# \[ERROR\]\[logstash.javapipeline

**URL:** <https://discuss.elastic.co/t/error-logstash-javapipeline/314746>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [September 20, 2022, 7:25am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746 "2022-09-20T07:25:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 20, 2022, 7:25am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/1 "2022-09-20T07:25:12Z")

</div>

``` [ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information fromlicense server {:message=\>"Unsupported or unrecognized SSL message"}`Preformatted text`  
[ERROR][logstash.javapipeline][main] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<Manticore::UnknownException: Unsupported or unrecognized SSL message\>, :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.7.0-java/lib/manticore/response.rb:37:in `block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.7.0-java/lib/manticore/response.rb:79:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:74:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:317:in `perform\_request\_to\_url'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:260:in `health_check_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:269:in `block in healthcheck!'", "org/jruby/RubyHash.java:1415:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:265:in `healthcheck!'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:367:in `update_urls'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:83:in `update\_initial\_urls'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:77:in `start'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client.rb:303:in `build\_pool'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client.rb:64:in `initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http_client_builder.rb:106:in `create\_http\_client'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch/http\_client\_builder.rb:102:in `build'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/plugin_mixins/elasticsearch/common.rb:34:in `build\_client'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.8.2-java/lib/logstash/outputs/elasticsearch.rb:270:in `register'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:131:in `register'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:68:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:228:in `block in register\_plugins'", "org/jruby/RubyArray.java:1809:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:227:in `register\_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:585:in `maybe_setup_out_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:240:in `start\_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:185:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:137:in `block in start'"], "pipeline.sources"=\>["/usr/share/logstash/pipeline/logstash.conf"], :thread=\>"#\<Thread:0x21896b59 run\>"}

```auto

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 21, 2022, 4:26pm UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/2 "2022-09-21T16:26:22Z")

</div>

The most likely you are trying to establish HTTP where HTTPS forced on the output side(Elasticsearch or whatever).

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [September 21, 2022, 7:10pm UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/3 "2022-09-21T19:10:28Z")

</div>

Like @Rios said... Check your logstash's output config, if the elasticsearch endpoint is HTTP instead HTTPS.

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 22, 2022, 1:57am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/4 "2022-09-22T01:57:46Z")

</div>

I tried to change the hosts of logstash to http  
**[ERROR]**[logstash.licensechecker.licensereader] Unable to retrieve license information fromlicense server {:message=\>"Got response code '401' contacting Elasticsearch at URL '[http://xxx.xxx.xxx.xx:9201/\_xpack](http://xxx.xxx.xxx.xx:9201/_xpack)'"}  
2022-09-22T01:46:31.158777649Z [2022-09-22T01:46:31,158\*\*][ERROR]\*\*[logstash.monitoring.internalpipelinesource] Failed to fetch X-Pack information from Elasticsearch. This is likely due to failure to reach a live Elasticsearch cluster.

[logstash.outputs.elasticsearch][main] Unable to get license information {:url=\>"[http://rvcope:xxxxxx@sxxx.xxx.xxx.xx:9201/](http://rvcope:xxxxxx@sxxx.xxx.xxx.xx:9201/)", :error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '400' contacting Elasticsearch at URL '[http://seroiudb00540.sero.gic.ericsson.se:9201/\_license](http://seroiudb00540.sero.gic.ericsson.se:9201/_license)'"}

**ERROR** ][logstash.outputs.elasticsearch][main] Failed to install template. {:message=\>"Got response code '403' contacting Elasticsearch at URL '[http://xxx.xxx.xxx.xx:9201/\_template/logstash](http://xxx.xxx.xxx.xx:9201/_template/logstash)'", :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError", :backtrace=\>[

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 22, 2022, 1:58am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/5 "2022-09-22T01:58:39Z")

</div>

Thank you very much. I'm looking at this problem, but I'm confused. Can you help me

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [September 22, 2022, 2:15am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/6 "2022-09-22T02:15:04Z")

</div>

> [@wxhgwh](#):
>
> "Got response code '401' contacting Elasticsearch at URL

Hello...

