# Receiving logstash error after installing watcher: SERVICE\_UNAVAILABLE/1/state not recovered / initialized SERVICE\_UNAVAILABLE/2/no master

**URL:** https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721
**Category:** Logstash
**Created:** [October 21, 2015, 7:53pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721 "2015-10-21T19:53:37Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 21, 2015, 7:53pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/1 "2015-10-21T19:53:37Z")

</div>

Hi,

I installed Watcher on my ES cluster and started receiving this error from my logstash servers:

:timestamp=\>"2015-10-21T10:56:48.613000-0700", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>37, :exception=\>"Java::OrgElasticsearchClusterBlock::ClusterBlockException", :backtrace=\>["org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(org/elasticsearch/cluster/block/ClusterBlocks.java:151)", "org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(org/elasticsearch/cluster/block/ClusterBlocks.java:141)", "org.elasticsearch.action.bulk.TransportBulkAction.executeBulk(org/elasticsearch/action/bulk/TransportBulkAction.java:215)", "org.elasticsearch.action.bulk.TransportBulkAction.access$000(org/elasticsearch/action/bulk/TransportBulkAction.java:67)", "org.elasticsearch.action.bulk.TransportBulkAction$1.onFailure(org/elasticsearch/action/bulk/TransportBulkAction.java:153)", "org.elasticsearch.action.support.TransportAction$ThreadedActionListener$2.run(org/elasticsearch/action/support/TransportAction.java:137)", "java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1142)", "java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:617)", "java.lang.Thread.run(java/lang/Thread.java:745)"], :level=\>:warn}  
{:timestamp=\>"2015-10-21T10:57:49.637000-0700", :message=\>"Got error to send bulk of actions: blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];", :level=\>:error}

There were not any corresponding errors in the ES logs.

I changed the Logstash ES output protocol to 'http' to fix the problem.

Why would I receive this error using the 'node' protocol?

Thank you.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [October 21, 2015, 8:12pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/2 "2015-10-21T20:12:31Z")

</div>

The ES client wasn't able to find a master node, most likely because it wasn't able to find the rest of the cluster. The cause of that situation can't be diagnosed without more information.

---

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 21, 2015, 9:46pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/3 "2015-10-21T21:46:05Z")

</div>

Each of the ES nodes, including the master, did show that it had joined.

What other information should I provide?

Thanks,  
Darin

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [October 21, 2015, 10:37pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/4 "2015-10-21T22:37:47Z")

</div>

Dies `_cat/nodes` list the client?

---

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 22, 2015, 7:52pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/5 "2015-10-22T19:52:16Z")

</div>

Yes, it does show up as a node in the cluster.

---

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 22, 2015, 7:56pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/6 "2015-10-22T19:56:06Z")

</div>

Before starting logstash:

[dfisher@ops-2 ~]$ curl -s -XGET '[http://mon-esm-1:9200/\_cat/nodes](http://mon-esm-1:9200/_cat/nodes)'  
[mon-esd-3.dc1.fm-hosted.com](http://mon-esd-3.dc1.fm-hosted.com) 10.1.108.111 35 29 0.15 d - mon-esd-3  
[mon-esd-2.dc1.fm-hosted.com](http://mon-esd-2.dc1.fm-hosted.com) 10.1.108.103 35 29 0.11 d - mon-esd-2  
[mon-esm-1.dc1.fm-hosted.com](http://mon-esm-1.dc1.fm-hosted.com) 10.1.108.101 18 9 0.02 d \* mon-esm-1  
[mon-esd-1.dc1.fm-hosted.com](http://mon-esd-1.dc1.fm-hosted.com) 10.1.108.102 24 8 0.10 d - mon-esd-1

After:  
[dfisher@ops-2 ~]$ curl -s -XGET '[http://mon-esm-1:9200/\_cat/nodes](http://mon-esm-1:9200/_cat/nodes)'  
[mon-esd-3.dc1.fm-hosted.com](http://mon-esd-3.dc1.fm-hosted.com) 10.1.108.111 35 29 0.06 d - mon-esd-3  
[mon-esd-2.dc1.fm-hosted.com](http://mon-esd-2.dc1.fm-hosted.com) 10.1.108.103 35 29 0.10 d - mon-esd-2  
[mon-esm-1.dc1.fm-hosted.com](http://mon-esm-1.dc1.fm-hosted.com) 10.1.108.101 18 9 0.01 d \* mon-esm-1  
[mon-esd-1.dc1.fm-hosted.com](http://mon-esd-1.dc1.fm-hosted.com) 10.1.108.102 24 8 0.51 d - mon-esd-1  
[mon-esp-1.dc1.fm-hosted.com](http://mon-esp-1.dc1.fm-hosted.com) 10.1.108.104 27 c - logstash-mon-esp-1.dc1.fm-hosted.com-2515-11638

