# \[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch

**URL:** <https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883>\
**Category:** Elasticsearch\
**Created:** [August 12, 2019, 4:03pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883 "2019-08-12T16:03:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![SCL\_ADMIN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scl_admin/32/49037_2.png) [@SCL\_ADMIN](https://discuss.elastic.co/u/SCL_ADMIN)\
**Post date:** [August 12, 2019, 4:03pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/1 "2019-08-12T16:03:52Z")

</div>

I had a really large logstash.log file which filled up the hdd

I deleted the file and restarted the service now I I get this

Aug 12 16:54:13 SCL-SIEM-01 logstash[3096]: [2019-08-12T16:54:13,127][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-7.3.0-2019.08.12", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:0x2d9a6298], :response=\>{"index"=\>{"\_index"=\>"filebeat-7.3.0-2019.08.12", "\_type"=\>"\_doc", "\_id"=\>

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 4:32pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/2 "2019-08-12T16:32:06Z")

</div>

Is that really the complete error message?

If you filled the disk and elasticsearch is writing indexes to the same disk then [this](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282/5) should help.

---

<div class="post-metadata">

**Author:** ![SCL\_ADMIN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scl_admin/32/49037_2.png) [@SCL\_ADMIN](https://discuss.elastic.co/u/SCL_ADMIN)\
**Post date:** [August 13, 2019, 2:28pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/3 "2019-08-13T14:28:15Z")

</div>

sorry the full entry is

Aug 13 10:07:30 SCL-SIEM-01 logstash[5784]: [2019-08-13T10:07:30,784][WARN][log stash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>4 00, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-7.3.0-2019.08.13", :\_type= \>"\_doc", :routing=\>nil}, #LogStash::Event:0x54349926], :response=\>{"index"=\>{" \_index"=\>"filebeat-7.3.0-2019.08.13", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400 , "error"=\>{"type"=\>"validation\_exception", "reason"=\>"Validation Failed: 1: thi s action would add [2] total shards, but this cluster currently has [1000]/[1000] maximum shards open;"}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2019, 2:34pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/4 "2019-08-13T14:34:59Z")

</div>

> [@SCL\_ADMIN](#):
>
> this action would add [2] total shards, but this cluster currently has [1000]/[1000] maximum shards open

There is a limit in elasticsearch of 1000 open shards. I expect it could be increased but I am pretty certain that doing so is the wrong approach. This is really an elasticsearch question and you should move it to that forum. The answer will be to reduce the number of shards and folks there should be able to provide guidance.

---

<div class="post-metadata">

**Author:** ![SCL\_ADMIN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scl_admin/32/49037_2.png) [@SCL\_ADMIN](https://discuss.elastic.co/u/SCL_ADMIN)\
**Post date:** [August 13, 2019, 2:42pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/5 "2019-08-13T14:42:42Z")

</div>

> [@Badger](#):
>
> There is a limit in elasticsearch of 1000 open shards. I expect it could be increased but I am pretty certain that doing so is the wrong approach. This is really an elasticsearch question and you should move it to that forum. The answer will be to reduce the number of shards and folks there should be able to provide guidance.

Agreed many thanks

---

<div class="post-metadata">

**Author:** ![SCL\_ADMIN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scl_admin/32/49037_2.png) [@SCL\_ADMIN](https://discuss.elastic.co/u/SCL_ADMIN)\
**Post date:** [August 13, 2019, 3:15pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/6 "2019-08-13T15:15:57Z")

</div>

Hello all

I manged to get around the problem by increasing the shards on the cluster

```
PUT /_cluster/settings
{
  "persistent": {
"cluster.max_shards_per_node": "1500"
  }
}

```

But I don't know if this is the correct course of action... Is there a way of merging the shards or reducing the amount of shards open?

Many Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 3:15pm UTC](https://discuss.elastic.co/t/warn-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch/194883/7 "2019-09-10T15:15:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
