# Error with LogStash after upgrading to 5.4 and installing x-pack

**URL:** <https://discuss.elastic.co/t/error-with-logstash-after-upgrading-to-5-4-and-installing-x-pack/86737>\
**Category:** Elasticsearch\
**Created:** [May 22, 2017, 8:25pm UTC](https://discuss.elastic.co/t/error-with-logstash-after-upgrading-to-5-4-and-installing-x-pack/86737 "2017-05-22T20:25:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [May 22, 2017, 8:25pm UTC](https://discuss.elastic.co/t/error-with-logstash-after-upgrading-to-5-4-and-installing-x-pack/86737/1 "2017-05-22T20:25:36Z")

</div>

I just upgraded to Release 5.4 of the ELK Stack and have installed x-pack for ElasticSearch, Kibana, and Logstash.

Here are my .yml settings used:  
ElasticSearch:  
xpack.monitoring.elasticsearch.url: "[http://localhost:9200](http://localhost:9200)"  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: ""

Kibana:  
xpack.monitoring.elasticsearch.url: "[http://localhost:9200](http://localhost:9200)"  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: ""

Logstash:  
xpack.monitoring.elasticsearch.url: "[http://localhost:9200](http://localhost:9200)"  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: ""

Logstash.conf:  
elasticsearch {  
document\_type =\> "ExceptionLogInfo"  
index =\> "exceptionlog-%{+YYYY.MM.dd}"  
user =\> logstash\_internal  
password =\> logstash\_internal\_password  
}

What I am seeing in my logstash-plain log file is this:  
[logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>#\<URI::HTTP:0x41b5bf37 URL:[http://logstash\_system:xxxxxx@localhost:9200/\_xpack/monitoring/?system\_id=logstash&system\_api\_version=2&interval=1s](http://logstash_system:xxxxxx@localhost:9200/_xpack/monitoring/?system_id=logstash&system_api_version=2&interval=1s)\>, :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"

From everything that I've read it looks like I have everything configured correctly yet I continue to get this error and don't know why so any help / assistance would be greatly appreciated.

TIA,  
Bill Youngman

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 22, 2017, 9:40pm UTC](https://discuss.elastic.co/t/error-with-logstash-after-upgrading-to-5-4-and-installing-x-pack/86737/2 "2017-05-22T21:40:49Z")

</div>

> [@byoungman](#):
>
> Got response code '401'

A `401` error is [Unauthorized](https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#4xx_Client_errors), which in the context of HTTP/REST really means "authentication failed"

The most probable causes are:

- The `logstash_internal` user was never created
- The `logstash_internal` user was created, but the relevant realm isn't configured in your `elasticsearch.conf`
- There's a mistake with `logstash_internal_password` in the `logstash.conf`

The first step to diagnosing this problem are:

1. Make sure you understand how Elasticsearch [authentication realms](https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html) work.
2. Make sure you understand how the [Logstash security documentation](https://www.elastic.co/guide/en/x-pack/current/logstash.html) fits into Elasticsearch realms.
3. Use the [authenticate API](https://www.elastic.co/guide/en/x-pack/current/security-api-authenticate.html) to test authenticating as "logstash\_internal".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2017, 9:41pm UTC](https://discuss.elastic.co/t/error-with-logstash-after-upgrading-to-5-4-and-installing-x-pack/86737/3 "2017-06-19T21:41:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
