# "Attempted to resurrect connection to dead ES instance, but got an error." Error, it worked before. What is wrong now?

**URL:** <https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721>\
**Category:** Logstash\
**Created:** [April 7, 2019, 5:17pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721 "2019-04-07T17:17:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tony\_Pham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_pham/32/42522_2.png) [@Tony\_Pham](https://discuss.elastic.co/u/Tony_Pham)\
**Post date:** [April 7, 2019, 5:17pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/1 "2019-04-07T17:17:11Z")

</div>

![settings%20%3Aetc%3Alogstash%3A%20(ssh)%202019-04-07%2019-13-34](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd02dd00bbd6e0f59a9025d4fcb729c808648af3.png)  
Hello,

I know that the device which is host to Logstash can ping to the device which is host to Kibana and Elasticsearch. I once parsed syslog using logstash to elasticsearch. Now I need to parse json file (suricata data) and now I get this error as seen on the picture. The configuration file of logstash is following:

input {  
file {  
path =\> ["/home/tony2/Desktop/sample\_data/eve.json"]  
codec =\> json  
type =\> "SuricataIDPS"  
}

}

filter {  
if [type] == "SuricataIDPS" {  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
ruby {  
code =\> "if event['event\_type'] == 'fileinfo'; event['fileinfo']['type']=event['fileinfo']['magic'].to\_s.split(',')[0]; end;"  
}  
}

if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
if ![geoip.ip] {  
if [dest\_ip] {  
geoip {  
source =\> "dest\_ip"  
target =\> "geoip"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["176.16.4.12:9200"]  
stdout {codec =\> rubydebug }  
}  
}

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [April 7, 2019, 10:01pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/2 "2019-04-07T22:01:24Z")

</div>

Did you verify that the ES instance is actually running? That you once used it to parse syslog does NOT imply that it is running now. And pinging does not imply that you can reach it on tcp port 9200 either.  
And PLEASE don't post images. Copy the text and post it properly formatted.

---

<div class="post-metadata">

**Author:** ![Tony\_Pham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_pham/32/42522_2.png) [@Tony\_Pham](https://discuss.elastic.co/u/Tony_Pham)\
**Post date:** [April 7, 2019, 10:17pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/3 "2019-04-07T22:17:50Z")

</div>

Hello,

Thank you for your reply. Yes I did write curl -XGET 174.16.4.12:9200 and it returned me with the correct output.

P.s. sorry for the picture.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [April 7, 2019, 10:21pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/4 "2019-04-07T22:21:07Z")

</div>

And why do you have stdout as part of the elasticsearch output? Align and format the code.. Placed the } wrong?

---

<div class="post-metadata">

**Author:** ![Tony\_Pham](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_pham/32/42522_2.png) [@Tony\_Pham](https://discuss.elastic.co/u/Tony_Pham)\
**Post date:** [April 7, 2019, 10:25pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/5 "2019-04-07T22:25:14Z")

</div>

The stdout has # in front of it in the original file... I guess I copy/pasted it wrong here. Nevertheless it’s not working. I don’t have suricata installed (yet), however those logs are sample logs on different device, that actually have suricata. Does that matter at all though?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2019, 10:25pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-error-it-worked-before-what-is-wrong-now/175721/6 "2019-05-05T22:25:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
