# Can not connect to localhost:9600 for logstash

**URL:** <https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687>\
**Category:** Logstash\
**Created:** [February 20, 2022, 7:14am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687 "2022-02-20T07:14:24Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 20, 2022, 7:14am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/1 "2022-02-20T07:14:24Z")

</div>

logstash 7.17.0  
Elasticsearch 7.17.0  
logstash with all default settings, fresh install  
use sudo systemctl start logstash to start, sudo status shows logstash actively running

However, curl -XGET 'localhost:9600/?pretty' returns can not connect to 9600  
do a netstat, seems no 9600 port is running at all

Please advise

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 21, 2022, 10:16am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/2 "2022-02-21T10:16:12Z")

</div>

Check Logstash logs: /var/log/logstash to see is Logstash running at all.

Add to logstash.yml:

```auto
config.debug: true
log.level: debug

```

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 21, 2022, 9:25pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/3 "2022-02-21T21:25:23Z")

</div>

Sorry, no need for that. I believe rubydebug already logged the error, that was taken care of.  
Do you know how to map mongodb data to Elasticsearch without messing up the document structure? logstash will parse(flatten) any object into string id: like user:{firstName: x} to user\_firstName: x. do you know any way to keep the structure?  
(maybe in filter copy and remove one by one, but that's too tedious I believe)  
Maybe I'll start a new topic?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2022, 9:57pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/4 "2022-02-21T21:57:08Z")

</div>

> [@TomYang1993](#):
>
> Do you know how to map mongodb data to Elasticsearch without messing up the document structure?

On a mongodb input, the default for the parse\_method option is "flatten". You may want "[simple](https://github.com/phutchins/logstash-input-mongodb/blob/097cc9be8bb57754ec4006e174f0cb5cf3ff6b65/lib/logstash/inputs/mongodb.rb#L345)" instead.

Although you may then need to re-parse any hashes that it calls .to\_s on.

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 22, 2022, 1:54am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/5 "2022-02-22T01:54:28Z")

</div>

works like a charm, but mongodb ISODate is giving me troubles

```auto
"caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [2022-02-22 01:38:05 UTC] with format [strict_date_optional_time||epoch_millis]"

```

I have a field `created_at_iso: ISODate("2022-02-22T01:38:05.150Z")` like this, logstash/elastic don't like it.  
Do I need to change the format on mongodb side?  
or can I do it on logstash side(filter section Date match)?  
or can i do it on elastic side(someone mentioned templating)?  
and is it related to the reparsing you were talking about?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 2:13am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/6 "2022-02-22T02:13:59Z")

</div>

> "failed to parse date field [2022-02-22 01:38:05 UTC] with format [strict\_date\_optional\_time||epoch\_millis]"

strict\_date\_optional\_time supports a date, and an optional time. Examples: `yyyy-MM-dd'T'HH:mm:ss.SSSZ` or `yyyy-MM-dd` . It will fail to parse when it reaches the ` UTC` at the end. You could try using mutate+gsub to remove it.

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 22, 2022, 2:31am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/7 "2022-02-22T02:31:32Z")

</div>

"error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"

yup, I gsub all UTC to empty strings, It passed that., that works!  
However, it returns to the old problem, I have a user field as an object, but it seems just parses it as a JSON string, for example: `"{\"firstName\"=>\"x\", \"lastName\"=>\"y\"}"`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 3:19am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/8 "2022-02-22T03:19:49Z")

</div>

> [@TomYang1993](#):
>
> I have a user field as an object

OK, that is what I was referring to when I wrote "you may then need to re-parse any hashes that it calls .to\_s on". If you look at the [code](https://github.com/phutchins/logstash-input-mongodb/blob/097cc9be8bb57754ec4006e174f0cb5cf3ff6b65/lib/logstash/inputs/mongodb.rb#L354), "simple" parsing will .to\_s any top level fields in the Mongo data except a Numeric, an Array, or the string "NaN". That converts an object to a string of JSON.

Is it a single field with a constant name? If so, just add a json filter to re-parse it.

