Watcher not starting on hosted cluster


(Jakehschwartz) #1

Hello all,

I have a cluster hosted on elastic cloud and I can index documents to the cluster, but when I try to create or delete watches, I receive the following error

   "error": "ElasticsearchIllegalStateException[not started]",
   "status": 500

Because this is a hosted cluster, I don't have logs or any sort of useful information. /_cat/indices shows the watcher indexes and /_cat/plugins shows the watcher plugin is installed. What else can I do?

(Alexander Reelsen) #2


Out of curiosity, I assume this an hosted cluster by Elastic Cloud?

Can you manually start watcher using the start API and paste what is being returned?


(Jakehschwartz) #3

Yes, sorry. Hosted by Elastic Cloud.

Both _watcher/_start and _watcher/_restart return

   "acknowledged": true

But my attempts to post a watch still return

    "error": "RemoteTransportException[[tiebreaker-0000000023][inet[/REDACTED-IP]]  [cluster:admin/watcher/watch/put]]; nested: ElasticsearchIllegalStateException[not started]; ",
    "status": 500

(Alexander Reelsen) #4


interesting. Let's try and debug this further.

  1. You do have access to the logs in cloud by checking the Logs tab in cloud. Can you search for watcher and or maybe just paste all the entries that occur when you try to start it?
  2. Is it possible, that you lost some shards of the watcher related indices? Can you run
GET _cat/shards/.w*
GET _cat/shards/.t*

and show the results?


(Jakehschwartz) #5

I can't believe I missed the logs tab :sob:

[2017-01-05 16:45:49,351][WARN ][watcher ] [tiebreaker-0000000023] failed to start watcher. please wait for the cluster to become ready or try to start Watcher manually org.elasticsearch.index.engine.DocumentAlreadyExistsException: [.watch_history-2017.01.04][0] [watch_record][danger-room-ab9c3479-5926-4686-8375-64d8b5075780_12-2017-01-04T00:00:00.096Z]: document already exists at org.elasticsearch.index.engine.InternalEngine.innerCreateNoLock( at org.elasticsearch.index.engine.InternalEngine.innerCreate( at org.elasticsearch.index.engine.InternalEngine.create( at org.elasticsearch.index.shard.IndexShard.create( at org.elasticsearch.action.index.TransportIndexAction.shardOperationOnPrimary( at$PrimaryPhase.performOnPrimary( at$PrimaryPhase$1.doRun( at at java.util.concurrent.ThreadPoolExecutor.runWorker( at java.util.concurrent.ThreadPoolExecutor$ at

I deleted the .watch_history* indicies and have attempted to restart it again but it looks like it hung with nothing in the logs other than "[INFO ][watcher ] starting watch service..."

(Jakehschwartz) #6

Even after a full cluster restart, nothing is happening in the logs. All of my shards are in a STARTED state as well.

(Jakehschwartz) #7

Looks like it just took a long time to start. Thanks for your help

17:22:42	INFO	watcher	[2017-01-05 17:22:42,604][INFO ][watcher ] watch service has started
17:06:37	INFO	watcher	[2017-01-05 17:06:37,444][INFO ][watcher ] starting watch service...

(Alexander Reelsen) #8


wow, thats a lot of time for starting up! I guess it is too late now, but was any one of those indices (especially the .triggered-watches one) containing a lot of documents?


(Jakehschwartz) #9

I removed all the watches before hand, so unless trigged-watches was full of deleted documents or something that caused it to be slow.

(system) #10

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.