# Logstash querying elasticsearch timeout error

**URL:** <https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085>\
**Category:** Logstash\
**Created:** [July 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085 "2023-07-24T11:23:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![willsy](https://avatars.discourse-cdn.com/v4/letter/w/f17d59/32.png) [@willsy](https://discuss.elastic.co/u/willsy)\
**Post date:** [July 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/1 "2023-07-24T11:23:33Z")

</div>

Hello,

I have the following error; just seeing if anyone knows where i am setting this? i originally put the timeout setting in the testpipeline.conf for logstash. Any help is greatly appreciated

```auto
[2023-07-24T11:59:41,350][WARN][logstash.inputs.elasticsearch][main][3b44aa36a60d114757681112ebc1cdb657d6c631c725cd9f44a1ad88081ecd1a] Attempt to run query but failed. Sleeping for 0.02 {:fail_count=>1, :exception=>"Read timed out"}
[2023-07-24T11:59:41,371][ERROR][logstash.inputs.elasticsearch][main][3b44aa36a60d114757681112ebc1cdb657d6c631c725cd9f44a1ad88081ecd1a] Tried run query unsuccessfully {:message=>"Read timed out", :cause=>#<Java::JavaNet::SocketTimeoutException: Read timed out>}

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 25, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/2 "2023-07-25T09:33:49Z")

</div>

Hi @willsy,

> [@willsy](#):
>
> `Tried run query unsuccessfully {:message=>"Read timed out", :cause=>#<Java::JavaNet::SocketTimeoutException: Read timed out>}`

It looks like Logstash is unable to read from the configured source. Can you share your config and where you are reading from?

---

<div class="post-metadata">

**Author:** ![willsy](https://avatars.discourse-cdn.com/v4/letter/w/f17d59/32.png) [@willsy](https://discuss.elastic.co/u/willsy)\
**Post date:** [July 27, 2023, 2:06pm UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/3 "2023-07-27T14:06:00Z")

</div>

Hey @carly.richmond certainly will do. here it is. i am literally just trying to get anything at the moment

```auto
input {
 elasticsearch {
 hosts => "localhost:9200"
 ssl_enabled => true
 ssl_verification_mode => none
 api_key => "xxxxxxxxxxxxxxxxxxx"
 index => "*logs*"
 query => '{ "query": { "query_string": { "query": "*" } } }'
 size => 5
 scroll => "5m"
 docinfo => true
 docinfo_target => "[@metadata][doc]"
}
}

output {
  tcp {
host => "A.B.C.D"
port => ABCD
  }
}

```

---

<div class="post-metadata">

**Author:** ![widhalmt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/widhalmt/32/8237_2.png) [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Post date:** [July 27, 2023, 5:17pm UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/4 "2023-07-27T17:17:45Z")

</div>

Can you try using `curl` to query this Elasticsearch instance from the Logstash host? Maybe there's a simple network connection problem.

---

<div class="post-metadata">

**Author:** ![willsy](https://avatars.discourse-cdn.com/v4/letter/w/f17d59/32.png) [@willsy](https://discuss.elastic.co/u/willsy)\
**Post date:** [July 31, 2023, 7:09am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/5 "2023-07-31T07:09:33Z")

</div>

Morning,

Yea we could, curling was fine. Everything that i was testing was working as expected. I had to create a netcat listener on my tower and send the logs that way to determine the formatting of the logs.

My issue was actually the json codex, for some reason it didnt like the default so i had to change it to json\_lines which seemed to sort it out.

I can only assume, (assumptions make an ass out of you and me) that the buffer on my external side couldnt handle the logs as it was coming in in batches and not smaller individual lines. When it came in in individual lines it seemed to work.

so my fix was to add codex =\> json\_lines

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2023, 7:10am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085/6 "2023-08-28T07:10:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
