# Is it possible to connect logstash with elasticsearch master node?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-connect-logstash-with-elasticsearch-master-node/37115>\
**Category:** Logstash\
**Created:** [December 14, 2015, 11:12am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-logstash-with-elasticsearch-master-node/37115 "2015-12-14T11:12:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jffifa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jffifa/32/44820_2.png) [@jffifa](https://discuss.elastic.co/u/jffifa)\
**Post date:** [December 14, 2015, 11:12am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-logstash-with-elasticsearch-master-node/37115/1 "2015-12-14T11:12:09Z")

</div>

When I read hints about elasticsearch output plugin I noticed that

> It is important to exclude dedicated master nodes from the hosts list to prevent LS from sending bulk requests to the master nodes. So this parameter should only reference either data or client nodes in Elasticsearch.

> **[Elasticsearch output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-hosts)**

But I tried to do so and connect my logstash instance to my ES cluster with only one node:

```auto
node.data: true
node.master: true

```

And I found that it worked well till today, I got numerous of 400 error when writing data to ES in logstash's log.

Then I checked my ES log and found a large number of DEBUG level error like this:

```auto
[2015-12-14 00:00:52,353][DEBUG][action.bulk] [] observer: timeout notification from cluster service. timeout setting [1m], time since start [1m]
[2015-12-14 00:01:53,925][DEBUG][action.bulk] [] observer: timeout notification from cluster service. timeout setting [1m], time since start [1m]

```

I don't know whether it is caused by the heavy load on indexing action for my ES node, or there is something wrong with my logstash configuration.

So I wonder that is it possible to connect logstash with elasticsearch master node? And if I do so, is there any side effect?

---

<div class="post-metadata">

**Author:** ![rclarke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rclarke/32/68604_2.png) [@rclarke](https://discuss.elastic.co/u/rclarke)\
**Post date:** [December 15, 2015, 11:23am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-logstash-with-elasticsearch-master-node/37115/2 "2015-12-15T11:23:43Z")

</div>

Hello Yangc,

These timeouts are an indication of high load on the cluster - probably long garbage collection cycles. As you say that you have only one node which is both data and master, then you must send all your requests to it. Only in the case where you have dedicated master nodes should you ensure **not** to send any requests to them.

To increase throughput, you will need to have more data nodes, and better still dedicated master nodes.

Cheers,  
-Robin-

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/is-it-possible-to-connect-logstash-with-elasticsearch-master-node/37115/3 "2017-07-06T05:18:22Z")

</div>


