# Elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error

**URL:** <https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291>\
**Category:** Elasticsearch\
**Created:** [November 7, 2022, 6:22am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291 "2022-11-07T06:22:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zay\_Lin\_Htun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zay_lin_htun/32/102063_2.png) [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Post date:** [November 7, 2022, 6:22am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/1 "2022-11-07T06:22:57Z")

</div>

My Logstash can not connect to Elastic Search.

My Logstash beats.conf config

```auto
input {
  beats {
    port => 5044
  }
}
output {
  elasticsearch { hosts => ["18.00.00.00:9200"] }
  stdout { codec => rubydebug }
}

```

My Filebeats Config

```auto
# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["3.00.00.00.00:5044"]

```

My Elastic Search config

```auto
# ---------------------------------- Network -----------------------------------
#
# By default Elasticsearch is only accessible on localhost. Set a different
# address here to expose this node on the network:
#
network.host: 0.0.0.0
#
# By default Elasticsearch listens for HTTP traffic on the first free port it
# finds starting at 9200. Set a specific HTTP port here:
#
http.port: 9200
#
# For more information, consult the network module documentation.
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
#
discovery.seed_hosts: ["logstash public ip"]

```

Current my logstash error when I run "bin/logstash -f beats.conf"

```auto
[INFO] 2022-11-07 06:13:32.665 [[main]-pipeline-manager] javapipeline - Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>2, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>250, "pipeline.sources"=>["/usr/share/logstash/beats.conf"], :thread=>"#<Thread:0x2148efd4 run>"}
[INFO] 2022-11-07 06:13:33.251 [[main]-pipeline-manager] javapipeline - Pipeline Java execution initialization time {"seconds"=>0.58}
[INFO] 2022-11-07 06:13:33.274 [[main]-pipeline-manager] beats - Starting input listener {:address=>"0.0.0.0:5044"}
[INFO] 2022-11-07 06:13:33.288 [[main]-pipeline-manager] javapipeline - Pipeline started {"pipeline.id"=>"main"}
[INFO] 2022-11-07 06:13:33.373 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[INFO] 2022-11-07 06:13:33.438 [[main]<beats] Server - Starting server on port: 5044
[INFO] 2022-11-07 06:13:37.589 [Ruby-0-Thread-9: :1] elasticsearch - Failed to perform request {:message=>"18.139.158.62:9200 failed to respond", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::OrgApacheHttp::NoHttpResponseException: 18.139.158.62:9200 failed to respond>}
[WARN] 2022-11-07 06:13:37.590 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://18.139.158.62:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://18.139.158.62:9200/][Manticore::ClientProtocolException] 18.139.158.62:9200 failed to respond"}
[INFO] 2022-11-07 06:13:42.598 [Ruby-0-Thread-9: :1] elasticsearch - Failed to perform request {:message=>"18.139.158.62:9200 failed to respond", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::OrgApacheHttp::NoHttpResponseException: 18.139.158.62:9200 failed to respond>}
[WARN] 2022-11-07 06:13:42.599 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://18.139.158.62:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://18.139.158.62:9200/][Manticore::ClientProtocolException] 18.139.158.62:9200 failed to respond"}
[INFO] 2022-11-07 06:13:47.606 [Ruby-0-Thread-9: :1] elasticsearch - Failed to perform request {:message=>"18.139.158.62:9200 failed to respond", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::OrgApacheHttp::NoHttpResponseException: 18.139.158.62:9200 failed to respond>}
[WARN] 2022-11-07 06:13:47.607 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://18.139.158.62:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://18.139.158.62:9200/][Manticore::ClientProtocolException] 18.139.158.62:9200 failed to respond"}
[INFO] 2022-11-07 06:13:52.615 [Ruby-0-Thread-9: :1] elasticsearch - Failed to perform request {:message=>"18.139.158.62:9200 failed to respond", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::OrgApacheHttp::NoHttpResponseException: 18.139.158.62:9200 failed to respond>}
[WARN] 2022-11-07 06:13:52.615 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://18.139.158.62:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://18.139.158.62:9200/][Manticore::ClientProtocolException] 18.139.158.62:9200 failed to respond"}
[INFO] 2022-11-07 06:13:57.623 [Ruby-0-Thread-9: :1] elasticsearch - Failed to perform request {:message=>"18.139.158.62:9200 failed to respond", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::OrgApacheHttp::NoHttpResponseException: 18.139.158.62:9200 failed to respond>}
[WARN] 2022-11-07 06:13:57.623 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://18.139.158.62:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://18.139.158.62:9200/][Manticore::ClientProtocolException] 18.139.158.62:9200 failed to respond"}
^C[WARN] 2022-11-07 06:13:58.041 [SIGINT handler] runner - SIGINT received. Shutting down.
^C[FATAL] 2022-11-07 06:13:58.626 [SIGINT handler] runner - SIGINT received. Terminating immediately..
[ERROR] 2022-11-07 06:13:58.684 [[main]>worker0] javapipeline - Pipeline worker error, the pipeline will be stopped {:pipeline_id=>"main", :error=>"", :exception=>Java::OrgJrubyExceptions::ThreadKill, :backtrace=>[], :thread=>"#<Thread:0x2148efd4 sleep>"}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 7, 2022, 6:25am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/2 "2022-11-07T06:25:13Z")

</div>

> [@Zay\_Lin\_Htun](#):
>
> ```auto
> elasticsearch { hosts => ["18.00.00.00:9200"] }
> 
> ```

That is not a valid IP.

> [@Zay\_Lin\_Htun](#):
>
> ```auto
> hosts: ["3.00.00.00.00:5044"]
> 
> ```

Nor is this.

> [@Zay\_Lin\_Htun](#):
>
> `"18.139.158.62:9200 failed to respond"`

What IP is Elasticsearch actually listening on?

---

<div class="post-metadata">

**Author:** ![Zay\_Lin\_Htun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zay_lin_htun/32/102063_2.png) [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Post date:** [November 7, 2022, 6:35am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/3 "2022-11-07T06:35:40Z")

</div>

The last one is real public IP of elasticsearch IP and above IPs are just modified security purpose

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 7, 2022, 8:36am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/4 "2022-11-07T08:36:08Z")

</div>

Is Elasticsearch responding on that IP and port?

---

<div class="post-metadata">

**Author:** ![Zay\_Lin\_Htun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zay_lin_htun/32/102063_2.png) [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Post date:** [November 7, 2022, 8:48am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/5 "2022-11-07T08:48:32Z")

</div>

I allowed all ports on both Elasticsearch and logstash for both inobound and outbound. How can I check Elastic Search is response on logstash machine?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 7, 2022, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/6 "2022-11-07T08:49:19Z")

</div>

Curl it 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2022, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291/7 "2022-12-05T08:50:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
