# Having trouble to get ELK working on the Logstash part

**URL:** https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396
**Category:** Elasticsearch
**Tags:** docker
**Created:** [October 28, 2019, 1:10am UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396 "2019-10-28T01:10:03Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![NewHere](https://avatars.discourse-cdn.com/v4/letter/n/5e9695/32.png) [@NewHere](https://discuss.elastic.co/u/NewHere)
#### Post date: [October 28, 2019, 1:10am UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/1 "2019-10-28T01:10:03Z")

</div>

I am trying out the ELK to pipe a tomcat log to ES via Logstash and view it in Kibana. After running "docker-compose up" I can visit ES via [http://localhost:9200/\_cat/health](http://localhost:9200/_cat/health). Also Kibana via [http://localhost:5601](http://localhost:5601). However, Logstash always gives

```
[logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://localhost:9200/][Manticore::SocketException] Connection refused (Connection refused)"}

```

Here is my docker-compose.yml

```
version: '3'
services:
  elasticsearch:
    container_name: elasticsearch
    image: docker.elastic.co/elasticsearch/elasticsearch:7.4.1
    environment:
      - node.name=elasticsearch
      - cluster.name=elasticsearch
      - bootstrap.memory_lock=true
      - discovery.type=single-node
    ports:
      - "9200:9200"
    ulimits:
      memlock:
        soft: -1
        hard: -1
  kibana:
    container_name: kibana
    image: docker.elastic.co/kibana/kibana:7.4.1
    ports:
      - "5601:5601"
  logstash:
    container_name: logstash
    image: docker.elastic.co/logstash/logstash:7.4.1
    volumes:
      - ./logstash.conf:/usr/share/logstash/pipeline/logstash.conf

```

And my logstash.conf

```
input {
  file {
    path => "C:\Tomcat\logs\myapp.log"
    codec => "json"
    type => "logback"
  }
}
output {
  elasticsearch {
    hosts => "localhost:9200"
  }
}

```

Please help

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 28, 2019, 5:04am UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/2 "2019-10-28T05:04:39Z")

</div>

In the logstash output section try below, elasticsearch is the name of the container within the docker context

`hosts => "http://elasticsearch:9200"`

Also if this is on Windows use forward slashes for the path to the log file.

`path => "C:/Tomcat/logs/myapp.log"`

---

<div class="post-metadata">

### Author: ![NewHere](https://avatars.discourse-cdn.com/v4/letter/n/5e9695/32.png) [@NewHere](https://discuss.elastic.co/u/NewHere)
#### Post date: [October 28, 2019, 7:19am UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/3 "2019-10-28T07:19:19Z")

</div>

Thanks @stephenb! The error has gone once I changed "localhost" to "elasticsearch"!  
As for the path, I have to mount a volume for "C:\Tomcat\logs\myapp.log" to "/usr/share/logstash/logs/myapp.log:ro" and update the input file path to "/usr/share/logstash/logs/myapp.log".

Now it all works! I wonder why localhost did not work though?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [October 28, 2019, 2:15pm UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/4 "2019-10-28T14:15:38Z")

</div>

Hi 1 other thing you should probably create a network in your docker compose. Example [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html)

And localhost for logstash is it's on container not the Elasticsearch container the others work because you bound the port from container to external host

---

<div class="post-metadata">

### Author: ![NewHere](https://avatars.discourse-cdn.com/v4/letter/n/5e9695/32.png) [@NewHere](https://discuss.elastic.co/u/NewHere)
#### Post date: [October 28, 2019, 11:48pm UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/5 "2019-10-28T23:48:32Z")

</div>

Very helpful @stephenb thank you!  
I checked, the docker images are already creating and joining the same network called "elk\_default" out of the box. So I guess thats enough 👌

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 25, 2019, 11:48pm UTC](https://discuss.elastic.co/t/having-trouble-to-get-elk-working-on-the-logstash-part/205396/6 "2019-11-25T23:48:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
