# Unable to access data from elastic search

**URL:** <https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258>\
**Category:** Elasticsearch\
**Created:** [December 1, 2020, 6:14pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258 "2020-12-01T18:14:42Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 1, 2020, 6:14pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/1 "2020-12-01T18:14:43Z")

</div>

In elastic search, when checking index health link, we could see that each index is having huge amount of data as per the size. But when running api \<index\_name\>/\_search, it is retrieving only only one alias data. We are not sure why we are not able to access other aliases data. Could you please help us on this?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c89f8fa893fe8d42aa8ea8cafc1bb067be68b2a3.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c7089830aae12b00b5833bdc9232985d03e3120f.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 2, 2020, 12:34am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/2 "2020-12-02T00:34:01Z")

</div>

What is the output from `_cat/aliases?v`?

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 2, 2020, 3:05am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/3 "2020-12-02T03:05:56Z")

</div>

it is returning all the aliases.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5fed0cfe73c0f2d53389a30fef51d19075c6cddb.png)

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 2, 2020, 5:33am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/4 "2020-12-02T05:33:34Z")

</div>

Can someone provide me update on this?

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 2, 2020, 5:53am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/5 "2020-12-02T05:53:07Z")

</div>

> [@DENMODSupport](#):
>
> But when running api \<index\_name\>/\_search, it is retrieving only only one alias data

I think what you mean to say is - It is returning data of only one ~~alias~~ index viz `en_y_96` and not from remaining indices? Is that correct?

If you want data from `all` indices, then for your use case, you'll need to do `GET en_*/_search`.

Alternatively, you need to map `all indices to an alias` and not the other way round. Then you can do `GET your_alias_name/_search`.

From the alias screenshot you shared, it seems you've done the reverse whereby you've mapped a `number of aliases` to `one index`.

You can use the following snippet to map all indices to a single alias.

```
POST /_aliases
{
  "actions" : [
    { "add" : { 
      "indices" : [
        "en_*"], "alias" : "denmod_m" } }
    ]
}

```

and then get data from all indices using `GET denmod_m/_search`.

Hope this helps.

P.S: You should redact the URL of your ES Cluster.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 2, 2020, 6:22am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/6 "2020-12-02T06:22:31Z")

</div>

> [@DENMODSupport](#):
>
> Can someone provide me update on this?

Please note that there are no SLAs on these forums. If you'd like guaranteed response times, then please check out [Subscriptions | Elastic Stack Products & Support | Elastic](https://www.elastic.co/subscriptions)

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 2, 2020, 6:31am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/7 "2020-12-02T06:31:44Z")

</div>

> [@sandeepkanabar](#):
>
> I think what you mean to say is - It is returning data of only one ~~alias~~ index viz `en_y_96` and not from remaining indices? Is that correct?

When running the en\_y\_96/\_alias, it is returning many aliases as like below screenshot.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3bec60a19f3eb6462599f4560f38b2dfb0e50979.png)

But when we running en\_y\_96/\_search, it is returning data of alias "denmod\_y\_108455" only and some how other data are not accessible.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5c6767367b3537da47655a79c20fa875707c624.png)

Also we are using below code snippet for creating aliases.

```
Post  

```

\_aliases

{

"actions": [

```
{ 

  "add": { 

    "index": "en_y_31", 

    "alias": "denmod_y_4280", 

    "filter": { 

      "term": { 

        "simulationId": 4280 

      } 

    } 

  } 

} 

```

]

}  
@warkolm @sandeepkanabar Please let me know what should i do for accessing other data from the index en\_y\_96.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 2, 2020, 10:08am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/8 "2020-12-02T10:08:22Z")

</div>

> [@DENMODSupport](#):
>
> But when we running en\_y\_96/\_search, it is returning data of alias "denmod\_y\_108455" only and some how other data are not accessible.

That might be because ES only returns top 10 records. To get more records, you can use the [size](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/search-request-from-size.html) and optionally `from` parameter.

