# Fresh instalation - Logstash cannot connect to ElasticSearch

**URL:** <https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085>\
**Category:** Logstash\
**Created:** [September 18, 2019, 8:16pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085 "2019-09-18T20:16:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 18, 2019, 8:16pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/1 "2019-09-18T20:16:58Z")

</div>

Hi all,

I installed Elasticsearch, Kibana, and Logstash from zip files on Windows.  
Elasticsearch seems to work - I can connect via Kibana and insert documents to the index. My browser returns JSON response when directed to localhost:9200  
Everything installed on the local machine on default settings - no changes to the configuration.  
But Logstash cannot connect. I have run `logstash-sample.conf` using following command:  
`c:\logstash-7.3.2\bin\logstash.bat --path.data c:\logstash-7.3.2\data\ -f c:\logstash-7.3.2\config\logstash-sample.conf`  
and I see following in the output:

> [2019-09-18T15:57:00,323][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to \_template/logstash  
> [2019-09-18T15:57:00,358][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
> [2019-09-18T15:57:00,382][INFO][org.logstash.beats.Server] Starting server on port: 5044  
> [2019-09-18T15:57:00,831][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2019-09-18T15:58:00,410][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError"}  
> [2019-09-18T15:58:00,414][ERROR][logstash.outputs.elasticsearch] Failed to install template. {:message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError", :backtrace=\>["C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:293:in `perform_request_to_url'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:278:in `block in perform\_request'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:373:in `with_connection'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:277:in `perform\_request'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:285:in `block in Pool'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client.rb:352:in `template\_put'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client.rb:86:in `template_install'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/template_manager.rb:28:in `install'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/template\_manager.rb:16:in `install_template'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/common.rb:130:in `install\_template'", "C:/logstash-7.3.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/common.rb:51:in `block in setup\_after\_successful\_connection'"]}

What am I missing or doing wrong?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2019, 8:28pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/2 "2019-09-18T20:28:33Z")

</div>

> [@MMH](#):
>
> Failed to install template. {:message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out",

It is connecting, but not getting a response when it tries to install a template. How is the elasticsearch output configured?

---

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 18, 2019, 8:35pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/3 "2019-09-18T20:35:56Z")

</div>

> [@Badger](#):
>
> It is connecting, but not getting a response when it tries to install a template. How is the elasticsearch output configured?

I do not know if I understand your question corectly. Here is `output` section of sample `conf` file:

> output {  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> #user =\> "elastic"  
> #password =\> "changeme"  
> }  
> }

I tried with `user` and `password` parameters uncommented, but still got same error.

---

<div class="post-metadata">

**Author:** ![parallelthought](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@parallelthought](https://discuss.elastic.co/u/parallelthought)\
**Post date:** [September 18, 2019, 8:50pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/4 "2019-09-18T20:50:29Z")

</div>

By default, Logstash tries to install a template for an Index within ES for every request it sends. The error indicates that the user "elastic" used in the output section of the Logstash's pipeline does not have enough privileges to create it.

So provide all the privileges via the Security to start and then refine it as per your needs.

---

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 18, 2019, 9:06pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/5 "2019-09-18T21:06:53Z")

</div>

> [@parallelthought](#):
>
> So provide all the privileges via the Security to start and then refine it as per your needs.

Can it be done with basic features? All documentation I can find states, that one need X-Pack to perform such actions.

---

<div class="post-metadata">

**Author:** ![parallelthought](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@parallelthought](https://discuss.elastic.co/u/parallelthought)\
**Post date:** [September 19, 2019, 8:49am UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/6 "2019-09-19T08:49:26Z")

</div>

The Security feature is part of XPack Basic license. And XPack is part of v7.3.2 by default. It just needs to be enabled in the config.

Some documentation on this topic:

- [https://www.elastic.co/blog/security-for-elasticsearch-is-now-free](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free)
- [https://www.elastic.co/blog/getting-started-with-elasticsearch-security](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)
- [https://www.elastic.co/guide/en/elastic-stack-overview/current/security-getting-started.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/security-getting-started.html)

> **[Secure Elasticsearch with TLS encryption and role-based access control](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)**
>
> Secure your Elasticsearch clusters -- and the other components of the Elastic Stack -- with node-to-node TLS and role-based access control (RBAC). These features and more are now available free with the default distribution of Elasticsearch and...

---

<div class="post-metadata">

**Author:** ![MMH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmh/32/54449_2.png) [@MMH](https://discuss.elastic.co/u/MMH)\
**Post date:** [September 19, 2019, 3:39pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/7 "2019-09-19T15:39:19Z")

</div>

Thank you, this was a case.  
I followed documentation from links you provided and my stack works perfectly now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2019, 3:39pm UTC](https://discuss.elastic.co/t/fresh-instalation-logstash-cannot-connect-to-elasticsearch/200085/8 "2019-10-17T15:39:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
