# Issue when deployingin remote server as a docker image: logstastash log -\> " Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties" - afterwards no logs from logstash

**URL:** <https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133>\
**Category:** Logstash\
**Created:** [July 31, 2019, 2:03pm UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133 "2019-07-31T14:03:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jobin](https://avatars.discourse-cdn.com/v4/letter/j/bbce88/32.png) [@jobin](https://discuss.elastic.co/u/jobin)\
**Post date:** [July 31, 2019, 2:03pm UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133/1 "2019-07-31T14:03:09Z")

</div>

_ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://localhost:5044)): dial tcp [::1]:5044: connect: cannot assign requested address_  
_2019-07-31T13:43:31.419Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(async(tcp://localhost:5044)) with 60 reconnect attempt(s)_

this is the filebeat log error

logstash is showing log like this for a long time.

_Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties_

but no progress after showing this message,

filebeat.yml file is like this

```
filebeat.inputs:
- type: docker
  combine_partial: true
  containers:
    path: "/usr/share/dockerlogs/data"
    stream: "stdout"
    close_inactive: 5m
    ids:
      - "*"
  exclude_files: ['\.gz$']
  ignore_older: 10m

output.logstash:
  enabled: true
  hosts: ["localhost:5044"]

```

logstash.conf file is like the folllowing

```
input { 
	beats {
	    port => 5044
	    host => "0.0.0.0"
	    ssl => false
  	}
}

filter {
  #If log line contains tab character followed by 'at' then we will tag that entry as stacktrace
  if [message] =~ "\tat" {
    grok {
      match => ["message", "^(\tat)"]
      add_tag => ["stacktrace"]
    }
  }

}

output { 

  stdout {
    codec => rubydebug
  }

  # Sending properly parsed log events to elasticsearch
  elasticsearch {
    hosts => ["192.168.99.100:9200"]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

In local everything is working fine

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 31, 2019, 3:12pm UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133/2 "2019-07-31T15:12:01Z")

</div>

When logstash is running what does 'netstat -an | grep -w 5044' show?

---

<div class="post-metadata">

**Author:** ![jobin](https://avatars.discourse-cdn.com/v4/letter/j/bbce88/32.png) [@jobin](https://discuss.elastic.co/u/jobin)\
**Post date:** [August 1, 2019, 9:45am UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133/3 "2019-08-01T09:45:48Z")

</div>

> [@Badger](#):
>
> netstat -an | grep -w 5044

tcp6 0 0 :::5044 :::\* LISTEN

---

<div class="post-metadata">

**Author:** ![jobin](https://avatars.discourse-cdn.com/v4/letter/j/bbce88/32.png) [@jobin](https://discuss.elastic.co/u/jobin)\
**Post date:** [August 1, 2019, 10:05am UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133/4 "2019-08-01T10:05:09Z")

</div>

I resolved the issue. It was in regards docker networking.

In logstash.conf i changed `hosts => ["localhost:9200]` to `hosts => ["test-elasticsearch"]`  
in which `test-elasticsearch` is my container name.

```
elasticsearch {
    hosts => ["test-elasticsearch"]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }

```

Similarly i updated in filebeat.yml also - from `hosts: ["localhost:5044"]` to `hosts: ["test-logstash"]`

```
`output.logstash:
    enabled: true
    hosts: ["test-logstash"]`

```

**Since the containers are in same network the changed host name worked for me.**

Thanks for the response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2019, 10:05am UTC](https://discuss.elastic.co/t/issue-when-deployingin-remote-server-as-a-docker-image-logstastash-log-sending-logstash-logs-to-usr-share-logstash-logs-which-is-now-configured-via-log4j2-properties-afterwards-no-logs-from-logstash/193133/5 "2019-08-29T10:05:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
