This is my setup
IIS Server --> logstash-forwarder --> 2 logstash instances (fqdn certs) --> haproxy --> 2 elasticsearch node
The logstash-forwarder is working and my cluster is also mostly in green.. but out of nowhere for no reason logstash-forwarder seems to stop.
had a look at the logs in the logstash instances and this is what i found
/var/log/logstash/logstash.err
INFO: I/O exception (org.apache.http.NoHttpResponseException) caught when processing request to {}->http://xx.xx.x.123:9200: The target server failed to respond
Jun 16, 2015 9:04:56 AM org.apache.http.impl.execchain.RetryExec execute
INFO: Retrying request to {}->http://xx.xx.xx.123:9200
http://xx.xx.xx.123:9200 <-- this is my haproxy ip!
This is my logstash output config
output {
if "_grokparsefailure" not in [tags] {
elasticsearch {
cluster => "elkstackz"
host => "xx.xx.xx.123"
protocol => "http"
user => "xxxx"
password => "xxxxx"
}
}
file {
tags => "_grokparsefailure_sysloginput"
path => "/var/log/grokparsefailure"
}
}
Is this because the 2 elastic nodes are having bad I/O? I am not using an SSD. Anyways i guess its failing from the haproxy?
regards,
Ismail