Also, I see there is an [open issue](https://github.com/phutchins/logstash-input-mongodb/issues/99) for the fact that it adds ` UTC` instead of `Z` to an ISODate when it parses one. Nobody has updated the code in 5 years, that it is unlikely to change.

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 22, 2022, 4:50am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/9 "2022-02-22T04:50:44Z")

</div>

it is one level deep object, but I got the same error.  
But reason is different in details.  
I applied `filter { json { source => user}}`  
it found the user field, it tries to parse it, but it seems to be already modified by logstash or something else, just like the example above `"{\"firstName\"=>\"x\", \"lastName\"=>\"y\"}"`  
so the parser complains about `ParserError: Unexpected character ('=' (code 61)): was expecting a colon to separate field name and value`  
is there any step I can do before?

my filter so far

```auto
filter {
        json {
                source => "user"
        }
        mutate {
                gsub => ["created_at_iso","UTC",""]
        }
        mutate {
                remove_field => ["log_entry"]
        }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2022, 6:28pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/10 "2022-02-22T18:28:30Z")

</div>

> [@Badger](#):
>
> That converts an object to a string of JSON.

@TomYang1993, that statement is incorrect. It uses "=\>" to separate the key and value, not ":". You can fix this using mutate+gsub

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { "[@metadata][b]" => "1" "[@metadata][c]" => "2" } }
    ruby { code => 'event.set("foo", event.get("@metadata").to_s)' }
    mutate { gsub => ["foo", "=>", ":"] }
    json { source => "foo" }
}

```

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 23, 2022, 4:17am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/11 "2022-02-23T04:17:18Z")

</div>

`"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}`

weird same error again, and =\> did parse to :

As I can tell from the parsed document, it seems move all four fields(email firstName lastName userId) to the top level, and keeps user field with a string like "{"firstName":"a", "lastName":"b", "email":"c", "username":"d"}". And it complains about this user field with a string value instead of an object, I am confused.

So I assume it parsed user object, spread them into top level, and somehow keeps a JSON string for the actual user field

```auto
filter {
        mutate {
                gsub => ["user", "=>",":"]
        }
        json {
                source => "user"
        }
        mutate {
                gsub => ["created_at_iso","UTC",""]
        }
        mutate {
                remove_field => ["log_entry"]
        }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 23, 2022, 4:26am UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/12 "2022-02-23T04:26:53Z")

</div>

> [@Badger](#):
>
> `json { source => "foo" }`

You might need to change that to

```
json { source => "foo" target => "user" }

```

Worst case, mutate+rename user to a [@metadata] sub-field, then parse it with a json filter that targets [user]

---

<div class="post-metadata">

**Author:** ![TomYang1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomyang1993/32/102023_2.png) [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Post date:** [February 23, 2022, 7:18pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/13 "2022-02-23T19:18:50Z")

</div>

cool! but created\_at\_iso is still giving troubles, why logstash is not showing all errors at once? I guess it's a fail safe.  
Anyway, so `"failed to parse date field [2022-02-23 19:09:15] with format [strict_date_optional_time||epoch_millis]`, we got rid of `UTC`, that seems to be out of the way.  
now the white space between are giving me troubles(not sure, but looks like it).

my updated filter:

```auto
filter {
        mutate {
                gsub => ["user", "=>",":"]
        }
        json {
                source => "user"
                target => "user"
        }
        mutate {
                gsub => ["created_at_iso","UTC|[\s]+$",""]
        }
        date {
                match => ["created_at_iso", "yyyy-MM-dd HH:mm:ss"]
                target => "created_at_iso"
        }
        mutate {
                remove_field => ["log_entry","_id"]
        }
}

```

I assume logstash regular expression is different? I comes from JS background.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 23, 2022, 7:23pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/14 "2022-02-23T19:23:22Z")

</div>

> [@TomYang1993](#):
>
> `gsub => ["created_at_iso","UTC|[\s]+$",""]`

That will globally replace _either_ the string UTC _or_ trailing whitespace, not both. Just use

```
gsub => ["created_at_iso", " UTC", ""]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2022, 7:23pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687/15 "2022-03-23T19:23:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
