# \[ERROR\]\[logstash.outputs.elasticsearch\]

**URL:** <https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch/107604>\
**Category:** Logstash\
**Created:** [November 14, 2017, 6:27pm UTC](https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch/107604 "2017-11-14T18:27:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cristiano\_Alves](https://avatars.discourse-cdn.com/v4/letter/c/b3f665/32.png) [@Cristiano\_Alves](https://discuss.elastic.co/u/Cristiano_Alves)\
**Post date:** [November 14, 2017, 6:27pm UTC](https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch/107604/1 "2017-11-14T18:27:30Z")

</div>

Hi, my logstash show ERROR:

[2017-11-14T16:19:04,713][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2017-11-14T16:19:04,713][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will\_retry\_in\_seconds=\>64}  
[2017-11-14T16:19:05,962][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2017-11-14T16:19:05,969][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}

my logstash config:

input {

tcp {  
codec =\> "json"  
port =\> 5140  
tags =\> ["windows","nxlog"]  
type =\> "nxlog-json"  
}  
}

filter {

if [type] == "nxlog-json" {  
date {  
match =\> ["[EventTime]", "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "America/Sao\_Paulo"  
}  
mutate {  
rename =\> ["AccountName", "user"]  
rename =\> ["AccountType", "[eventlog][account\_type]" ]  
rename =\> ["ActivityId", "[eventlog][activity\_id]" ]  
rename =\> ["Address", "ip6"]  
rename =\> ["ApplicationPath", "[eventlog][application\_path]" ]  
rename =\> ["AuthenticationPackageName", "[eventlog][authentication\_package\_name]" ]  
rename =\> ["Category", "[eventlog][category]" ]  
rename =\> ["Channel", "[eventlog][channel]" ]  
rename =\> ["Domain", "domain"]  
rename =\> ["EventID", "[eventlog][event\_id]" ]  
rename =\> ["EventType", "[eventlog][event\_type]" ]  
rename =\> ["File", "[eventlog][file\_path]" ]  
rename =\> ["Guid", "[eventlog][guid]" ]  
rename =\> ["Hostname", "hostname"]  
rename =\> ["Interface", "[eventlog][interface]" ]  
rename =\> ["InterfaceGuid", "[eventlog][interface\_guid]" ]  
rename =\> ["InterfaceName", "[eventlog][interface\_name]" ]  
rename =\> ["IpAddress", "ip"]  
rename =\> ["Key", "[eventlog][key]" ]  
rename =\> ["LogonGuid", "[eventlog][logon\_guid]" ]  
rename =\> ["Message", "message"]  
rename =\> ["ModifyingUser", "[eventlog][modifying\_user]" ]  
rename =\> ["NewProfile", "[eventlog][new\_profile]" ]  
rename =\> ["OldProfile", "[eventlog][old\_profile]" ]  
rename =\> ["PrivilegeList", "[eventlog][privilege\_list]" ]  
rename =\> ["ProcessID", "pid"]  
rename =\> ["ProcessName", "[eventlog][process\_name]" ]  
rename =\> ["ProviderGuid", "[eventlog][provider\_guid]" ]  
rename =\> ["ReasonCode", "[eventlog][reason\_code]" ]  
rename =\> ["RecordNumber", "[eventlog][record\_number]" ]  
rename =\> ["ScenarioId", "[eventlog][scenario\_id]" ]  
rename =\> ["Severity", "level"]  
rename =\> ["SeverityValue", "[eventlog][severity\_code]" ]  
rename =\> ["SourceModuleName", "nxlog\_input"]  
rename =\> ["SourceName", "[eventlog][program]" ]  
rename =\> ["SubjectDomainName", "[eventlog][subject\_domain\_name]" ]  
rename =\> ["SubjectLogonId", "[eventlog][subject\_logonid]" ]  
rename =\> ["SubjectUserName", "[eventlog][subject\_user\_name]" ]  
rename =\> ["SubjectUserSid", "[eventlog][subject\_user\_sid]" ]  
rename =\> ["SubjectUserSid", "[eventlog][subject\_user\_sid]" ]  
rename =\> ["System", "[eventlog][system]" ]  
rename =\> ["TargetDomainName", "[eventlog][target\_domain\_name]" ]  
rename =\> ["TargetLogonId", "[eventlog][target\_logonid]" ]  
rename =\> ["TargetUserName", "[eventlog][target\_user\_name]" ]  
rename =\> ["TargetUserSid", "[eventlog][target\_user\_sid]" ]  
rename =\> ["ThreadID", "thread"]

```
}
mutate {
    remove_field => [
                "CurrentOrNextState",
                "Description",
                "EventReceivedTime",
                "EventTime",
                "EventTimeWritten",
                "IPVersion",
                "KeyLength",
                "Keywords",
                "LmPackageName",
                "LogonProcessName",
                "LogonType",
                "Name",
                "Opcode",
                "OpcodeValue",
                "PolicyProcessingMode",
                "Protocol",
                "ProtocolType",
                "SourceModuleType",
                "State",
                "Task",
                "TransmittedServices",
                "Type",
                "UserID",
                "Version"
                ]
}

```

}

}

output {  
elasticsearch { hosts =\> ["127.0.0.1:9200"] }  
#stdout { codec =\> rubydebug }

}

I don't understand because this error, the port 9200 is listing  
curl -s localhost:9200

{  
"name" : "elk-logs",  
"cluster\_name" : "elk-logs",  
"cluster\_uuid" : "pxpQ2VXuTsedXXGlp2SKyQ",  
"version" : {  
"number" : "5.6.4",  
"build\_hash" : "8bbedf5",  
"build\_date" : "2017-10-31T18:55:38.105Z",  
"build\_snapshot" : false,  
"lucene\_version" : "6.6.1"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 6:27pm UTC](https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch/107604/2 "2017-12-12T18:27:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
