# Attempted to resurrect connection to dead ES instance

**URL:** <https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/300480>\
**Category:** Logstash\
**Tags:** windows\
**Created:** [March 23, 2022, 3:33pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/300480 "2022-03-23T15:33:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bavaria](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@Bavaria](https://discuss.elastic.co/u/Bavaria)\
**Post date:** [March 23, 2022, 3:33pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/300480/1 "2022-03-23T15:33:12Z")

</div>

Am I missing something? I am trying to send in a basic tryout some logs from a Server with Filebeat, via Logstash to Elasticsearch. I am getting the data from Beats in Logstash. But Logstash is giving me following message constantly:

```auto
[2022-03-23T16:20:12,663][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://localhost:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://localhost:9200/'"}

```

I tried a basic pipeline, to see if the connection works. Like in this documentation [https://www.elastic.co/guide/en/logstash/current/ls-security.html](https://www.elastic.co/guide/en/logstash/current/ls-security.html)

```auto
# The # character at the beginning of a line indicates a comment. Use
# comments to describe your configuration.
input {
	beats {
        	port => "5044"
    	}
}
# The filter part of this file is commented out to indicate that it is
# optional.
# filter {
#
# }
output {
    elasticsearch {
        hosts => ["https://localhost:9200"]
	ssl => true
	cacert => "C:\\Users\\Name\\ElasticStack\\logstash-8.0.1\\config\\certs\\http_ca.crt"
    }
}

```

Any ideas how to solve this, to get the connection? Elasticsearch is running.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 29, 2022, 9:21am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/300480/2 "2022-03-29T09:21:30Z")

</div>

Security features ( authentication and TLS ) are enabled by default in Elasticsearch, as of 8.0.0. See [Secure your connection to Elasticsearch | Logstash Reference [8.1] | Elastic](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic) to configure the Elasticsearch output to authenticate to Elasticsearch. Hope this helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2022, 9:22am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/300480/3 "2022-04-26T09:22:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
