# Fail to send data from logstash to elasticsearch after installing x-pack

**URL:** https://discuss.elastic.co/t/fail-to-send-data-from-logstash-to-elasticsearch-after-installing-x-pack/66165
**Category:** Elasticsearch
**Created:** [November 15, 2016, 8:12pm UTC](https://discuss.elastic.co/t/fail-to-send-data-from-logstash-to-elasticsearch-after-installing-x-pack/66165 "2016-11-15T20:12:55Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![mathias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mathias/32/23176_2.png) [@mathias](https://discuss.elastic.co/u/mathias)
#### Post date: [November 15, 2016, 8:12pm UTC](https://discuss.elastic.co/t/fail-to-send-data-from-logstash-to-elasticsearch-after-installing-x-pack/66165/1 "2016-11-15T20:12:55Z")

</div>

Hi,

I tried to install x-pack to get marvel functionality in ES 5.0.0.  
Unfortunately did it force me to use security.

I am currently having problmes sending data from logstash to elastic search.  
[2016-11-15T20:03:15,183][WARN][logstash.outputs.elasticsearch] UNEXPECTED POOL ERROR {:e=\>#\<LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError: No Available connections\>}  
[2016-11-15T20:03:15,183][WARN][logstash.outputs.elasticsearch] Elasticsearch output attempted to sniff for new connections but cannot. No living connections are detected. Pool contains the following current URLs {:url\_info=\>{}}  
[2016-11-15T20:03:20,067][WARN][logstash.outputs.elasticsearch] UNEXPECTED POOL ERROR {:e=\>#\<LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError: No Available connections\>}  
[2016-11-15T20:03:20,068][ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch, but no there are no living connections in the connection pool. Perhaps Elasticsearch is unreachable or down? {:error\_message=\>"No Available connections", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError", :will\_retry\_in\_seconds=\>64}

There is no problem with basic connectivity:  
curl -u elastic:changeme elasticsearch:9200  
{  
"name" : "5--6n-p",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "JLQqztpqR6C55p4x4baNLg",  
"version" : {  
"number" : "5.0.0",  
"build\_hash" : "253032b",  
"build\_date" : "2016-10-26T04:37:51.531Z",  
"build\_snapshot" : false,  
"lucene\_version" : "6.2.0"  
},  
"tagline" : "You Know, for Search"  
}

There are no filebeat indices:  
curl [http://elasticsearch:9200/\_cat/indices/](http://elasticsearch:9200/_cat/indices/) -u elastic:changeme  
yellow open .monitoring-es-2-2016.11.15 RLKhWkBATFCIAvbqPyczgg 1 1 27510 27 11.7mb 11.7mb  
yellow open .monitoring-data-2 8yhqiEkqS\_a3PLjvEXGZ4w 1 1 3 0 6.9kb 6.9kb  
yellow open .kibana alfvdT1hQz-FQNWzFn\_LsA 1 1 62 425 348kb 348kb  
yellow open .monitoring-kibana-2-2016.11.15 oVGI4CUxTw6pFBHYLlALGg 1 1 5184 0 1.2mb 1.2mb  
green open .security 9qs8Gj\_NSQW1V8CYF9ylZg 1 0 4 0 16.2kb 16.2kb

logstash output config:  
output {  
elasticsearch {  
user =\> logstash\_internal  
password =\> changeme  
hosts =\> ["elasticsearch.service.consul:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Role configuration:  
curl -XGET -u elastic:changeme 'elasticsearch:9200/\_xpack/security/role/logstash\_reader?pretty'  
{  
"logstash\_reader" : {  
"cluster" : [],  
"indices" : [  
{  
"names" : [  
"filebeat-\*"  
],  
"privileges" : [  
"read",  
"view\_index\_metadata"  
]  
}  
],  
"run\_as" : [],  
"metadata" : { }  
}  
}

user configuration:  
curl -XGET -u elastic:changeme 'elasticsearch:9200/\_xpack/security/user/logstash\_user?pretty'  
{  
"logstash\_user" : {  
"username" : "logstash\_user",  
"roles" : [  
"logstash\_reader"  
],  
"full\_name" : "Kibana User",  
"email" : null,  
"metadata" : { },  
"enabled" : true  
}  
}

Any ideas why elastic search is not taking logstash data?

Br Mat

---

<div class="post-metadata">

### Author: ![mathias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mathias/32/23176_2.png) [@mathias](https://discuss.elastic.co/u/mathias)
#### Post date: [November 16, 2016, 5:40pm UTC](https://discuss.elastic.co/t/fail-to-send-data-from-logstash-to-elasticsearch-after-installing-x-pack/66165/2 "2016-11-16T17:40:59Z")

</div>

Hi,

I noticed that even after uninstalling x-pack, logstash was still unsuccessfull sending data to elasticsearch.  
I found a work around for the problem. Disabling sniffing in logstash output configuration file made event transfers work again.

Br mat

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 14, 2016, 5:41pm UTC](https://discuss.elastic.co/t/fail-to-send-data-from-logstash-to-elasticsearch-after-installing-x-pack/66165/3 "2016-12-14T17:41:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
