# Filebeat error Failed to publish events

**URL:** <https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 6, 2018, 11:49am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710 "2018-03-06T11:49:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![849938e6ef0f16f9da83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/849938e6ef0f16f9da83/32/28482_2.png) [@849938e6ef0f16f9da83](https://discuss.elastic.co/u/849938e6ef0f16f9da83)\
**Post date:** [March 6, 2018, 11:49am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/1 "2018-03-06T11:49:35Z")

</div>

Filebeat outputs such error  
**ERROR pipeline/output.go:92 Failed to publish events: temporary bulk send failure**

filebeat version 6.2.2 (amd64), libbeat 6.2.2

The error occurs on log files with long messages (tens lines). On other files filebeat works good.  
I've tried to play with option **bulk\_max\_size**. But even setting it to **bulk\_max\_size:1** and reading just one log file have not received the problem.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 11, 2018, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/2 "2018-03-11T19:42:43Z")

</div>

Can you share your filebeat config?

I would recommend you to have a look at the elasticsearch logs, perhaps there you see more details about the error.

---

<div class="post-metadata">

**Author:** ![849938e6ef0f16f9da83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/849938e6ef0f16f9da83/32/28482_2.png) [@849938e6ef0f16f9da83](https://discuss.elastic.co/u/849938e6ef0f16f9da83)\
**Post date:** [March 12, 2018, 6:42am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/3 "2018-03-12T06:42:33Z")

</div>

There is no sense to view elasticsearch logs - errors occur on Filebeat.  
As I mentioned above, only log files with long messages are the cause of such errors. And Filebeat cannot handle them correctly.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 12, 2018, 10:30am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/4 "2018-03-12T10:30:33Z")

</div>

Normally the bulk sense failure is caused by an error on the Elasticsearch side. Knowing which error elasticsearch returns could be helpful here.

---

<div class="post-metadata">

**Author:** ![849938e6ef0f16f9da83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/849938e6ef0f16f9da83/32/28482_2.png) [@849938e6ef0f16f9da83](https://discuss.elastic.co/u/849938e6ef0f16f9da83)\
**Post date:** [March 12, 2018, 2:26pm UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/5 "2018-03-12T14:26:10Z")

</div>

Alas. There are no errors on Elasticsearch side.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 13, 2018, 7:27am UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/6 "2018-03-13T07:27:54Z")

</div>

I would have definitively expected some errors on the Elasticsearch side as it means one or more items from the bulk request were reject by Elasticsearch.

Can you share your full filebeat config file and run filebeat with debug log level enabled. This should give us some more insights on what exactly happens when ES rejects part of the bulk request.

---

<div class="post-metadata">

**Author:** ![849938e6ef0f16f9da83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/849938e6ef0f16f9da83/32/28482_2.png) [@849938e6ef0f16f9da83](https://discuss.elastic.co/u/849938e6ef0f16f9da83)\
**Post date:** [March 28, 2018, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/7 "2018-03-28T14:59:10Z")

</div>

There was not problem in files with long log messages. I could handle such files with Filebeat. In my case such log files had big size - about 18MB. After I cleared these files, Filebeat could handle them correctly.  
So, dear developers, take attention at this bug.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2018, 3:00pm UTC](https://discuss.elastic.co/t/filebeat-error-failed-to-publish-events/122710/8 "2018-04-25T15:00:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
