# Too Many Request 429

**URL:** <https://discuss.elastic.co/t/too-many-request-429/69771>\
**Category:** Elasticsearch\
**Created:** [December 22, 2016, 10:39am UTC](https://discuss.elastic.co/t/too-many-request-429/69771 "2016-12-22T10:39:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![LOSApevo](https://avatars.discourse-cdn.com/v4/letter/l/ee7513/32.png) [@LOSApevo](https://discuss.elastic.co/u/LOSApevo)\
**Post date:** [December 22, 2016, 10:39am UTC](https://discuss.elastic.co/t/too-many-request-429/69771/1 "2016-12-22T10:39:27Z")

</div>

Hello,  
I have this cluster configuration:  
Server 1: ES node  
Server 2: ES node + Logstash

All the instances have pretty much the default settings of the version 2.4  
I am retrieving data from social media and then push it to logstash on server 2 via socket. I use server 1 just for query requests. Data from social media are retrieved with a js node application that can push up to 1000 documents/sec into logstash.  
In the peak times I get this error in the logstash log:  
`[logstash.outputs.elasticsearch] retrying failed action with response code: 429 ({"type"=>"es_rejected_execution_exception", "reason"=>"rejected execution of org.elasticsearch.transport.TransportService$4@7e188f1b on EsThreadPoolExecutor[bulk, queue capacity = 50, org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor@86c6c81[Running, pool size = 4, active threads = 4, queued tasks = 52, completed tasks = 6336583]]"})`

What do you suggest? I have many doubts:  
How many ES nodes should I have?  
It is right to have just one logstash instance? I mean, should I split my data and push it, I don't know, half in a logstash instance and half into another one on a 3rd server? Or should I push all the data into a single logstash instance and then logstash push into several ES nodes?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 27, 2016, 6:59am UTC](https://discuss.elastic.co/t/too-many-request-429/69771/2 "2016-12-27T06:59:23Z")

</div>

> [@LOSApevo](#):
>
> Data from social media are retrieved with a js node application that can push up to 1000 documents/sec into logstash.

Are you using bulk requests?

---

<div class="post-metadata">

**Author:** ![LOSApevo](https://avatars.discourse-cdn.com/v4/letter/l/ee7513/32.png) [@LOSApevo](https://discuss.elastic.co/u/LOSApevo)\
**Post date:** [December 28, 2016, 11:44am UTC](https://discuss.elastic.co/t/too-many-request-429/69771/3 "2016-12-28T11:44:02Z")

</div>

From app to losgstah: a document at a time via socket.  
From logstash to elasticsearch: I use the elasticsearch  
`elasticsearch { hosts => ["ip:port"] index => '%{[data][index]}' document_id => '%{[data][post][id]}' document_type => '%{[data][type]}' }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2017, 11:44am UTC](https://discuss.elastic.co/t/too-many-request-429/69771/4 "2017-01-25T11:44:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
