# ELK stack set up - Filebeat setup failing

**URL:** <https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 30, 2020, 7:58pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122 "2020-11-30T19:58:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guy\_Goodrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guy_goodrick/32/79962_2.png) [@Guy\_Goodrick](https://discuss.elastic.co/u/Guy_Goodrick)\
**Post date:** [November 30, 2020, 7:58pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/1 "2020-11-30T19:58:33Z")

</div>

Hello - I'm new to this, just getting started installing the ELK stack on Ubuntu 20.04. Everything is running on that one server for now (though eventually we will want to look at a production version with a cluster, but for now this is fine) I'm following a tutorial:

> **[How To Install Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-20-04)**
>
> In this tutorial, we will go over the installation of the Elastic Stack on an Ubuntu 20.04 server. You will learn how to install all of the components of the Elastic Stack (including Filebeat, a Beat used for forwarding and centralizing logs and...

Everything has been ok, up until this:

```
root@snipe:~# sudo filebeat setup --pipelines --modules system
Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch http://localhost:5044: Get http://localhost:5044: read tcp 127.0.0.1:43464->127.0.0.1:5044: read: connection reset by peer]

```

As per the instructions I had already edited /etc/filebeat/filebeat.yml  
I commented out:

```
#output.elasticsearch:
  # Array of hosts to connect to.
  #hosts: ["localhost:9200"]

```

And uncommented

```
output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

```

But still the error message. Any idea what I may have missed? Or where I should look?

Thank you, any help much appreciated!

Guy

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 30, 2020, 8:15pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/2 "2020-11-30T20:15:29Z")

</div>

Because you are passing in `--pipelines` it needs to connect to Elasticsearch to load the ingest pipelines, but you've commented that part out.

It might be easier if you follow [https://www.elastic.co/guide/en/beats/filebeat/7.10/filebeat-installation-configuration.html](https://www.elastic.co/guide/en/beats/filebeat/7.10/filebeat-installation-configuration.html)

---

<div class="post-metadata">

**Author:** ![Guy\_Goodrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guy_goodrick/32/79962_2.png) [@Guy\_Goodrick](https://discuss.elastic.co/u/Guy_Goodrick)\
**Post date:** [November 30, 2020, 8:17pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/3 "2020-11-30T20:17:50Z")

</div>

Okay thank you I'll try those instructions (should have known I'd be better off with the docs than random tutorials!)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 30, 2020, 8:20pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/4 "2020-11-30T20:20:35Z")

</div>

DO can be good, but that one looks a little heavy, there's no need to use ngix for eg as we include free access control in Elasticsearch/Kibana 🙂

---

<div class="post-metadata">

**Author:** ![Guy\_Goodrick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guy_goodrick/32/79962_2.png) [@Guy\_Goodrick](https://discuss.elastic.co/u/Guy_Goodrick)\
**Post date:** [November 30, 2020, 8:53pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/5 "2020-11-30T20:53:36Z")

</div>

Ah really?! Access control was something that I was a bit concerned about - is that a new(ish) thing? I'll dig around the docs for that stuff.

Oh and it's working now - as you said, once I re-enabled elasticsearch as an output I could run that command, then I could follow on with the rest of the tutorial - thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 30, 2020, 9:54pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/6 "2020-11-30T21:54:51Z")

</div>

It's been free for over a year now! 🙂

> **[Security for Elasticsearch is now free](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free)**
>
> We are thrilled to announce that the core security features of the Elastic Stack -- like TLS encryption, RBAC, and both file and native authentication -- are now free.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2020, 9:55pm UTC](https://discuss.elastic.co/t/elk-stack-set-up-filebeat-setup-failing/257122/7 "2020-12-28T21:55:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
