# Can\`t start up logstash at installed xpack

**URL:** <https://discuss.elastic.co/t/can-t-start-up-logstash-at-installed-xpack/154373>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [October 29, 2018, 5:06am UTC](https://discuss.elastic.co/t/can-t-start-up-logstash-at-installed-xpack/154373 "2018-10-29T05:06:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![KevinLiu](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@KevinLiu](https://discuss.elastic.co/u/KevinLiu)\
**Post date:** [October 29, 2018, 5:06am UTC](https://discuss.elastic.co/t/can-t-start-up-logstash-at-installed-xpack/154373/1 "2018-10-29T05:06:31Z")

</div>

## use offical document config logstash\_internal grant logstash\_writer role,modifyed logstash.yml write logstash\_system username and password,but logstash still can`t start up,log file like this:

```auto
[2018-10-29T04:44:57,702][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://localhost:9200/'"}

```

* * *

```auto

```

* * *

## my logstash output config

```auto
output {
     elasticsearch {
        hosts => ["localhost:9200"]
        user => logstash_internal
        password => mypassword
        index => "logstash-%{tags}-%{+YYYY.MM.dd}"
        document_type => "%{tags}"
        action => "index"
     }
  stdout { codec => rubydebug }
}

```

### command line authentication this accout

```auto
root@baf6624e70ae:/opt/logstash/config# curl -u logstash_internal:mypassword 'http://localhost:9200/_xpack/security/_authenticate?pretty'
{
  "username" : "logstash_internal",
  "roles" : [
    "logstash_writer"
  ],
  "full_name" : "logstash_internal",
  "email" : "logstash_internal@rapid7.com",
  "metadata" : { },
  "enabled" : true
}

```

* * *

## my logstash config file

## xpack.monitoring.enabled: true xpack.monitoring.elasticsearch.username: logstash\_system xpack.monitoring.elasticsearch.password: mypassword xpack.monitoring.elasticsearch.url: ["[http://localhost:9200](http://localhost:9200)"]

**what should i do,for this problem.**

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 1, 2018, 4:28pm UTC](https://discuss.elastic.co/t/can-t-start-up-logstash-at-installed-xpack/154373/2 "2018-11-01T16:28:54Z")

</div>

`logstash_system` and `logstash_internal` are different users.

You have shown that you can authenticate to Elasticsearch with `logstash_internal` and `mypassword`  
but can you please verify that `mypassword` is the correct password for `logstash_system` too?

Try

```auto
curl -u logstash_system:mypassword 'http://localhost:9200/_xpack/security/_authenticate?pretty'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 4:28pm UTC](https://discuss.elastic.co/t/can-t-start-up-logstash-at-installed-xpack/154373/3 "2018-11-29T16:28:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
