# Fiebeat test output error (Java heap size)

**URL:** <https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 5, 2021, 2:07am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483 "2021-08-05T02:07:14Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 5, 2021, 2:07am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/1 "2021-08-05T02:07:14Z")

</div>

Hi All

Can anyone help one the below error ? the file beat fails the test and we unable to access the Wazuh's dashboard

[root@ELS01 conf]# filebeat test output  
elasticsearch: [http://1.1.1.1:9200](http://1.1.1.1:9200)...  
parse url... OK  
connection...  
parse host... OK  
dns lookup... OK  
addresses: 1.1.1.1  
dial up... OK  
TLS... WARN secure connection disabled  
talk to server... ERROR Connection marked as failed because the onConnect  
callback failed: cannot retrieve the elasticsearch license from the /\_xpack  
endpoint, Filebeat requires the default distribution of Elasticsearch. Please  
make the endpoint accessible to Filebeat so it can verify the license.: could  
not retrieve the license information from the cluster: 429 Too Many Requests:  
{"error":{"root\_cause":  
[{"type":"circuit\_breaking\_exception","reason":"[parent] Data too large, data  
for [\<http\_request\>] would be [1000976936/954.6mb], which is larger than the  
limit of [986061209/940.3mb], real usage: [1000976936/954.6mb], new bytes  
reserved: [0/0b], usages [request=0/0b, fielddata=0/0b,  
in\_flight\_requests=0/0b,  
accounting=144179448/137.5mb]","bytes\_wanted":1000976936,"bytes\_limit":9860612  
09,"durability":"PERMANENT"}],"type":"circuit\_breaking\_exception","reason":"[p  
arent] Data too large, data for [\<http\_request\>] would be  
[1000976936/954.6mb], which is larger than the limit of [986061209/940.3mb],  
real usage: [1000976936/954.6mb], new bytes reserved: [0/0b], usages  
[request=0/0b, fielddata=0/0b, in\_flight\_requests=0/0b,  
accounting=144179448/137.5mb]","bytes\_wanted":1000976936,"bytes\_limit":9860612  
09,"durability":"PERMANENT"},"status":429}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 5, 2021, 2:08am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/2 "2021-08-05T02:08:08Z")

</div>

Welcome to our community! 😃

It looks like your Elasticsearch is overloaded. What is the output from the `_cluster/stats?pretty&human` API?

---

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 5, 2021, 5:51am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/3 "2021-08-05T05:51:30Z")

</div>

@warkolm Please see below per your request :  
curl -XGET 'localhost:9200/\_cluster/health?pretty'  
{  
"cluster\_name" : "elasticsearch",  
"status" : "green",  
"timed\_out" : false,  
"number\_of\_nodes" : 1,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 462,  
"active\_shards" : 462,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 0,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0,  
"task\_max\_waiting\_in\_queue\_millis" : 0,  
"active\_shards\_percent\_as\_number" : 100.0  
}  
]0;root@XXX:~ [root@XXX~]# curl -XGET 'localhost:9200/\_cluster/health?pretty' &' h' u' m' a' n'  
{  
"cluster\_name" : "elasticsearch",  
"status" : "green",  
"timed\_out" : false,  
"number\_of\_nodes" : 1,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 462,  
"active\_shards" : 462,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 0,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0,  
"task\_max\_waiting\_in\_queue" : "0s",  
"task\_max\_waiting\_in\_queue\_millis" : 0,  
"active\_shards\_percent" : "100.0%",  
"active\_shards\_percent\_as\_number" : 100.0  
}  
]0;root@XXX:~ [root@XXX~]#

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 5, 2021, 5:52am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/4 "2021-08-05T05:52:54Z")

</div>

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

Also that is not the API that I asked for, it's `_cluster/stats?pretty&human`.

---

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 5, 2021, 8:24am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/5 "2021-08-05T08:24:20Z")