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 4, 2020, 10:06am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/9 "2020-12-04T10:06:39Z")

</div>

@sandeepkanabar the problem is that data is available in elk server based on the size we can confirm that. But while fetching data through dot net application, it is returning null from ELK. Do you have any idea on that? My ELk version is 5.3.1.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 4, 2020, 10:15am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/10 "2020-12-04T10:15:36Z")

</div>

Please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 4, 2020, 10:25am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/11 "2020-12-04T10:25:05Z")

</div>

```
ok.. could you please help me on above issue?
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 4, 2020, 11:09am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/12 "2020-12-04T11:09:52Z")

</div>

Could you explain what the problem is?

> [@DENMODSupport](#):
>
> But while fetching data through dot net application, it is returning null from ELK.

Hard to tell without seeing any information on that like code.  
That said, I'm not a dotnet dev so I don't know if I can help but may be someone would be able to.

> [@DENMODSupport](#):
>
> My ELk version is 5.3.1.

That's a way too old. It's not even the latest stable of the 5.x version. We don't support 5.x anymore.  
Consider updating to 7.10.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 4, 2020, 12:11pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/13 "2020-12-04T12:11:48Z")

</div>

@DENMODSupport - In addition to David's answer, if the .NET application returns null, there could be a number of reasons.

1. You need to check if the connection object is instantiated successfully or not.
2. And when you get null, what does the stack-trace show?
3. You can look up the appropriate documentation corresponding to your .NET client version.

I'm not a .NET guy but this should be your starting point and that question is better asked in a new post.

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 4, 2020, 1:17pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/14 "2020-12-04T13:17:59Z")

</div>

We are getting below error from elastic search logs.

```
[2020-12-04T13:25:20,571][WARN][o.e.a.a.c.n.i.TransportNodesInfoAction] [elk-denmod-web] not accumulating exceptions, excluding exception from response
org.elasticsearch.action.FailedNodeException: Failed node [t7JmFe-iSn63CALYD-0lxw]
	at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction.onFailure(TransportNodesAction.java:246) ~[elasticsearch-5.3.1.jar:5.3.1]
	at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction.access$200(TransportNodesAction.java:160) ~[elasticsearch-5.3.1.jar:5.3.1]
	at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction$1.handleException(TransportNodesAction.java:218) ~[elasticsearch-5.3.1.jar:5.3.1]
	at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1032) ~[elasticsearch-5.3.1.jar:5.3.1]
	at org.elasticsearch.transport.TransportService$Adapter.lambda$onNodeDisconnected$6(TransportService.java:859) ~[elasticsearch-5.3.1.jar:5.3.1]
	at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:569) [elasticsearch-5.3.1.jar:5.3.1]
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) [?:1.8.0_131]
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) [?:1.8.0_131]
	at java.lang.Thread.run(Thread.java:748) [?:1.8.0_131]
Caused by: org.elasticsearch.transport.NodeDisconnectedException: [elk-denmod-1][168.124.25.140:9300][cluster:monitor/nodes/info[n]] disconnected
[2020-12-04T13:25:20,571][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elk-denmod-web] failed to execute [indices:monitor/stats] on node [t7JmFe-iSn63CALYD-0lxw]
org.elasticsearch.transport.NodeDisconnectedException: [elk-denmod-1][168.124.25.140:9300][indices:monitor/stats[n]] disconnected
[2020-12-04T13:25:25,032][INFO][o.e.c.s.ClusterService] [elk-denmod-web] added {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2274]])
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 4, 2020, 1:33pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/15 "2020-12-04T13:33:27Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 4, 2020, 1:50pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/16 "2020-12-04T13:50:03Z")

</div>

i formatted the code.. Could you please help me on that error which am getting in elastic search

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 4, 2020, 5:03pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/17 "2020-12-04T17:03:00Z")

</div>

Is that related to the original question? What are you doing to generate such a log? Or what is happening in the cluster when this log appears?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [December 4, 2020, 5:55pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/18 "2020-12-04T17:55:46Z")

</div>

Hello @DENMODSupport ,

From the initial screenshot, it seems your indices are named (2 examples):

```auto
en_y_71
en_m_73
en_y_96

```

When you search against `en_y_96`, you are searching against a normal index.  
The document count 6830118 in the `_search` result (`hits.total`) matches the screenshot you've shared (`GET _cat/indices?v`).

In the screenshot you've shared with all the aliases of `en_y_96`, we see you are trying to use a filtered alias to _emulate_ some sort of isolation/security restriction based on `SimulationId`.

If you want to get the data of `denmod_y_108455`, you have to search against the alias, not the actual index, using `POST dnmod_y_108455/_search`.  
If you search against `en_y_96` it search against all documents.

Checking the stacktrace you've provided, it seems you might be hitting [https://github.com/elastic/elasticsearch/pull/25016](https://github.com/elastic/elasticsearch/pull/25016), but I am not 100% sure.

The node `elk-denmod-web` detects the node `elk-denmod-1` disconnects/fails.

