# Cannot get input from elasticsearch - logstash terminates itself

**URL:** <https://discuss.elastic.co/t/cannot-get-input-from-elasticsearch-logstash-terminates-itself/215713>\
**Category:** Logstash\
**Created:** [January 20, 2020, 10:35am UTC](https://discuss.elastic.co/t/cannot-get-input-from-elasticsearch-logstash-terminates-itself/215713 "2020-01-20T10:35:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![peter\_pan](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@peter\_pan](https://discuss.elastic.co/u/peter_pan)\
**Post date:** [January 20, 2020, 10:35am UTC](https://discuss.elastic.co/t/cannot-get-input-from-elasticsearch-logstash-terminates-itself/215713/1 "2020-01-20T10:35:10Z")

</div>

Hi ELKers,

I would like to ask about your help on the following issue, which it is that I cannot get input from elasticsearch into logstash.

My configuration is simple as that in the logstash-simple.conf:

```
input {
 elasticsearch {
   hosts => "localhost:9200"
   query => '{ "query": { "match_all": {} } }'
 }
}

output {
  elasticsearch {
    hosts => "localhost:9200"
    index => "test_logstash"
  }
}

```

And the command that i use is the following:  
bin/logstash --log.level debug -f config/logstash-simple.yml

When I run the logstash it seems that cannot get data from Elasticsearch for some reason and terminates itself. A sample output is:

> Blockquote

[2020-01-20T10:29:07,007][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2020-01-20T10:29:07,008][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2020-01-20T10:29:07,098][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2020-01-20T10:29:07,150][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2020-01-20T10:29:07,154][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2020-01-20T10:29:07,161][DEBUG][logstash.outputs.elasticsearch] Found existing Elasticsearch template. Skipping template management {:name=\>"logstash"}  
[2020-01-20T10:29:07,161][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2020-01-20T10:29:07,167][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
[2020-01-20T10:29:07,286][INFO][logstash.pipeline] Pipeline main started  
[2020-01-20T10:29:07,316][DEBUG][logstash.agent] Starting puma  
[2020-01-20T10:29:07,320][DEBUG][logstash.agent] Trying to start WebServer {:port=\>9600}  
[2020-01-20T10:29:07,331][DEBUG][logstash.api.service] [api-service] start  
[2020-01-20T10:29:07,371][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2020-01-20T10:29:07,373][DEBUG][logstash.inputs.elasticsearch] closing {:plugin=\>"LogStash::Inputs::Elasticsearch"}  
[2020-01-20T10:29:07,374][DEBUG][logstash.pipeline] Input plugins stopped! Will shutdown filter/output workers.  
[2020-01-20T10:29:07,418][DEBUG][logstash.pipeline] Pushing flush onto pipeline  
[2020-01-20T10:29:07,419][DEBUG][logstash.pipeline] Pushing shutdown {:thread=\>"#\<Thread:0x1f26c632 sleep\>"}  
[2020-01-20T10:29:07,419][DEBUG][logstash.pipeline] Pushing shutdown {:thread=\>"#\<Thread:0x14dcc3d2 sleep\>"}  
[2020-01-20T10:29:07,420][DEBUG][logstash.pipeline] Pushing shutdown {:thread=\>"#\<Thread:0x34c17ed1 run\>"}  
[2020-01-20T10:29:07,421][DEBUG][logstash.pipeline] Pushing shutdown {:thread=\>"#\<Thread:0x55162334 sleep\>"}  
[2020-01-20T10:29:07,422][DEBUG][logstash.pipeline] Shutdown waiting for worker thread #Thread:0x1f26c632  
[2020-01-20T10:29:07,461][DEBUG][logstash.pipeline] Shutdown waiting for worker thread #Thread:0x14dcc3d2  
[2020-01-20T10:29:07,461][DEBUG][logstash.pipeline] Shutdown waiting for worker thread #Thread:0x34c17ed1  
[2020-01-20T10:29:07,463][DEBUG][logstash.pipeline] Shutdown waiting for worker thread #Thread:0x55162334  
[2020-01-20T10:29:07,463][DEBUG][logstash.outputs.elasticsearch] closing {:plugin=\>"LogStash::Outputs::Elasticsearch"}  
[2020-01-20T10:29:07,464][DEBUG][logstash.outputs.elasticsearch] Stopping sniffer  
[2020-01-20T10:29:07,464][DEBUG][logstash.outputs.elasticsearch] Stopping resurrectionist  
[2020-01-20T10:29:08,152][DEBUG][logstash.outputs.elasticsearch] Waiting for in use manticore connections  
[2020-01-20T10:29:08,152][DEBUG][logstash.outputs.elasticsearch] Closing adapter #LogStash::Outputs::ElasticSearch::HttpClient::ManticoreAdapter:0x1c6336d9  
[2020-01-20T10:29:08,153][DEBUG][logstash.pipeline] Pipeline main has been shutdown  
[2020-01-20T10:29:10,311][DEBUG][logstash.instrument.periodicpoller.os] PeriodicPoller: Stopping  
[2020-01-20T10:29:10,311][DEBUG][logstash.instrument.periodicpoller.jvm] PeriodicPoller: Stopping  
[2020-01-20T10:29:10,311][DEBUG][logstash.instrument.periodicpoller.persistentqueue] PeriodicPoller: Stopping  
[2020-01-20T10:29:10,312][DEBUG][logstash.instrument.periodicpoller.deadletterqueue] PeriodicPoller: Stopping  
[2020-01-20T10:29:10,314][WARN][logstash.agent] stopping pipeline {:id=\>"main"}  
[2020-01-20T10:29:10,315][DEBUG][logstash.pipeline] Closing inputs  
[2020-01-20T10:29:10,316][DEBUG][logstash.inputs.elasticsearch] stopping {:plugin=\>"LogStash::Inputs::Elasticsearch"}  
[2020-01-20T10:29:10,316][DEBUG][logstash.pipeline] Closed inputs

Notes:

1. I run the elasticsearch and the logstash on the same machine.
2. When i try to give an input from stdin{} instead of the elasticseach it works fine and the new index "text\_logstash" is created.
3. A simple curl query to localhost:9200 works fine, I am getting the response back.

Your help is appreciated!!

---

<div class="post-metadata">

**Author:** ![peter\_pan](https://avatars.discourse-cdn.com/v4/letter/p/d78d45/32.png) [@peter\_pan](https://discuss.elastic.co/u/peter_pan)\
**Post date:** [January 20, 2020, 3:08pm UTC](https://discuss.elastic.co/t/cannot-get-input-from-elasticsearch-logstash-terminates-itself/215713/2 "2020-01-20T15:08:49Z")

</div>

OK guys the issue is now SOLVED.  
The problem was that I was not referring to specific index in the input.  
So, if I modify the input to

elasticsearch {  
hosts =\> "localhost:9200"  
**index =\> "index\_name"**  
query =\> '{ "query": { "match\_all": {} } }'  
}

it connects to elasticsearch and gets the data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2020, 3:22pm UTC](https://discuss.elastic.co/t/cannot-get-input-from-elasticsearch-logstash-terminates-itself/215713/3 "2020-02-17T15:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