401 error mean "Unauthorized", please check the elasticsearch's authentication (username/password).

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 22, 2022, 2:17am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/7 "2022-09-22T02:17:14Z")

</div>

Thank you very much for trying to get your answer

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 22, 2022, 7:14am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/8 "2022-09-22T07:14:33Z")

</div>

I can log in to kbana with the account in the configuration file and query the data. Does this verify that my account has permissions

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [September 22, 2022, 10:26am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/9 "2022-09-22T10:26:42Z")

</div>

Does your elasticsearch endpoint listen on port 9201?

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 23, 2022, 2:11am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/11 "2022-09-23T02:11:52Z")

</div>

I don't know where the cause is, but the investigation has been fruitless for a long time

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1f0fe4b84b819003cb7ec5d5aec74066466e3699.png)

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 23, 2022, 2:13am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/12 "2022-09-23T02:13:34Z")

</div>

yes 9201

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 23, 2022, 3:08am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/13 "2022-09-23T03:08:21Z")

</div>

Use curl

`curl -u user:pass http://elastichost:9201` - try with _ **-k** _ and _ **https** _, and without

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 23, 2022, 6:30am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/15 "2022-09-23T06:30:33Z")

</div>

I went to my elasticsearch curl -u HTTP with the command you gave me,  
However, I do not understand how to configure or make a strategy. There is error when logstash is connected.

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 26, 2022, 3:09am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/16 "2022-09-26T03:09:13Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/817e09f1fc3365c65b6056d047da0522a5914ea9.png)  
Boss, do you know what this problem is? What needs to be modified? Please give me your advice

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 26, 2022, 3:21am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/17 "2022-09-26T03:21:22Z")

</div>

Hi @wxhgwh We ask specific questions and I do not see specific answers if you can be specific we can probably help if not it is very hard.

This message appears to indicate elasticsearch is using HTTPS but we do not know.  
`{:message=>"Unsupported or unrecognized SSL message"}`

The very first specific question is is Elasticsearch running on HTTP or HTTPS.

Please be very specific.

Which one works? or do neither

HTTP  
`curl -u user:password http://<host-or-ip>:9201`

or HTTPS  
`curl -k -u user:password https://<host-or-ip>:9201`

Then we can help you with logstash...

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 26, 2022, 3:27am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/18 "2022-09-26T03:27:54Z")

</div>

Hello, my problem has been solved. Thank you for your help  
Let me introduce my environment. I started logstash with Docker, and then modified logstach.conf,  
And reported an error,

It says that the connected is the default Elasticsearch: 9200  
However, my configuration file is not at this address. I hope to get your help. Thank you very much. Can you tell me which configuration file should be modified

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 26, 2022, 3:31am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/19 "2022-09-26T03:31:35Z")

</div>

logstash.conf

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9be87c4af5434e603dbc6fb7a28578a1fe12512b.png)

error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc91c01d5af485466a9e47c8af9c892eb656f464.png)

docker stack.yml

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e936b010af41ebd515aa47894d39424bc431aef3.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 26, 2022, 3:40am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/20 "2022-09-26T03:40:31Z")

</div>

Pasting images of text make it very difficult to help we can not cut-n-paste and help you and many people can not even see / read them.

Looks to me your docker config is not using finding your logstash.conf

I would read this carefully, and make sure these files are readable

> **[Configuring Logstash for Docker | Logstash Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/logstash/7.12/docker-config.html)**

> Bind-mounted configuration files will retain the same permissions and ownership within the container that they have on the host system. Be sure to set permissions such that the files will be readable and, ideally, not writeable by the container’s `logstash` user (UID 1000).

perhaps you should try directories not just the individual files...

---

<div class="post-metadata">

**Author:** ![wxhgwh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wxhgwh/32/111034_2.png) [@wxhgwh](https://discuss.elastic.co/u/wxhgwh)\
**Post date:** [September 26, 2022, 3:44am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/21 "2022-09-26T03:44:05Z")

</div>

Okay Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 3:44am UTC](https://discuss.elastic.co/t/error-logstash-javapipeline/314746/22 "2022-10-24T03:44:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
