2024-01-22T18:56:38.420-0300 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
Jan 22 18:56:38 proxy-120 filebeat[15099]: 2024-01-22T18:56:38.420-0300 INFO [publisher] pipeline/retry.go:223 done
Jan 22 18:56:40 proxy-120 filebeat[15099]: 2024-01-22T18:56:40.331-0300 ERROR [publisher_pipeline_output] pipeline/output.go:180 failed to publish events: Post "http://my_elastic_ip:9200/_bulk": EOF

```

-no firewall , no selinux in the machines  
-I can curl to elastic, create index via curl, bulk indexing via curl from the filebeat machine  
-test data arriving filebeat with stdout ouput

this is my conf in filebeat.yml

```auto
filebeat.inputs:
- type: filestream
  enabled: false
  paths:
    - /var/log/*.log

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1

output.elasticsearch:
  hosts: ["my_elastic_ip:9200"]
  username: "elastic"
  password: "my_pass"
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded

```

netflow module:

```auto
- module: netflow
  log:
    enabled: true
    var:
      netflow_host: 0.0.0.0
      netflow_port: 2055

      internal_networks:
        - private

```

Any ideas?  
thanks!

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 22, 2024, 11:20pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582/2 "2024-01-22T23:20:13Z")

</div>

I've seen this behavior before when the bulk request is interrupted. EOF means the network socket was closed prematurely, when it was expecting more data.

Do you have a network firewall or proxy between the device and the elasticsearch node?

It looks like you're not using https, you should be able to capture a tcpdump and see if it's the client or server closing the connection prematurely.

Can you attempt to do a large \_bulk request from the client to the server?

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [January 23, 2024, 4:16pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582/3 "2024-01-23T16:16:06Z")

</div>

Hi, It was a networking problem, your answer help us to reach te solution, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2024, 6:16pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582/4 "2024-02-20T18:16:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
