# Elasticsearch network configuration

**URL:** <https://discuss.elastic.co/t/elasticsearch-network-configuration/146714>\
**Category:** Logstash\
**Created:** [August 30, 2018, 1:43pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714 "2018-08-30T13:43:54Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![arush\_khanna](https://avatars.discourse-cdn.com/v4/letter/a/cdc98d/32.png) [@arush\_khanna](https://discuss.elastic.co/u/arush_khanna)\
**Post date:** [August 30, 2018, 1:43pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/1 "2018-08-30T13:43:54Z")

</div>

I'm new to elk stack trying to get my hands dirty.  
  
There are two machines - one with logstash where i want to ingest a csv file and store it on another machine where elasticsearch and kibana are installed.  
  
I tried editing elasticsearch.yml and logstash.yml files to assign addresses of host but it is giving error "can't assign requested address".  
  
I couldn't find any resources related to this.   
  
What configuration settings do i need to make?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 30, 2018, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/2 "2018-08-30T13:49:06Z")

</div>

To configure which Elasticsearch host Logstash sends to change the `hosts` option of the elasticsearch output.

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [August 30, 2018, 3:21pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/3 "2018-08-30T15:21:14Z")

</div>

you need to create configuration file that will look something like:

input {  
#ingest your csv file here, read: [INPUT PLUGIN FILE](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html)  
}  
filter {  
#whatever you want to filder etc, read: [FILTER PLUGIN CSV](https://www.elastic.co/guide/en/logstash/current/plugins-filters-csv.html)  
}  
output {  
elasticsearch {  
hosts =\> ["YOUR\_ELASTICSEARCH:9200"]  
index =\> "YOUR\_INDEX\_NAME"  
document\_type =\> "default"  
}  
}

Place your config file in /etc/logstash/conf.d/ with extension .conf  
If you want to have dedicated configuration file location, than you will have to edit the file:

/etc/logstash/pipelines.yml and add custom path to the configuration file, for example:  
you have a config file in **/your/path/myconfig.conf**  
Make sure that logstash can read from this location.

Than you you need to add to the file /etc/logstash/pipelines.yml

> - pipeline.id: whatever\_name\_you\_want\_to\_have  
> path.config: "/your/path/myconfig.conf"  
> pipeline.workers: 16 #by default it is the number of threads your cpu have

Does that answer your question?

---

<div class="post-metadata">

**Author:** ![arush\_khanna](https://avatars.discourse-cdn.com/v4/letter/a/cdc98d/32.png) [@arush\_khanna](https://discuss.elastic.co/u/arush_khanna)\
**Post date:** [September 4, 2018, 1:36pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/4 "2018-09-04T13:36:52Z")

</div>

Thanks @pastechecker @magnusbaeck . It solved the problem.  
  
  
Now it is giving a new error "Unexpected Pool Error".  
  
Tried all solutions in threads related to "Unexpected Pool Error" but it doesn't work.  
  
  
  
i'm running logstash in windows machine and elasticsearch in ubuntu. Are there any extra configurations needed?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 4, 2018, 1:44pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/5 "2018-09-04T13:44:00Z")

</div>

What's the full error message?

---

<div class="post-metadata">

**Author:** ![arush\_khanna](https://avatars.discourse-cdn.com/v4/letter/a/cdc98d/32.png) [@arush\_khanna](https://discuss.elastic.co/u/arush_khanna)\
**Post date:** [September 4, 2018, 3:49pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/6 "2018-09-04T15:49:55Z")

</div>

Hey @magnusbaeck

This thread ([Unexpected pool error](https://discuss.elastic.co/t/unexpected-pool-error/74340)) solved the "Unexpected Pool Error".

It is now showing following message.

> [2018-09-04T20:57:28,485][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://192.168.75.204:9200/](http://192.168.75.204:9200/)][Manticore::SocketException] Connection refused: connect {:url=\>[http://192.168.75.204:9200/](http://192.168.75.204:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://192.168.75.204:9200/](http://192.168.75.204:9200/)][Manticore::SocketException] Connection refused: connect", :error\_class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError"}  
>   
> [2018-09-04T20:57:28,516][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_message=\>"Elasticsearch Unreachable: [[http://192.168.75.204:9200/](http://192.168.75.204:9200/)][Manticore::SocketException] Connection refused: connect", :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError", :will\_retry\_in\_seconds=\>2}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 4, 2018, 8:57pm UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/7 "2018-09-04T20:57:08Z")

</div>

Well, is [http://192.168.75.204:9200](http://192.168.75.204:9200) actually accessible to the Logstash host?

---

<div class="post-metadata">

**Author:** ![arush\_khanna](https://avatars.discourse-cdn.com/v4/letter/a/cdc98d/32.png) [@arush\_khanna](https://discuss.elastic.co/u/arush_khanna)\
**Post date:** [September 5, 2018, 7:29am UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/8 "2018-09-05T07:29:39Z")

</div>

Yes, it is. Echo request is working.  
Windows firewall is disabled too.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 5, 2018, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/9 "2018-09-05T08:51:02Z")

</div>

> Echo request is working.

You mean ping?

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [September 6, 2018, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/10 "2018-09-06T10:43:53Z")

</div>

Can you verify the connectivity using TCP?  
use telnet, curl, wget, tcptraceroute and take traffic sample with tcpdump: ("tcpdump -nni any host 192.168.75.203 and port 9200 and tcp" ) to verify it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-network-configuration/146714/11 "2018-10-04T10:43:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
