# Visualize Bad Gateway and socket hang up errors

**URL:** <https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828>\
**Category:** Elasticsearch\
**Created:** [November 22, 2018, 8:50am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828 "2018-11-22T08:50:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [November 22, 2018, 8:50am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/1 "2018-11-22T08:50:53Z")

</div>

I am using ELK 6.3.1 and off late I have started getting below errors when I try to load any dashboard (including discover) for a relatively longer time span.

 ![Bad%20Gateway%20Error](https://us1.discourse-cdn.com/elastic/original/3X/1/6/1651d4c840483cdb70f5e1f7fe325b121821f610.png)

Sometimes I get this error as well.

 ![Aborted%20Defer%20Error](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d567ee938100172499c23158ed0b7c28187ce694.png)

The only error I see is in Kibana logs that indicate socket hang up.

```auto
{"type":"log","@timestamp":"2018-11-21T13:17:03Z","tags":["error","elasticsearch","data"],"pid":1,"message":"Request error, retrying\nPOST http://10.193.104.42:9200/_msearch => socket hang up"}

```

I checked the usual stats (cpu/memory/disk usage) and they all look OK.  
After I restarted the nodes, it looked like the problem was solved but it soon appeared. I then deleted some old data and since then it is almost working well. (Able to search last 1 year in Discover but not able to load a dashboard that has some heavy aggregations)

Any idea, what I should check? Let me know what other information you may need. Thank You.

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [November 22, 2018, 11:15am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/2 "2018-11-22T11:15:05Z")

</div>

You may want to increase the [`elasticsearch.requestTimeout` setting](https://www.elastic.co/guide/en/kibana/current/settings.html) in `kibana.yml`.

However, you should also be aware that aggregations over big data sets and long timespans are potentially very resource intensive and can lead to out-of-memory situations in addition to taking a long time.

The [Rollup APIs](https://www.elastic.co/guide/en/elasticsearch/reference/master/rollup-apis.html) were created to address some of these issues, and since Kibana 6.5 [rollup visualisations](https://www.elastic.co/guide/en/kibana/6.5/visualize-rollup-data.html) are now also (partially) supported.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2018, 11:19am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/3 "2018-11-22T11:19:42Z")

</div>

What is the output of the [cluster health API](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/cluster-health.html)?

---

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [November 23, 2018, 4:34am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/4 "2018-11-23T04:34:44Z")

</div>

I have already increased that to 600 seconds. I'll be moving to 6.5 as soon as compatible versions of the plugins are available. So i'll give rollup APIs a try. Yes, I understand that and I am mindful of the fact that my setup is relatively low-power (one 64 GB server running two docker instances with 16 gb reserved mem for each instance) and another 16 GB server running client + kibana. I just want to root-cause the issue since the current errors shown are not sufficient. Moreover the behavior is slightly unpredictable. The same data set + span works at times and other times even a reduced set throws error.

If I can see the proof that OOM has occurred or CPU is maxing out, then I can know that is the problem. Thanks.

---

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [November 23, 2018, 4:39am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/5 "2018-11-23T04:39:34Z")

</div>

Green.

{  
"cluster\_name": "es-staging-cluster",  
"status": "green",  
"timed\_out": false,  
"number\_of\_nodes": 6,  
"number\_of\_data\_nodes": 2,  
"active\_primary\_shards": 72,  
"active\_shards": 144,  
"relocating\_shards": 0,  
"initializing\_shards": 0,  
"unassigned\_shards": 0,  
"delayed\_unassigned\_shards": 0,  
"number\_of\_pending\_tasks": 0,  
"number\_of\_in\_flight\_fetch": 0,  
"task\_max\_waiting\_in\_queue\_millis": 0,  
"active\_shards\_percent\_as\_number": 100  
}

---

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [November 23, 2018, 4:43am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/6 "2018-11-23T04:43:02Z")

</div>

BTW, why does it say "Bad Gateway"? Only because the socket is in a stuck state?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [November 23, 2018, 1:51pm UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/7 "2018-11-23T13:51:41Z")

</div>

The HTTP response code `502` (`Bad Gateway`) is usually generated by a proxy. Do you access Elasticsearch or Kibana via a proxy by any chance? If this is the case, you may want to increase the timeout the proxy uses to keep connections open.

---

<div class="post-metadata">

**Author:** ![Nikhil\_Utane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_utane/32/27547_2.png) [@Nikhil\_Utane](https://discuss.elastic.co/u/Nikhil_Utane)\
**Post date:** [November 26, 2018, 5:57am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/8 "2018-11-26T05:57:56Z")

</div>

No, I am not using any proxy.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 5:57am UTC](https://discuss.elastic.co/t/visualize-bad-gateway-and-socket-hang-up-errors/157828/9 "2018-12-24T05:57:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