**Can you check/share what are the logs on the other node around the time `2020-12-04T13:25:20,571`?**

Regarding the .NET issue and returning `null`, it might be because the node(s) is removed/disconnects from the cluster.  
Would it be possible to share:

- What is the version of the Elasticsearch client you're using
- The settings of the client and the parameters to connect to Elasticsearch (excluding sensitive data)
- Potentially, a snippet of the code of the request you're sending.

The official Elasticsearch client documentation is [at this page](https://www.elastic.co/guide/en/elasticsearch/client/net-api/5.x/index.html) and as [you can see in the compatibility matrix](https://github.com/elastic/elasticsearch-net#compatibility-matrix), they are no more officially supported as Elasticsearch 5.3.1 reached [end of life on October 2018](https://www.elastic.co/support/eol).

---

<div class="post-metadata">

**Author:** ![DENMODSupport](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denmodsupport/32/67186_2.png) [@DENMODSupport](https://discuss.elastic.co/u/DENMODSupport)\
**Post date:** [December 11, 2020, 7:51am UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/19 "2020-12-11T07:51:38Z")

</div>

> [@Luca\_Belluccini](#):
>
> Checking the stacktrace you've provided, it seems you might be hitting [\_nodes/stats should not fail due to concurrent AlreadyClosedException by pickypg · Pull Request #25016 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/25016), but I am not 100% sure.

> [@DENMODSupport](#):
>
> ```auto
> [2020-12-04T13:25:20,571][WARN][o.e.a.a.c.n.i.TransportNodesInfoAction] [elk-denmod-web] not accumulating exceptions, excluding exception from response
> org.elasticsearch.action.FailedNodeException: Failed node [t7JmFe-iSn63CALYD-0lxw]
> at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction.onFailure(TransportNodesAction.java:246) ~[elasticsearch-5.3.1.jar:5.3.1]
> at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction.access$200(TransportNodesAction.java:160) ~[elasticsearch-5.3.1.jar:5.3.1]
> at org.elasticsearch.action.support.nodes.TransportNodesAction$AsyncAction$1.handleException(TransportNodesAction.java:218) ~[elasticsearch-5.3.1.jar:5.3.1]
> at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1032) ~[elasticsearch-5.3.1.jar:5.3.1]
> at org.elasticsearch.transport.TransportService$Adapter.lambda$onNodeDisconnected$6(TransportService.java:859) ~[elasticsearch-5.3.1.jar:5.3.1]
> at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:569) [elasticsearch-5.3.1.jar:5.3.1]
> at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142) [?:1.8.0_131]
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617) [?:1.8.0_131]
> at java.lang.Thread.run(Thread.java:748) [?:1.8.0_131]
> Caused by: org.elasticsearch.transport.NodeDisconnectedException: [elk-denmod-1][168.124.25.140:9300][cluster:monitor/nodes/info[n]] disconnected
> [2020-12-04T13:25:20,571][DEBUG][o.e.a.a.i.s.TransportIndicesStatsAction] [elk-denmod-web] failed to execute [indices:monitor/stats] on node [t7JmFe-iSn63CALYD-0lxw]
> org.elasticsearch.transport.NodeDisconnectedException: [elk-denmod-1][168.124.25.140:9300][indices:monitor/stats[n]] disconnected
> [2020-12-04T13:25:25,032][INFO][o.e.c.s.ClusterService] [elk-denmod-web] added {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2274]])
> 
> ```

The reference you have provided is having "AlreadyClosedException" but we are getting "Node Disconnected exception". Please find the above stack trace for your reference.

> [@Luca\_Belluccini](#):
>
> Can you check/share what are the logs on the other node around the time `2020-12-04T13:25:20,571` ?

Please find error logs from other node at the same time.

```
[2020-12-04T13:25:20,520][INFO][o.e.c.s.ClusterService] [elk-denmod-6] removed {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2273]])
[2020-12-04T13:25:24,998][INFO][o.e.c.s.ClusterService] [elk-denmod-6] added {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2274]])
[2020-12-04T13:41:30,120][INFO][o.e.d.z.ZenDiscovery] [elk-denmod-6] master_left [{elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300}], reason [transport disconnected]
[2020-12-04T13:41:30,135][WARN][o.e.d.z.ZenDiscovery] [elk-denmod-6] master left (reason = transport disconnected), current nodes: nodes: 
   {elk-denmod-4}{rS_6QTYGSiKTyXJnjvSdyw}{EZ4987G6TQymqCTJk_Mxmw}{168.124.170.244}{168.124.170.244:9300}

```

> [@Luca\_Belluccini](#):
>
> What is the version of the Elasticsearch client you're using

Our Elastic search client version is 5.3.1

> [@Luca\_Belluccini](#):
>
> The settings of the client and the parameters to connect to Elasticsearch (excluding sensitive data)

