# How to stop datafeed

**URL:** <https://discuss.elastic.co/t/how-to-stop-datafeed/93167>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [July 14, 2017, 10:40am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167 "2017-07-14T10:40:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 14, 2017, 10:40am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/1 "2017-07-14T10:40:25Z")

</div>

Hi, I having issue about datafeed.  
I `can't stop datafeed` and `delete` it.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8c49ddbde84f51465940175fa82e7e4b8d2c29f.png)

This error in **kibana command**.

> error [10:34:54.287] [null\_pointer\_exception] null :: {"path":"/\_xpack/ml/datafeeds/datafeed-alert-mem/\_stop","query":{},"statusCode":500,"response":"{"error":{"root\_cause":[{"type":"null\_pointer\_exception","reason":null}],"type":"null\_pointer\_exception","reason":null},"status":500}"}  
> at respond (C:\Users\dol\_n\Downloads\kibana-5.4.1-windows-x86\node\_modules\elasticsearch\src\lib\transport.js:295:15)  
> at checkRespForFailure (C:\Users\dol\_n\Downloads\kibana-5.4.1-windows-x86\node\_modules\elasticsearch\src\lib\transport.js:254:7)  
> at HttpConnector. (C:\Users\dol\_n\Downloads\kibana-5.4.1-windows-x86\node\_modules\elasticsearch\src\lib\connectors\http.js:157:7)  
> at IncomingMessage.bound (C:\Users\dol\_n\Downloads\kibana-5.4.1-windows-x86\node\_modules\elasticsearch\node\_modules\lodash\dist\lodash.js:729:21)  
> at emitNone (events.js:91:20)  
> at IncomingMessage.emit (events.js:185:7)  
> at endReadableNT (\_stream\_readable.js:974:12)  
> at \_combinedTickCallback (internal/process/next\_tick.js:80:11)  
> at process.\_tickDomainCallback (internal/process/next\_tick.js:128:9)

i hope anyone can help me.  
thanks.

---

<div class="post-metadata">

**Author:** ![dkyle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkyle/32/59114_2.png) [@dkyle](https://discuss.elastic.co/u/dkyle)\
**Post date:** [July 14, 2017, 10:45am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/2 "2017-07-14T10:45:52Z")

</div>

Hi,

Is it possible for you to share your elasticsearch.log file and the version of x-pack you are using? That will help us understand the issue.

Thanks

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 14, 2017, 11:03am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/3 "2017-07-14T11:03:41Z")

</div>

thank for the quick reply @dkyle.  
I used elasticsearch, kibana and x-pack version 5.4.1 .

And example elasticsearch.log.

> [2017-07-14T17:34:53,375][WARN][r.suppressed] path: /\_xpack/ml/datafeeds/datafeed-alert-mem/\_stop, params: {datafeed\_id=datafeed-alert-mem}  
> java.lang.NullPointerException: null  
> at org.elasticsearch.cluster.node.DiscoveryNodes.isAllNodes(DiscoveryNodes.java:232) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.cluster.node.DiscoveryNodes.resolveNodes(DiscoveryNodes.java:290) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.action.support.tasks.TransportTasksAction.resolveNodes(TransportTasksAction.java:167) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.action.support.tasks.TransportTasksAction$AsyncAction.(TransportTasksAction.java:246) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.action.support.tasks.TransportTasksAction$AsyncAction.(TransportTasksAction.java:231) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.action.support.tasks.TransportTasksAction.doExecute(TransportTasksAction.java:104) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.xpack.ml.action.StopDatafeedAction$TransportAction.doExecute(StopDatafeedAction.java:351) ~[?:?]  
> at org.elasticsearch.xpack.ml.action.StopDatafeedAction$TransportAction.doExecute(StopDatafeedAction.java:265) ~[?:?]  
> at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:170) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$apply$1(SecurityActionFilter.java:128) ~[?:?]  
> at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) ~[elasticsearch-5.4.1.jar:5.4.1]  
> at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$authorizeRequest$4(SecurityActionFilter.java:203) ~[?:?]  
> at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.maybeRun(AuthorizationUtils.java:127) ~[?:?]  
> at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.setRunAsRoles(AuthorizationUtils.java:121) ~[?:?]  
> at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.authorize(AuthorizationUtils.java:109) ~[?:?]  
> at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.authorizeRequest(SecurityActionFilter.java:205) ~[?:?]  
> at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$applyInternal$3(SecurityActionFilter.java:181) ~[?:?]

thanks.

---

<div class="post-metadata">

**Author:** ![dkyle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkyle/32/59114_2.png) [@dkyle](https://discuss.elastic.co/u/dkyle)\
**Post date:** [July 14, 2017, 11:28am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/4 "2017-07-14T11:28:04Z")

</div>

Thanks for the log file.

Machine Learning in X-Pack GA'd in the 5.5 release. Version 5.4.1 is a beta release. I really recommend upgrading to 5.5 where you will benefit from a number of improvements.

Are you running on a multi-node cluster? From the snippet of the log file it appears the datafeed has already stopped - possibly because the node it was running on left the cluster.

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 17, 2017, 2:52am UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/5 "2017-07-17T02:52:20Z")

</div>

Sorry for late @dkyle.  
I don't want to tried latest version now, because elasticsearch has rapid development.

And now i can't stop datafeed state (alert-mem created by multi-job).

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c31c9590267438d10d0a5d07f1325ee10516dc47.png)

from you tell me about node on left cluster how to stop it ?

thanks

---

<div class="post-metadata">

**Author:** ![dkyle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkyle/32/59114_2.png) [@dkyle](https://discuss.elastic.co/u/dkyle)\
**Post date:** [July 17, 2017, 12:16pm UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/6 "2017-07-17T12:16:25Z")

</div>

Hi,

I think the issue is that the datafeed is reported as being in the started state but it is actually stopped. You can check this via the [Task API](https://www.elastic.co/guide/en/elasticsearch/reference/current/tasks.html). If the datafeed is running you will see a task named `datafeed-alert-mem`.

The root cause of the issue is fixed in 5.5 so again I would encourage you to upgrade. Version 5.5 also has a force delete option which would help in this situation.

If you can't upgrade you can continue to create new jobs and datafeeds, the existing `alert-mem` datafeed won't affect any new jobs. I'm sorry you are having these problems I recommend creating a new multi-metric job and exploring the ML features in a new job.

---

<div class="post-metadata">

**Author:** ![Thanadol\_Thadasade](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thanadol\_Thadasade](https://discuss.elastic.co/u/Thanadol_Thadasade)\
**Post date:** [July 17, 2017, 3:17pm UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/7 "2017-07-17T15:17:05Z")

</div>

OK, I understand and thanks you very much @dkyle .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2017, 3:17pm UTC](https://discuss.elastic.co/t/how-to-stop-datafeed/93167/8 "2017-08-14T15:17:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
