# error=\>"Elasticsearch Unreachable:

**URL:** <https://discuss.elastic.co/t/error-elasticsearch-unreachable/127676>\
**Category:** Logstash\
**Created:** [April 11, 2018, 4:22pm UTC](https://discuss.elastic.co/t/error-elasticsearch-unreachable/127676 "2018-04-11T16:22:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dchan08](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dchan08](https://discuss.elastic.co/u/dchan08)\
**Post date:** [April 11, 2018, 4:22pm UTC](https://discuss.elastic.co/t/error-elasticsearch-unreachable/127676/1 "2018-04-11T16:22:20Z")

</div>

Hi,  
i was running the latest version of ELK stack and decided to add x-pack to it, after which when i tried to run the configuration file in logstash it throws me the following error

[INFO] 2018-04-11 06:09:25.860 [main] scaffold - Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/share/logstash/modules/netflow/configuration"}  
[INFO] 2018-04-11 06:09:25.880 [main] scaffold - Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/share/logstash/modules/fb\_apache/configuration"}  
[INFO] 2018-04-11 06:09:26.254 [main] scaffold - Initializing module {:module\_name=\>"arcsight", :directory=\>"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.3-java/modules/arcsight/configuration"}  
[WARN] 2018-04-11 06:09:26.828 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[INFO] 2018-04-11 06:09:27.129 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=\>"6.2.3"}  
[INFO] 2018-04-11 06:09:27.380 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=\>9600}  
[WARN] 2018-04-11 06:09:28.176 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] elasticsearch - You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[[http://localhost:9200](http://localhost:9200)], bulk\_path=\>"/\_xpack/monitoring/\_bulk?system\_id=logstash&system\_api\_version=2&interval=1s", manage\_template=\>false, document\_type=\>"%{[@metadata][document\_type]}", sniffing=\>false, id=\>"8e126056909147d749c2e21d4df5a526c2b41da050e1288d2a23c33a59fd672b", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_21301093-6ba2-4ede-b638-7bfc4d786332", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}

[INFO] 2018-04-11 06:09:28.686 [[.monitoring-logstash]-pipeline-manager] elasticsearch - Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>**[[http://localhost:9200/](http://localhost:9200/)]}}**  
[INFO] 2018-04-11 06:09:28.692 [[.monitoring-logstash]-pipeline-manager] elasticsearch - Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[WARN] 2018-04-11 06:09:28.854 [[.monitoring-logstash]-pipeline-manager] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}  
[INFO] 2018-04-11 06:09:28.863 [[.monitoring-logstash]-pipeline-manager] elasticsearch - New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://localhost:9200](http://localhost:9200)"]}  
[INFO] 2018-04-11 06:09:29.786 [[.monitoring-logstash]-pipeline-manager] licensereader - Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[INFO] 2018-04-11 06:09:29.787 [[.monitoring-logstash]-pipeline-manager] licensereader - Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[WARN] 2018-04-11 06:09:29.796 [[.monitoring-logstash]-pipeline-manager] licensereader - Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}  
[WARN] 2018-04-11 06:09:29.832 [[.monitoring-logstash]-pipeline-manager] licensereader - Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused) {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)  
[ERROR] 2018-04-11 06:09:29.845 [[.monitoring-logstash]-pipeline-manager] licensemanager - Unable to retrieve license information from license server {:message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[WARN] 2018-04-11 06:09:29.849 [[.monitoring-logstash]-pipeline-manager] xpackinfo - Nil response from License Server  
[INFO] 2018-04-11 06:09:29.886 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] pipeline - Pipeline started succesfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x2a453264@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 run\>"}  
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

I am not sure why logstash is trying to reach localhost:9200, when i have configured the logstash to reach 192.168.46.135:9200

---

<div class="post-metadata">

**Author:** ![dchan08](https://avatars.discourse-cdn.com/v4/letter/d/2acd7d/32.png) [@dchan08](https://discuss.elastic.co/u/dchan08)\
**Post date:** [April 11, 2018, 4:24pm UTC](https://discuss.elastic.co/t/error-elasticsearch-unreachable/127676/2 "2018-04-11T16:24:13Z")

</div>

my configuration files

output {  
elasticsearch{  
hosts =\> ["192.168.46.135:9200"]  
protocol =\> http  
}  
stdout {codec =\> rubydebug}  
}

logstash.yml

# Settings file in YAML

# 

# Settings can be specified either in hierarchical form, e.g.:

# 

# pipeline:

# batch:

# size: 125

# delay: 5

# 

# Or as flat keys:

# 

# pipeline.batch.size: 125

# pipeline.batch.delay: 5

# 

# ------------ Node identity ------------

# node.name: test

# ------------ Data path ------------------

path.data: /var/lib/logstash

# ------------ Pipeline Settings --------------

path.logs: /var/log/logstash

# 

# ------------ Other Settings --------------

# 

# Where to find custom plugins

# path.plugins: []

xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.url: [http://192.168.46.135:9200](http://192.168.46.135:9200)  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 4:24pm UTC](https://discuss.elastic.co/t/error-elasticsearch-unreachable/127676/3 "2018-05-09T16:24:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