Please find the settings and parameters to connect to elasticsearch below.

```
cluster.name: elk-denmod
cluster.routing.allocation.disk.watermark.low: 95%
node.name: elk-denmod-web
bootstrap.memory_lock: true
network.host: [ELK1.pharma.aventis.com,_local_]
discovery.zen.ping.unicast.hosts: [ELK1.pharma.aventis.com, ELK2.pharma.aventis.com, ELK3.pharma.aventis.com, ELK4.pharma.aventis.com, ELK5.pharma.aventis.com, ELK6.pharma.aventis.com, ELK7.pharma.aventis.com, ELK8.pharma.aventis.com]
node.master: true
node.data: false
node.ingest: false
xpack.security.enabled: false
xpack.monitoring.enabled: false

Note: Server names are replaced by ELK(1-8) numbering

```

> [@Luca\_Belluccini](#):
>
> Potentially, a snippet of the code of the request you're sending.

Please find the document which contains snippet of the code.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4d5b20d736119f5ec152f4fd48366c10fb39ec97.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aec855e7abb779161bfcb7e8e443c6baf39d4407.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dcc08f39dccba8e00884b1786c0639fbe2ee7939.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff89606ff0315a68c25c1e023135e42554800f1e.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c7e51f68450994c3767aa1d93a2a7993193d4fc.png)

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [December 11, 2020, 12:28pm UTC](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258/20 "2020-12-11T12:28:19Z")

</div>

> [@DENMODSupport](#):
>
> > [@Luca\_Belluccini](#):
> >
> > Can you check/share what are the logs on the other node around the time `2020-12-04T13:25:20,571` ?
> 
> Please find error logs from other node at the same time.
> 
> ```auto
> [2020-12-04T13:25:20,520][INFO][o.e.c.s.ClusterService] [elk-denmod-6] removed {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2273]])
> [2020-12-04T13:25:24,998][INFO][o.e.c.s.ClusterService] [elk-denmod-6] added {{elk-denmod-1}{t7JmFe-iSn63CALYD-0lxw}{Ah6ks-dJScCxug_-xO4zkA}{168.124.25.140}{168.124.25.140:9300},}, reason: zen-disco-receive(from master [master {elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300} committed version [2274]])
> [2020-12-04T13:41:30,120][INFO][o.e.d.z.ZenDiscovery] [elk-denmod-6] master_left [{elk-denmod-web-2}{GhAsUHj8TOSdqWwjdOuPJA}{hTnv0AekT6eVJYSJSBPiDg}{xspw50a102k.pharma.aventis.com}{168.124.170.195:9300}], reason [transport disconnected]
> [2020-12-04T13:41:30,135][WARN][o.e.d.z.ZenDiscovery] [elk-denmod-6] master left (reason = transport disconnected), current nodes: nodes: 
> {elk-denmod-4}{rS_6QTYGSiKTyXJnjvSdyw}{EZ4987G6TQymqCTJk_Mxmw}{168.124.170.244}{168.124.170.244:9300}
> 
> ```

I requested to share the logs of the node `elk-denmod-1`, not `elk-denmod-6`.

> [@DENMODSupport](#):
>
> Please find the settings and parameters to connect to elasticsearch below.
> 
> ```auto
> cluster.name: elk-denmod
> cluster.routing.allocation.disk.watermark.low: 95%
> node.name: elk-denmod-web
> bootstrap.memory_lock: true
> network.host: [ELK1.pharma.aventis.com,_local_]
> discovery.zen.ping.unicast.hosts: [ELK1.pharma.aventis.com, ELK2.pharma.aventis.com, ELK3.pharma.aventis.com, ELK4.pharma.aventis.com, ELK5.pharma.aventis.com, ELK6.pharma.aventis.com, ELK7.pharma.aventis.com, ELK8.pharma.aventis.com]
> node.master: true
> node.data: false
> node.ingest: false
> xpack.security.enabled: false
> xpack.monitoring.enabled: false
> 
> Note: Server names are replaced by ELK(1-8) numbering
> 
> ```

This is the configuration file of one of the nodes.  
In particular, it is a master node and you should avoid connecting to it for search requests.  
You should use a coordinating or target directly a data node if possible.

* * *

Can you run `GET _cat/nodes?v` and explain how the client connects to the cluster (what are the connection parameters you provide in your .NET application to connect to Elasticsearch and to which host you connect to)?

[Next page](https://discuss.elastic.co/t/unable-to-access-data-from-elastic-search/257258.md?page=2)
