# Can’t start logstash after x-pack installation

**URL:** <https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353>\
**Category:** Logstash\
**Created:** [January 12, 2018, 7:26pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353 "2018-01-12T19:26:01Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 12, 2018, 7:26pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/1 "2018-01-12T19:26:01Z")

</div>

I have this issue now as well, I had logstash running and connecting without issue, after installing x-pack it is now looking at localhost for elastic which doesn't exist.  
Elastic 6.1.1, logstash 6.1.1 Windows 2012R2.  
Config,  
input {  
beats { port =\> 5044  
}  
}  
output {  
elasticsearch {  
hosts =\> ["elastic1:9200"]  
}  
stdout { codec =\> rubydebug }

output:  
[2018-01-12T19:18:35,705][INFO][logstash.licensechecker.licensereader] Running  
health check to see if an Elasticsearch connection is working {:healthcheck\_url=

> [http://localhost:9200/](http://localhost:9200/), :path=\>"/"}

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 12, 2018, 8:00pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/2 "2018-01-12T20:00:11Z")

</div>

I have this in the logstash.yml file,  
xpack.license.self\_generated.type: basic  
xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.url: "[http://elastic1:9200](http://elastic1:9200)"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2018, 11:48pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/3 "2018-01-12T23:48:25Z")

</div>

Did you install X-Pack in Elasticsearch as well?

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 13, 2018, 12:06am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/4 "2018-01-13T00:06:52Z")

</div>

Yes, x-pack is installed on all nodes and kibana

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 13, 2018, 12:08am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/5 "2018-01-13T00:08:13Z")

</div>

> [@GSCully](#):
>
> xpack.license.self\_generated.type: basic

I don't think you need that.

Also, what do the rest of the logs show?

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 13, 2018, 12:36am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/6 "2018-01-13T00:36:27Z")

</div>

Here you go,

[2018-01-12T19:17:58,972][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"D:/logstash/modules/fb\_apache/configuration"}  
[2018-01-12T19:17:58,988][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"D:/logstash/modules/netflow/configuration"}  
[2018-01-12T19:18:00,409][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"arcsight", :directory=\>"D:/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.1.1-java/modules/arcsight/configuration"}  
[2018-01-12T19:18:00,722][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-01-12T19:18:01,769][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.1.1"}  
[2018-01-12T19:18:02,284][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-01-12T19:18:05,128][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[[http://localhost:9200](http://localhost:9200)], bulk\_path=\>"/\_xpack/monitoring/\_bulk?system\_id=logstash&system\_api\_version=2&interval=1s", manage\_template=\>false, document\_type=\>"%{[@metadata][document\_type]}", sniffing=\>false, id=\>"ad524e5a1a68d2ca7086e1144ec98005bcfc1ad3103a990fb9bbf21aa44aa140", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_4913a6bd-22a9-48f8-b3f8-0c2db2c1a1b7", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[2018-01-12T19:18:05,769][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-01-12T19:18:05,784][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-01-12T19:18:08,034][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect"}  
[2018-01-12T19:18:08,050][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://localhost:9200](http://localhost:9200)"]}  
[2018-01-12T19:18:08,065][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>".monitoring-logstash", "pipeline.workers"=\>1, "pipeline.batch.size"=\>2, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>2, :thread=\>"#\<Thread:0x39ca0750 run\>"}  
[2018-01-12T19:18:08,253][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-01-12T19:18:08,253][INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-01-12T19:18:10,315][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect"}  
[2018-01-12T19:18:12,378][WARN][logstash.licensechecker.licensereader] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2018-01-12T19:18:12,393][ERROR][logstash.licensechecker.licensemanager] Unable to retrieve license information from license server {:message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2018-01-12T19:18:12,393][WARN][logstash.licensechecker.xpackinfo] Nil response from License Server  
[2018-01-12T19:18:12,456][INFO][logstash.pipeline] Pipeline started {"[pipeline.id](http://pipeline.id)"=\>".monitoring-logstash"}  
[2018-01-12T19:18:13,128][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-01-12T19:18:15,206][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused: connect"}  
[2018-01-12T19:18:15,221][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://elastic1:9200/](http://elastic1:9200/)]}}  
[2018-01-12T19:18:15,237][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://elastic1:9200/](http://elastic1:9200/), :path=\>"/"}  
[2018-01-12T19:18:15,284][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://elastic1:9200/](http://elastic1:9200/)"}  
[2018-01-12T19:18:15,346][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>nil}  
[2018-01-12T19:18:15,346][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-01-12T19:18:15,362][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 13, 2018, 1:02am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/7 "2018-01-13T01:02:06Z")

</div>

Looks ok to me?

