# How to force LogStash to connect using Ip Address instead of DNS names

**URL:** https://discuss.elastic.co/t/how-to-force-logstash-to-connect-using-ip-address-instead-of-dns-names/233748
**Category:** Logstash
**Tags:** docker
**Created:** [May 21, 2020, 1:58pm UTC](https://discuss.elastic.co/t/how-to-force-logstash-to-connect-using-ip-address-instead-of-dns-names/233748 "2020-05-21T13:58:59Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)
#### Post date: [May 21, 2020, 1:58pm UTC](https://discuss.elastic.co/t/how-to-force-logstash-to-connect-using-ip-address-instead-of-dns-names/233748/1 "2020-05-21T13:58:59Z")

</div>

In my local environment, I must use IP Address instead of Localhost or other nickname. My settup is Docker over Virtual Box instead of Docker For Windows. It is not part of my question discuss why I am using Virtual Box instead of HyperV but only for superficial explanation I use also Minishift for other projects (free OpenShift) and it depends on Virtualbox.

I have noted that I must use Docker Machine IP address in some places that most of Hello World tutorials just use localhost, 127.0.0.1 or the name of the container.

After I enable xpack security Logstash can't connect to Elasticsearch poping up this error

... Got response code '401' contacting Elasticsearch at URL '[http://elasticsearch:9200/](http://elasticsearch:9200/)' ... Got response code '401' contacting Elasticsearch at URL '[http://elasticsearch:9200/\_xpack](http://elasticsearch:9200/_xpack)'"

I am not sure this is the issue but I would like try force Logstash connect to Elasticsearch throw my Docker Machine IP address ([http://192.168.99.100:9200](http://192.168.99.100:9200))

Is it possible? If so, how?

Here are my docker-compose.yml

`  
version: '3.2'  
services:

\*\*\* zookpeeper, kafka and filebeat removed

elasticsearch:  
image: [docker.elastic.co/elasticsearch/elasticsearch:7.7.0](http://docker.elastic.co/elasticsearch/elasticsearch:7.7.0)  
environment:  
- cluster.name=docker-cluster  
- bootstrap.memory\_lock=true  
- "ES\_JAVA\_OPTS=-Xms512m -Xmx512m"  
- xpack.security.enabled=true  
- xpack.security.http.ssl.enabled=false  
- discovery.type=single-node  
ulimits:  
memlock:  
soft: -1  
hard: -1  
volumes:  
- "//c/Users/mycomp/docker\_folders/esdata:/usr/share/elasticsearch/data"  
ports:  
- "9200:9200"

kibana:  
image: [docker.elastic.co/kibana/kibana:7.7.0](http://docker.elastic.co/kibana/kibana:7.7.0)  
volumes:  
- "//c/Users/mycomp/docker\_folders/kibana.yml:/usr/share/kibana/config/kibana.yml"  
restart: always  
environment:  
- SERVER\_NAME=kibana.localhost  
- ELASTICSEARCH\_HOSTS=http://192.168.99.100:9200  
ports:  
- "5601:5601"  
links:  
- elasticsearch  
depends\_on:  
- elasticsearch

logstash:  
image: [docker.elastic.co/logstash/logstash:7.7.0](http://docker.elastic.co/logstash/logstash:7.7.0)  
volumes:  
- "//c/Users/mycomp/docker\_folders/logstash.conf:/config-dir/logstash.conf"  
restart: always  
command: logstash -f /config-dir/logstash.conf  
ports:  
- "9600:9600"  
- "7777:7777"  
links:  
- elasticsearch  
- kafka1  
`

logstash.conf

`  
xpack.monitoring.elasticsearch.hosts: ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: =\> "l12345"

input{  
kafka{  
codec =\> "json"  
bootstrap\_servers =\> "kafka1:9092"  
topics =\> ["app\_logs","request\_logs"]  
tags =\> ["app"]  
}  
}

filter {   
\*\*\* removed  
}

output {  
elasticsearch {  
hosts =\> ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
index =\> "logstash-{+YYYY.MM.dd}"  
user =\> "userlog"  
password =\> "userlog"  
}  
}  
`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f34b1f26b9264510f89af64a2085d05003354bb.png)

Complete Logs

`logstash_1 | WARNING: All illegal access operations will be denied in a future release logstash_1 | Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties logstash_1 | [2020-05-21T12:41:12,468][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified logstash_1 | [2020-05-21T12:41:12,488][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.7.0"} logstash_1 | [2020-05-21T12:41:13,543][WARN][logstash.monitoringextension.pipelineregisterhook] xpack.monitoring.enabled has not been defined, but found elasticsearch configuration. Please explicitly set`xpack.monitoring.enabled: true`in logstash.yml logstash_1 | [2020-05-21T12:41:13,548][WARN][deprecation.logstash.monitoringextension.pipelineregisterhook] Internal collectors option for Logstash monitoring is deprecated and targeted for removal in the next major version. logstash_1 | Please configure Metricbeat to monitor Logstash. Documentation can be found at: logstash_1 | https://www.elastic.co/guide/en/logstash/current/monitoring-with-metricbeat.html logstash_1 | [2020-05-21T12:41:15,361][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://elasticsearch:9200/]}} logstash_1 | [2020-05-21T12:41:15,763][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://elasticsearch:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://elasticsearch:9200/'"} logstash_1 | [2020-05-21T12:41:15,861][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=>"Got response code '401' contacting Elasticsearch at URL 'http://elasticsearch:9200/_xpack'"} logstash_1 | [2020-05-21T12:41:15,939][ERROR][logstash.monitoring.internalpipelinesource] Failed to fetch X-Pack information from Elasticsearch. This is likely due to failure to reach a live Elasticsearch cluster. logstash_1 | [2020-05-21T12:41:16,538][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"input\", \"filter\", \"output\" at line 1, column 1 (byte 1)", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:58:in`compile\_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:66:in `compile_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:28:in `block in compile\_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:27:in `compile\_sources'", "org/logstash/execution/AbstractPipelineExt.java:181:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:67:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:43:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:342:in `block in converge_state'"]} logstash_1 | [2020-05-21T12:41:17,011][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600} logstash_1 | [2020-05-21T12:41:21,818][INFO][logstash.runner] Logstash shut down. dockercomposelogs_logstash_1 exited with code 1 `

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 18, 2020, 1:59pm UTC](https://discuss.elastic.co/t/how-to-force-logstash-to-connect-using-ip-address-instead-of-dns-names/233748/2 "2020-06-18T13:59:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