</div>

```auto
{
  "_nodes" : {
    "total" : 1,
    "successful" : 1,
    "failed" : 0
  },
  "cluster_name" : "elasticsearch",
  "cluster_uuid" : "gJPxqzdeSqGMEhYL22a-HQ",
  "timestamp" : 1628150444964,
  "status" : "green",
  "indices" : {
    "count" : 191,
    "shards" : {
      "total" : 462,
      "primaries" : 462,
      "replication" : 0.0,
      "index" : {
        "shards" : {
          "min" : 1,
          "max" : 3,
          "avg" : 2.418848167539267
        },
        "primaries" : {
          "min" : 1,
          "max" : 3,
          "avg" : 2.418848167539267
        },
        "replication" : {
          "min" : 0.0,
          "max" : 0.0,
          "avg" : 0.0
        }
      }
    },
    "docs" : {
      "count" : 57398485,
      "deleted" : 10075
    },
    "store" : {
      "size" : "145.9gb",
      "size_in_bytes" : 156733409177
    },
    "fielddata" : {
      "memory_size" : "0b",
      "memory_size_in_bytes" : 0,
      "evictions" : 0
    },
    "query_cache" : {
      "memory_size" : "0b",
      "memory_size_in_bytes" : 0,
      "total_count" : 0,
      "hit_count" : 0,
      "miss_count" : 0,
      "cache_size" : 0,
      "cache_count" : 0,
      "evictions" : 0
    },
    "completion" : {
      "size" : "0b",
      "size_in_bytes" : 0
    },
    "segments" : {
      "count" : 4326,
      "memory" : "137.5mb",
      "memory_in_bytes" : 144179448,
      "terms_memory" : "104mb",
      "terms_memory_in_bytes" : 109059434,
      "stored_fields_memory" : "26.1mb",
      "stored_fields_memory_in_bytes" : 27389768,
      "term_vectors_memory" : "0b",
      "term_vectors_memory_in_bytes" : 0,
      "norms_memory" : "1.2mb",
      "norms_memory_in_bytes" : 1301312,
      "points_memory" : "1.4mb",
      "points_memory_in_bytes" : 1502798,
      "doc_values_memory" : "4.6mb",
      "doc_values_memory_in_bytes" : 4926136,
      "index_writer_memory" : "0b",
      "index_writer_memory_in_bytes" : 0,
      "version_map_memory" : "0b",
      "version_map_memory_in_bytes" : 0,
      "fixed_bit_set" : "528b",
      "fixed_bit_set_memory_in_bytes" : 528,
      "max_unsafe_auto_id_timestamp" : 1601563153739,
      "file_sizes" : { }
    }
  },
  "nodes" : {
    "count" : {
      "total" : 1,
      "coordinating_only" : 0,
      "data" : 1,
      "ingest" : 1,
      "master" : 1,
      "ml" : 1,
      "voting_only" : 0
    },
    "versions" : [
      "7.5.2"
    ],
    "os" : {
      "available_processors" : 12,
      "allocated_processors" : 12,
      "names" : [
        {
          "name" : "Linux",
          "count" : 1
        }
      ],
      "pretty_names" : [
        {
          "pretty_name" : "RHEL",
          "count" : 1
        }
      ],
      "mem" : {
        "total" : "62.7gb",
        "total_in_bytes" : 67386687488,
        "free" : "25.7gb",
        "free_in_bytes" : 27645804544,
        "used" : "37gb",
        "used_in_bytes" : 39740882944,
        "free_percent" : 41,
        "used_percent" : 59
      }
    },
    "process" : {
      "cpu" : {
        "percent" : 8
      },
      "open_file_descriptors" : {
        "min" : 9943,
        "max" : 9943,
        "avg" : 9943
      }
    },
    "jvm" : {
      "max_uptime" : "6.2d",
      "max_uptime_in_millis" : 540406620,
      "versions" : [
        {
          "version" : "13.0.1",
          "vm_name" : "OpenJDK 64-Bit Server VM",
          "vm_version" : "13.0.1+9",
          "vm_vendor" : "AdoptOpenJDK",
          "bundled_jdk" : true,
          "using_bundled_jdk" : true,
          "count" : 1
        }
      ],
      "mem" : {
        "heap_used" : "978.7mb",
        "heap_used_in_bytes" : 1026335768,
        "heap_max" : "989.8mb",
        "heap_max_in_bytes" : 1037959168
      },
      "threads" : 186
    },
    "fs" : {
      "total" : "215.4gb",
      "total_in_bytes" : 231380877312,
      "free" : "27.2gb",
      "free_in_bytes" : 29278244864,
      "available" : "27.2gb",
      "available_in_bytes" : 29278244864
    },
    "plugins" : [],
    "network_types" : {
      "transport_types" : {
        "security4" : 1
      },
      "http_types" : {
        "security4" : 1
      }
    },
    "discovery_types" : {
      "zen" : 1
    },
    "packaging_types" : [
      {
        "flavor" : "default",
        "type" : "rpm",
        "count" : 1
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 6, 2021, 4:01am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/6 "2021-08-06T04:01:49Z")

</div>

Hi @warkolm

Any Idea what might cause the issue ?

Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 6, 2021, 4:37am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/7 "2021-08-06T04:37:43Z")

</div>

What do you have the JVM heap set at?

> **[Setting the heap size | Elasticsearch Guide \[7.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/heap-size.html)**

Is it perhaps left at the default of 1GB?

On a 60GB host it should be set at 26 - 28GB

Also 7.5 pretty old, newer versions automatically set the proper JVM heap size

---

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 20, 2021, 7:56am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/8 "2021-08-20T07:56:04Z")

</div>

Hi @stephenb

I managed to fix the filebeat issue by increasing the heapsize . however I "Cant" connect to management interface listening to port 5601.  
**\_cluster/stats?pretty&human` new out put per below :**

