# Metricbeat - Bulk send failure - 429 Too Many Requests

**URL:** <https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 18, 2020, 4:57pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839 "2020-02-18T16:57:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Djaswan](https://avatars.discourse-cdn.com/v4/letter/d/71c47a/32.png) [@Djaswan](https://discuss.elastic.co/u/Djaswan)\
**Post date:** [February 18, 2020, 4:57pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839/1 "2020-02-18T16:57:40Z")

</div>

Hi,

We are running a metricbeat daemon set within two GKE environments, a test and production environment. Both metricbeats are sending data to the same elasticsearch monitoring cluster. De metricbeat from the test environment is configured to output data to a custom index, see config below.

Config test metricbeat:

> setup.template.name: "test-metricbeat"  
> setup.template.pattern: "test-metricbeat-\*"
> 
> setup.template.settings:  
> index.number\_of\_shards: 1  
> index.codec: best\_compression
> 
> setup.ilm.enabled: auto  
> setup.ilm.rollover\_alias: "test-metricbeat"  
> setup.ilm.pattern: "{now/d}-000001"
> 
> setup.kibana:  
> host: '${KIBANA\_HOST}'
> 
> output.elasticsearch:  
> hosts: ['${ELASTICSEARCH\_HOST}']  
> username: ${ELASTICSEARCH\_USERNAME}  
> password: ${ELASTICSEARCH\_PASSWORD}  
> index: "test-metricbeat-%{[agent.version]}-%{+yyyy.MM.dd}"

If we only deploy metricbeat to the production environment everything works correct, but deploying the second metricbeat to the test enviroment gives the following errors:

> "2020-02-17T16:39:37.575Z ERROR pipeline/output.go:121 Failed to publish events: temporary bulk send failure

> 2020-02-18 15:08:46.981 CET  
> 2020-02-18T14:08:46.981Z ERROR elasticsearch/client.go:344 Failed to perform any bulk index operations: 429 Too Many Requests: {"error":{"root\_cause":[{"type":"circuit\_breaking\_exception","reason":"[parent] Data too large, data for [\<http\_request\>] would be [1015096192/968mb], which is larger than the limit of [1003493785/957mb], real usage: [1014940576/967.9mb], new bytes reserved: [155616/151.9kb], usages [request=0/0b, fielddata=58922011/56.1mb, in\_flight\_requests=2334824/2.2mb, accounting=29581323/28.2mb]","bytes\_wanted":1015096192,"bytes\_limit":1003493785,"durability":"PERMANENT"}],"type":"circuit\_breaking\_exception","reason":"[parent] Data too large, data for [\<http\_request\>] would be [1015096192/968mb], which is larger than the limit of [1003493785/957mb], real usage: [1014940576/967.9mb], new bytes reserved: [155616/151.9kb], usages [request=0/0b, fielddata=58922011/56.1mb, in\_flight\_requests=2334824/2.2mb, accounting=29581323/28.2mb]","bytes\_wanted":1015096192,"bytes\_limit":1003493785,"durability":"PERMANENT"},"status":429}

Elasticsearch monitorings cluster runs on a elastic cloud solution, two nodes (hot/warm). Do i need to adjust some limits to solve the issues?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 18, 2020, 5:10pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839/2 "2020-02-18T17:10:22Z")

</div>

It looks like you need to increase the size of your hot tier.

---

<div class="post-metadata">

**Author:** ![Djaswan](https://avatars.discourse-cdn.com/v4/letter/d/71c47a/32.png) [@Djaswan](https://discuss.elastic.co/u/Djaswan)\
**Post date:** [February 19, 2020, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839/3 "2020-02-19T13:03:04Z")

</div>

I 've changed the hot tier setting to a two node solution.  
I still get the same errors and the CPU of one (hot) instance spikes to 100%.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2020, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-bulk-send-failure-429-too-many-requests/219839/4 "2020-03-18T13:03:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
