# How to rectify this error?

**URL:** <https://discuss.elastic.co/t/how-to-rectify-this-error/177588>\
**Category:** Logstash\
**Created:** [April 19, 2019, 9:15am UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588 "2019-04-19T09:15:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [April 19, 2019, 9:15am UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/1 "2019-04-19T09:15:14Z")

</div>

[INFO] 2019-04-19 14:44:01.440 [[apachelogs]\>worker10] elasticsearch - retrying failed action with response code: 429 ({"type"=\>"es\_rejected\_execution\_exception", "reason"=\>"rejected execution of processing of [17928][indices:data/write/bulk[s][p]]: request: BulkShardRequest [[logstash\_apchelogs][3]] containing [27] requests, target allocation id: ZPiFvyGQQQKeZko\_10H5gQ, primary term: 1 on EsThreadPoolExecutor[name = uv8cruY/write, queue capacity = 200, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@39ff1121[Running, pool size = 12, active threads = 12, queued tasks = 200, completed tasks = 16039]]"})

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 19, 2019, 9:19am UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/2 "2019-04-19T09:19:47Z")

</div>

> [@Vikash\_Singh1](#):
>
> retrying failed action with response code: 429

This indicates that you are seeing [bulk rejections](https://www.elastic.co/blog/why-am-i-seeing-bulk-rejections-in-my-elasticsearch-cluster), likely because your cluster is overloaded. How many indices and shards do you have in the cluster? How many of these are you actively indexing into? What is the size of the cluster? Which version are you running?

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [April 19, 2019, 11:00am UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/3 "2019-04-19T11:00:48Z")

</div>

i am using elk 6.6.2...I am injecting different logs from different locations although indices are created..can you tell me how to check the number of indices and shards in cluster???

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 19, 2019, 12:34pm UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/4 "2019-04-19T12:34:08Z")

</div>

You can use the [cluster health API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html) to get a total count. How are you naming your indices? What type of hardware is your cluster running on?

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [April 19, 2019, 4:35pm UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/5 "2019-04-19T16:35:06Z")

</div>

I am using grok to name the indices

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 19, 2019, 5:26pm UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/6 "2019-04-19T17:26:17Z")

</div>

How many indices are you creating? I suspect this may be due to you indexing into a lot of small indices and shards. Can you please provide the cluster health output?

If you are dynamically creating index names there is a good chance you should read [this blog post](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2019, 5:26pm UTC](https://discuss.elastic.co/t/how-to-rectify-this-error/177588/7 "2019-05-17T17:26:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