> [@GSCully](#):
>
> [2018-01-12T19:18:15,346][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the type event field won't be used to determine the document \_type {:es\_version=\>6}

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 16, 2018, 12:21am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/8 "2018-01-16T00:21:14Z")

</div>

I see it is only a warning, but it is spamming the log window and I was hoping the Logstash would show up on the kibana but it isn't .

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 17, 2018, 6:51pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/9 "2018-01-17T18:51:16Z")

</div>

More info?  
The below error is spamming my log every two minutes and I see a connection to elastic but I cant see any data getting to it. Any ideas? do you need more info?  
I was thinking of installing elastic on the logstash as an ingest node, but I don't know if that would help?

[WARN][logstash.licensechecker.licensereader] UNEXPECTED POOL ERROR {:e=\>#\<LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError: No Available connections\>}  
[2018-01-17T18:47:32,814]**[ERROR]**[logstash.licensechecker.licensemanager] Unable to retrieve license information from license server {:message=\>"No Available connections", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError"}

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [January 17, 2018, 7:38pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/10 "2018-01-17T19:38:31Z")

</div>

can you confirm that your logstash.yml file doesn't have lines that start with empty spaces?  
It seems that logstash isn't processing those settings correctly so it's defaulting to connect to localhost

Something like:

```auto
 xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.url: "http://elastic1:9200"

```

Or similar could be causing this issue.

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 17, 2018, 9:16pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/11 "2018-01-17T21:16:08Z")

</div>

Made some progress, cleaned up the yml file and removed the x-pack ssl settings, that said now when I try to connect I am getting this,  
[logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance,  
but got an error. {:url=\>"[https://elastic1:9200/](https://elastic1:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[https://elastic1:9200/](https://elastic1:9200/)][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}

So I think that means it isn't reading the ca cert maybe?  
I have this in the conf file, am I missing anything?

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate\_authorities =\> ["D:\logstash\config\ca\ca.crt"]  
ssl\_certificate =\> "D:\logstash\config\logstash\logstash.crt"  
ssl\_key =\> "D:\logstash\config\logstash\logstash.key"

```
} 

```

}  
output {  
elasticsearch {  
hosts =\> ["[https://elastic1:9200](https://elastic1:9200)"]  
ssl =\> true  
cacert =\> "D:/logstash/config/ca/ca.crt"

```
}

```

stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 17, 2018, 9:26pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/12 "2018-01-17T21:26:47Z")

</div>

Please show your `logstash.yml` file.

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 17, 2018, 9:36pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/13 "2018-01-17T21:36:47Z")

</div>

I only included uncommented settings.

[node.name](http://node.name): logstash  
xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.url: "[https://elastic1:9200](https://elastic1:9200)"  
xpack.monitoring.elasticsearch.sniffing: true  
dead\_letter\_queue.enable: true  
dead\_letter\_queue.max\_bytes: 1024mb  
http.host: "10.210.0.161"

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 18, 2018, 7:55pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/14 "2018-01-18T19:55:06Z")

</div>

I've tried reversing the slash's in the config file, that didn't help.

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 18, 2018, 11:50pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/15 "2018-01-18T23:50:35Z")

</div>

Found a solution, Import the CA into the Java keystore, note do not use IP's in the cert, Logstash will spam errors about the ip address.

"C:\Program Files\Java\jre1.8.0\_151\bin\keytool" -import -alias ca -keystore "C:\Program Files\Java\jre1.8.0\_151\lib\security\cacerts" -file "D:\logstash\config\ca\ca.crt"

---

<div class="post-metadata">

**Author:** ![Shahnaz\_Shariff](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Shahnaz\_Shariff](https://discuss.elastic.co/u/Shahnaz_Shariff)\
**Post date:** [February 6, 2018, 4:22am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/16 "2018-02-06T04:22:52Z")

</div>

[2018-02-05T23:20:02,277][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-02-05T23:20:02,280][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}

I'm facing a similar problem. I don't understand why localhost:9200 is mentioned in the logs when I've given the IP address of elasticsearch in both the config file and logstash.yml file.

Any help will be appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 6, 2018, 4:32am UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/17 "2018-02-06T04:32:44Z")

</div>

Please start a new thread with your question 🙂

---

<div class="post-metadata">

**Author:** ![Shahnaz\_Shariff](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Shahnaz\_Shariff](https://discuss.elastic.co/u/Shahnaz_Shariff)\
**Post date:** [February 6, 2018, 3:43pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/18 "2018-02-06T15:43:26Z")

</div>

Sure thanks. Please check [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [http://localhost:9200/]](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-httpclient-pool-hostunreachableerror-error-elasticsearch-unreachable-http-localhost-9200/118674)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2018, 3:43pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353/19 "2018-03-06T15:43:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
