# High Value of total\_opened http connection in node stats when ES Cluster is idle

**URL:** https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968
**Category:** Elasticsearch
**Created:** [August 24, 2015, 5:37pm UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968 "2015-08-24T17:37:27Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Deb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deb/32/46162_2.png) [@Deb](https://discuss.elastic.co/u/Deb)
#### Post date: [August 24, 2015, 5:37pm UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968/1 "2015-08-24T17:37:27Z")

</div>

I have a simple ELK deployment in which logstash is pushing log events to elasticsearch cluster. The elasticsearch cluster has 4 nodes out of which there are 3 master + data nodes and one client node. The logstash configuration for Elasticsearch output is as follows:-

```
output {
  elasticsearch {    
  index => "test-2015-08-18"
  }
}

```

I am seeing a high number of total\_opened http connection about 50-60 K (per node) but this number is constant. This stays at this even when there are hardly any indexing or query being done on the elasticsearch. Is this expected?

The [node-monitoring guide](https://www.elastic.co/guide/en/elasticsearch/guide/current/_monitoring_individual_nodes.html#_fs_and_network_sections) states:-

> If you see a very large total\_opened number that is constantly increasing, that is a sure sign that one of your HTTP clients is not using keep-alive connections.

Since in my case the number 50-60 K is constant so is it ok and nothing to worry about?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [August 24, 2015, 11:08pm UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968/2 "2015-08-24T23:08:25Z")

</div>

It's constant so I wouldn't worry _too_ much, but it'd be interesting to see why it's that high.

---

<div class="post-metadata">

### Author: ![Deb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deb/32/46162_2.png) [@Deb](https://discuss.elastic.co/u/Deb)
#### Post date: [August 25, 2015, 5:22am UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968/3 "2015-08-25T05:22:34Z")

</div>

Thanks Mark.

Is there a way I can see what all http connections are opened by elasticsearch. Doing `netstat | grep http` is returning empty results?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [August 25, 2015, 7:47am UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968/4 "2015-08-25T07:47:40Z")

</div>

There's no way to get that from ES unfortunately, we just don't provide visibility into that ☹

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:54pm UTC](https://discuss.elastic.co/t/high-value-of-total-opened-http-connection-in-node-stats-when-es-cluster-is-idle/27968/5 "2017-07-05T23:54:03Z")

</div>