```auto
{
  "_nodes" : {
    "total" : 1,
    "successful" : 1,
    "failed" : 0
  },
  "cluster_name" : "elasticsearch",
  "cluster_uuid" : "gJPxqzdeSqGMEhYL22a-HQ",
  "timestamp" : 1629434471001,
  "status" : "green",
  "indices" : {
    "count" : 216,
    "shards" : {
      "total" : 525,
      "primaries" : 525,
      "replication" : 0.0,
      "index" : {
        "shards" : {
          "min" : 1,
          "max" : 3,
          "avg" : 2.4305555555555554
        },
        "primaries" : {
          "min" : 1,
          "max" : 3,
          "avg" : 2.4305555555555554
        },
        "replication" : {
          "min" : 0.0,
          "max" : 0.0,
          "avg" : 0.0
        }
      }
    },
    "docs" : {
      "count" : 59326820,
      "deleted" : 10420
    },
    "store" : {
      "size" : "149.4gb",
      "size_in_bytes" : 160490395427
    },
    "fielddata" : {
      "memory_size" : "0b",
      "memory_size_in_bytes" : 0,
      "evictions" : 0
    },
    "query_cache" : {
      "memory_size" : "0b",
      "memory_size_in_bytes" : 0,
      "total_count" : 0,
      "hit_count" : 0,
      "miss_count" : 0,
      "cache_size" : 0,
      "cache_count" : 0,
      "evictions" : 0
    },
    "completion" : {
      "size" : "0b",
      "size_in_bytes" : 0
    },
    "segments" : {
      "count" : 4780,
      "memory" : "145.2mb",
      "memory_in_bytes" : 152311951,
      "terms_memory" : "110.3mb",
      "terms_memory_in_bytes" : 115715159,
      "stored_fields_memory" : "26.9mb",
      "stored_fields_memory_in_bytes" : 28240488,
      "term_vectors_memory" : "0b",
      "term_vectors_memory_in_bytes" : 0,
      "norms_memory" : "1.4mb",
      "norms_memory_in_bytes" : 1494784,
      "points_memory" : "1.4mb",
      "points_memory_in_bytes" : 1551936,
      "doc_values_memory" : "5mb",
      "doc_values_memory_in_bytes" : 5309584,
      "index_writer_memory" : "0b",
      "index_writer_memory_in_bytes" : 0,
      "version_map_memory" : "0b",
      "version_map_memory_in_bytes" : 0,
      "fixed_bit_set" : "528b",
      "fixed_bit_set_memory_in_bytes" : 528,
      "max_unsafe_auto_id_timestamp" : 1628479262137,
      "file_sizes" : { }
    }
  },
  "nodes" : {
    "count" : {
      "total" : 1,
      "coordinating_only" : 0,
      "data" : 1,
      "ingest" : 1,
      "master" : 1,
      "ml" : 1,
      "voting_only" : 0
    },
    "versions" : [
      "7.5.2"
    ],
    "os" : {
      "available_processors" : 12,
      "allocated_processors" : 12,
      "names" : [
        {
          "name" : "Linux",
          "count" : 1
        }
      ],
      "pretty_names" : [
        {
          "pretty_name" : "RHEL",
          "count" : 1
        }
      ],
      "mem" : {
        "total" : "62.7gb",
        "total_in_bytes" : 67386687488,
        "free" : "9.7gb",
        "free_in_bytes" : 10433200128,
        "used" : "53gb",
        "used_in_bytes" : 56953487360,
        "free_percent" : 15,
        "used_percent" : 85
      }
    },
    "process" : {
      "cpu" : {
        "percent" : 0
      },
      "open_file_descriptors" : {
        "min" : 15185,
        "max" : 15185,
        "avg" : 15185
      }
    },
    "jvm" : {
      "max_uptime" : "13.4m",
      "max_uptime_in_millis" : 809013,
      "versions" : [
        {
          "version" : "13.0.1",
          "vm_name" : "OpenJDK 64-Bit Server VM",
          "vm_version" : "13.0.1+9",
          "vm_vendor" : "AdoptOpenJDK",
          "bundled_jdk" : true,
