# My elasticsearch doesn't work

**URL:** <https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997>\
**Category:** Elasticsearch\
**Created:** [October 26, 2015, 4:05pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997 "2015-10-26T16:05:41Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 26, 2015, 4:05pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/1 "2015-10-26T16:05:41Z")

</div>

Hello, this morning I have seen that suddenly kibana didn't represent any message.  
I have seen that the problem is in elasticsearch but the cluster health is yellow (it seems to be OK), however everytime I want to send a message I'm not able to see it, I have to restart the service to start seeing the messages. What could I do?

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 26, 2015, 4:12pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/2 "2015-10-26T16:12:08Z")

</div>

Can you acces any kind of ES API? for example these:

$ curl -XGET '[http://localhost:9200/\_cluster/health?pretty=true](http://localhost:9200/_cluster/health?pretty=true)'

$ curl -XGET '[http://localhost:9200](http://localhost:9200)'

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 26, 2015, 4:14pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/3 "2015-10-26T16:14:10Z")

</div>

Yes, this is what I get:

{  
"cluster\_name" : "logstash",  
"status" : "yellow",  
"timed\_out" : false,  
"number\_of\_nodes" : 2,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 221,  
"active\_shards" : 221,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 221,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0  
}

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 26, 2015, 4:20pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/4 "2015-10-26T16:20:25Z")

</div>

Can you also give me the output of just $ curl -XGET '[http://localhost:9200](http://localhost:9200)'?

Did you restart it already? Or is it still in this odd state?

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 26, 2015, 4:21pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/5 "2015-10-26T16:21:29Z")

</div>

{  
"status" : 200,  
"name" : "Loggy",  
"cluster\_name" : "logstash",  
"version" : {  
"number" : "1.7.1",  
"build\_hash" : "b88f43fc40b0bcd7f173a1f9ee2e97816de80b19",  
"build\_timestamp" : "2015-07-29T09:54:16Z",  
"build\_snapshot" : false,  
"lucene\_version" : "4.10.4"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 26, 2015, 4:29pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/6 "2015-10-26T16:29:09Z")

</div>

Okay, this looks as good as it can get..

What exactly do you mean when you say "everytime I want to send a message I'm not able to see it"?

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 26, 2015, 4:32pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/7 "2015-10-26T16:32:11Z")

</div>

I sent UDP messages to logstash (port 30000) but I'm not able to see them in Kibana.  
I tried to delete some indexes I'm not using from EShead and the ack is false.  
What can be happening?

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 26, 2015, 4:41pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/8 "2015-10-26T16:41:59Z")

</div>

Oh, okay.

Can you set logging to debug and check the logs located at $ES-HOME/logs ?

PUT /\_cluster/settings  
{"transient":{"logger.\_root":"DEBUG"}}

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 26, 2015, 5:11pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/9 "2015-10-26T17:11:13Z")

</div>

I think that this is the problem:  
[2015-10-26 11:36:26,748][WARN][index.engine] [Loggy] [logstash-syslog-2015.10.26][0] failed engine [out of memory (source: [maybe\_merge])]  
java.lang.OutOfMemoryError: unable to create new native thread  
at java.lang.Thread.start0(Native Method)  
at java.lang.Thread.start(Thread.java:714)  
at org.apache.lucene.index.ConcurrentMergeScheduler.merge(ConcurrentMergeScheduler.java:391)  
at org.elasticsearch.index.merge.EnableMergeScheduler.merge(EnableMergeScheduler.java:50)  
at org.apache.lucene.index.IndexWriter.maybeMerge(IndexWriter.java:1985)  
at org.apache.lucene.index.IndexWriter.maybeMerge(IndexWriter.java:1979)  
at org.elasticsearch.index.engine.InternalEngine.maybeMerge(InternalEngine.java:778)  
at org.elasticsearch.index.shard.IndexShard$EngineMerger$1.run(IndexShard.java:1241)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:745)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 27, 2015, 12:58am UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/10 "2015-10-27T00:58:27Z")

</div>

> [@billy6](#):
>
> java.lang.OutOfMemoryError: unable to create new native thread

Yeah, you need to check your heap size and, ideally, increase it.

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 27, 2015, 1:28pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/11 "2015-10-27T13:28:05Z")

</div>

I had 3 GB, but with the previous version (elasticsearch 1.1.1 and Kibana4) we had only 1,5 GB for ES\_MAX\_MEM and it worked fine. What could be the reason?

thank you

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 27, 2015, 1:51pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/12 "2015-10-27T13:51:51Z")

</div>

I have increased ES\_HEAP\_SIZE=4g  
but I have tried sending 100 messages and it get stuck...(same problem)  
How could this be possible?

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 27, 2015, 5:20pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/13 "2015-10-27T17:20:21Z")

</div>

How much memory does your host machine have?

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 27, 2015, 5:21pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/14 "2015-10-27T17:21:06Z")

</div>

8GB, for this reason I can't increase it more.

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 27, 2015, 5:23pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/15 "2015-10-27T17:23:09Z")

</div>

Can you tell me a little more about the data in your ES?

How many documents, how much total in GB, how many indices, what kind of messages you are trying to send

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 27, 2015, 5:29pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/16 "2015-10-27T17:29:42Z")

</div>

I have 44 indexes,  
here I have a copy from the elasticsearch head

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0bf76b6b54c6fcef0ab8765f97e9167415aa4b9a.PNG)

I made a migration from another machine and in order to have the same indexes I moved the directory /var/lib/elasticsearch/NAMEOFtHECLUSTER to another directory and there I have now the past indexes (from the other machine) and the new indexes...

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 27, 2015, 5:48pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/17 "2015-10-27T17:48:15Z")

</div>

This looks fine. Should not be a problem 😕

So you still get the outofMemory if you try to index new data?

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [October 27, 2015, 5:52pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/18 "2015-10-27T17:52:44Z")

</div>

yes, when I send a big amount of data.

---

<div class="post-metadata">

**Author:** ![lwintergerst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lwintergerst/32/18164_2.png) [@lwintergerst](https://discuss.elastic.co/u/lwintergerst)\
**Post date:** [October 27, 2015, 5:53pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/19 "2015-10-27T17:53:42Z")

</div>

I dont know what else to do. Im sorry. Maybe @warkolm can help you out

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 27, 2015, 9:41pm UTC](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997/20 "2015-10-27T21:41:18Z")

</div>

You should reduce your shard count, that's likely causing the heap pressure.

[Next page](https://discuss.elastic.co/t/my-elasticsearch-doesnt-work/32997.md?page=2)