Then just over 2 minutes after starting logstash the log shows the following:  
{:timestamp=\>"2015-10-22T12:48:12.712000-0700", :message=\>"Got error to send bulk of actions: blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];", :level=\>:error}  
{:timestamp=\>"2015-10-22T12:48:12.715000-0700", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>2027, :exception=\>"Java::OrgElasticsearchClusterBlock::ClusterBlockException", :backtrace=\>["org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(org/elasticsearch/cluster/block/ClusterBlocks.java:151)", "org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(org/elasticsearch/cluster/block/ClusterBlocks.java:141)", "org.elasticsearch.action.bulk.TransportBulkAction.executeBulk(org/elasticsearch/action/bulk/TransportBulkAction.java:215)", "org.elasticsearch.action.bulk.TransportBulkAction.access$000(org/elasticsearch/action/bulk/TransportBulkAction.java:67)", "org.elasticsearch.action.bulk.TransportBulkAction$1.onFailure(org/elasticsearch/action/bulk/TransportBulkAction.java:153)", "org.elasticsearch.action.support.TransportAction$ThreadedActionListener$2.run(org/elasticsearch/action/support/TransportAction.java:137)", "java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1142)", "java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:617)", "java.lang.Thread.run(java/lang/Thread.java:745)"], :level=\>:warn}  
{:timestamp=\>"2015-10-22T12:49:13.781000-0700", :message=\>"Got error to send bulk of actions: blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];", :level=\>:error}  
{:timestamp=\>"2015-10-22T12:49:13.781000-0700", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>2027, :exception=\>"Java::OrgElasticsearchClusterBlock::ClusterBlockException", :backtrace=\>["org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(org/elasticsearch/cluster/block/ClusterBlocks.java:151)", "org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(org/elasticsearch/cluster/block/ClusterBlocks.java:141)", "org.elasticsearch.action.bulk.TransportBulkAction.executeBulk(org/elasticsearch/action/bulk/TransportBulkAction.java:215)", "org.elasticsearch.action.bulk.TransportBulkAction.access$000(org/elasticsearch/action/bulk/TransportBulkAction.java:67)", "org.elasticsearch.action.bulk.TransportBulkAction$1.onFailure(org/elasticsearch/action/bulk/TransportBulkAction.java:153)", "org.elasticsearch.action.support.TransportAction$ThreadedActionListener$2.run(org/elasticsearch/action/support/TransportAction.java:137)", "java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1142)", "java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:617)", "java.lang.Thread.run(java/lang/Thread.java:745)"], :level=\>:warn}  
{:timestamp=\>"2015-10-22T12:50:14.858000-0700", :message=\>"Got error to send bulk of actions: blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];", :level=\>:error}

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [October 22, 2015, 8:33pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/7 "2015-10-22T20:33:04Z")

</div>

Try switching to the http protocol in the LS output.

---

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 22, 2015, 8:52pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/8 "2015-10-22T20:52:22Z")

</div>

Yes, the HTTP output does work and that is what I have had to do at this point.  
I would prefer the node protocol and am still "curious" as to why this is not working anymore.

The only change I made was to install watcher.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [October 22, 2015, 11:11pm UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/9 "2015-10-22T23:11:51Z")

</div>

Ahh, then you need the license plugin jar on your LS node.

This sort of thing is why LS 2.0 will default to HTTP, it's easier and as fast as node/transport.

---

<div class="post-metadata">

### Author: ![darinfisher](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darinfisher](https://discuss.elastic.co/u/darinfisher)
#### Post date: [October 23, 2015, 2:26am UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/10 "2015-10-23T02:26:36Z")

</div>

That's good to know.

Thank you so much for your help!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721/11 "2017-07-06T05:25:42Z")

</div>