          "using_bundled_jdk" : true,
          "count" : 1
        }
      ],
      "mem" : {
        "heap_used" : "1.6gb",
        "heap_used_in_bytes" : 1756215688,
        "heap_max" : "25.9gb",
        "heap_max_in_bytes" : 27830059008
      },
      "threads" : 97
    },
    "fs" : {
      "total" : "215.4gb",
      "total_in_bytes" : 231380877312,
      "free" : "47.8gb",
      "free_in_bytes" : 51360935936,
      "available" : "47.8gb",
      "available_in_bytes" : 51360935936
    },
    "plugins" : [],
    "network_types" : {
      "transport_types" : {
        "security4" : 1
      },
      "http_types" : {
        "security4" : 1
      }
    },
    "discovery_types" : {
      "zen" : 1
    },
    "packaging_types" : [
      {
        "flavor" : "default",
        "type" : "rpm",
        "count" : 1
      }
    ]
  }
}

```

* * *

**Netstat Status :** 😀

[root@XXX ~]# netstat -a -n | grep tcp | grep 5601 tcp 0 0 127.0.0.1:5601 0.0.0.0:\* LISTEN  
[root@XXX ~]# netstat -ntlp  
Active Internet connections (only servers)  
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name  
tcp 0 0 0.0.0.0:55932 0.0.0.0:\* LISTEN 2400/cvd  
tcp 0 0 127.0.0.1:5601 0.0.0.0:\* LISTEN 1204/node  
tcp 0 0 0.0.0.0:49157 0.0.0.0:\* LISTEN 2401/ClMgrS  
tcp 0 0 0.0.0.0:1515 0.0.0.0:\* LISTEN 2192/ossec-authd  
tcp 0 0 127.0.0.1:51536 0.0.0.0:\* LISTEN 2400/cvd  
tcp 0 0 0.0.0.0:8400 0.0.0.0:\* LISTEN 2400/cvd  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN 1619/sshd  
tcp 0 0 127.0.0.1:25 0.0.0.0:\* LISTEN 1973/master  
tcp6 0 0 :::14942 :::\* LISTEN 2330/splxhttpd  
tcp6 0 0 :::14943 :::\* LISTEN 2330/splxhttpd  
tcp6 0 0 1.1.1.1:9200 :::\* LISTEN 436/java  
tcp6 0 0 :::80 :::\* LISTEN 1620/httpd  
tcp6 0 0 1.1.1.1:9300 :::\* LISTEN 436/java  
tcp6 0 0 :::22 :::\* LISTEN 1619/sshd  
tcp6 0 0 :::55000 :::\* LISTEN 1629/node  
tcp6 0 0 ::1:25 :::\* LISTEN

* * *

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2021, 1:28pm UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/9 "2021-08-20T13:28:36Z")

</div>

There is no 'management interface" for Elasticsearch running on port 5601.

I Believe what you referring to is Kibana which is an entire separate app that you need to install and configure.

Kibana runs on Port 5601 and then connects to Elasticsearch. Kibana Is the management and data exploration interface.

See here

> **[Kibana Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/kibana/current/index.html)**

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 23, 2021, 1:31am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/10 "2021-08-23T01:31:32Z")

</div>

> [@Ahmed2021](#):
>
> ```auto
> "versions" : [
> "7.5.2"
> ],
> 
> ```

I just wanted to drop in and mention 7.5 is [EOL](https://www.elastic.co/support/eol), please upgrade 🙂

---

<div class="post-metadata">

**Author:** ![Ahmed2021](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@Ahmed2021](https://discuss.elastic.co/u/Ahmed2021)\
**Post date:** [August 23, 2021, 2:50am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/11 "2021-08-23T02:50:38Z")

</div>

Hi All

Filebeat issue resolved by increasing the **JVM heapsize**  
Kibana issue resolved by disabling the **Firewall-cmd module**

Thank you for cool community support  
Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2021, 2:51am UTC](https://discuss.elastic.co/t/fiebeat-test-output-error-java-heap-size/280483/12 "2021-09-20T02:51:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
