The logstash keep getting 'UNEXPECTED POOL ERROR', even the Elastic Search is in GREEN mode

(Mike) #1
  • Version: Logstash 5.5, AWS Elasticsearch 5.5
  • Operating System: Linux CentOS 7(Logstash)
  • Sample Error:

[2018-05-01T12:05:52,235][WARN ][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [][Manticore::ClientProtocolException] failed to respond {:url=>, :error_message=>"Elasticsearch Unreachable: [][Manticore::ClientProtocolException] failed to respond", :error_class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}

[2018-05-01T12:05:52,235][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error_message=>"Elasticsearch Unreachable: [][Manticore::ClientProtocolException] failed to respond", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will_retry_in_seconds=>2}

[2018-05-01T12:05:54,088][WARN ][logstash.outputs.elasticsearch] UNEXPECTED POOL ERROR {:e=>#<LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError: No Available connections>}

[2018-05-01T12:05:55,920][INFO ][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>, :path=>"/"}

[2018-05-01T12:05:55,936][WARN ][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>""}

  • Thread_Pool Settings:
    bulk:"max" : 4, "min":4, "queue_size": 200

(Ry Biesemeyer) #2

It looks like the machine on which your Logstash is running is losing its route to your Elasticsearch host(s).

(Mike) #3

Thanks for your reply. So you think that may be caused by network glitch?

(Ry Biesemeyer) #4

Whether it is a network glitch, a change in your virtual network configuration, or the hosts you are pointing at being replaced by new nodes with new IPs, there are many possibilities.

(Mike) #5

Is there a way that I can narrow down the reasons? What could be best solution to this kind of issue.

(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.