# Logstash 6.0 to elasticsearch 5.6.4 get a 503

**URL:** <https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748>\
**Category:** Logstash\
**Created:** [November 22, 2017, 3:58pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748 "2017-11-22T15:58:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rj-reilly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rj-reilly/32/24568_2.png) [@rj-reilly](https://discuss.elastic.co/u/rj-reilly)\
**Post date:** [November 22, 2017, 3:58pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/1 "2017-11-22T15:58:29Z")

</div>

Hi,  
I upgraded logstash to 6.0 to take advantage of multiple pipelines and logstash receives a 503 from the already working elasticsearch. below is my config and conf  
logstash.yml

```
path.data: /var/lib/logstash
path.logs: /var/log/logstash
path.settings: /etc/logstash
config.reload.automatic: true

```

syslog\_filebeat\_ingest.conf

```
input {
  beats {
    port => 5044
  }
}
filter {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
}
output {
  elasticsearch {
   hosts => ["tf-d-ubu-elk-e-00.edrcore.com:9200"]
    index => "system-beats-%{+YYYY.MM.dd}"
  }
}

```

Error:

[2017-11-22T15:54:21,327][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://redacted.com:9200/](http://redacted.com:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '503' contacting Elasticsearch at URL '[http://redacted.com:9200/](http://redacted.com:9200/)'"}

pipelines.yml

```
- pipeline.id: elb
  path.config: "/etc/logstash/conf.d/elb_ingest.conf"
  pipeline.workers: 1
- pipeline.id: logs_beat
  path.config: "/etc/logstash/conf.d/syslog_filebeat_ingest.conf"
  pipeline.workers: 2

```

it's not a connectivity problem

from my logstash host

```
curl .redacted.com:9200
{
  "name" : "redacted.com",
  "cluster_name" : "redacted",
  "cluster_uuid" : "_na_",
  "version" : {
    "number" : "5.6.4",
    "build_hash" : "8bbedf5",
    "build_date" : "2017-10-31T18:55:38.105Z",
    "build_snapshot" : false,
    "lucene_version" : "6.6.1"
  },
  "tagline" : "You Know, for Search"
}

```

thanks for any help !  
cheers,  
rob

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2017, 5:18pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/2 "2017-11-22T17:18:26Z")

</div>

> [@rj-reilly](#):
>
> beats\_input.conf

I am not sure I understand. You are showing a file named `beats_input.conf`, which does not appear to be part of your `pipelines.yml` file. What do the files you are specifying in `pipelines.yml` look like?

---

<div class="post-metadata">

**Author:** ![rj-reilly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rj-reilly/32/24568_2.png) [@rj-reilly](https://discuss.elastic.co/u/rj-reilly)\
**Post date:** [November 22, 2017, 5:19pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/3 "2017-11-22T17:19:17Z")

</div>

yeah that was just a typo, i did not supply the elb conf because it requires heavy redacting. if you need it I will supply it

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2017, 5:39pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/4 "2017-11-22T17:39:22Z")

</div>

What is the [state of your Elasticsearch cluster](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/_cluster_health.html)? Is there anything in the Elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![rj-reilly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rj-reilly/32/24568_2.png) [@rj-reilly](https://discuss.elastic.co/u/rj-reilly)\
**Post date:** [November 22, 2017, 5:44pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/5 "2017-11-22T17:44:08Z")

</div>

I can reach it no problem

```
ubuntu@xx:~$ telnet xx 9200
Trying xx.xx.xx.xx...
Connected to xx.com.
Escape character is '^]'.
^C^]
telnet> quit 
Connection closed.
ubuntu@xx:~$ curl xx:9200
{
  "name" : "xx.com",
  "cluster_name" : "xx",
  "cluster_uuid" : "_na_",
  "version" : {
    "number" : "5.6.4",
    "build_hash" : "8bbedf5",
    "build_date" : "2017-10-31T18:55:38.105Z",
    "build_snapshot" : false,
    "lucene_version" : "6.6.1"
  },
  "tagline" : "You Know, for Search"
}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2017, 5:54pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/6 "2017-11-22T17:54:03Z")

</div>

That is not the API I linked to.

---

<div class="post-metadata">

**Author:** ![rj-reilly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rj-reilly/32/24568_2.png) [@rj-reilly](https://discuss.elastic.co/u/rj-reilly)\
**Post date:** [November 22, 2017, 6:08pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/7 "2017-11-22T18:08:00Z")

</div>

@Christian_Dahlqvist thank you for your help i was under the assumption that if 9200 was open elastic is up. There was an error in my chef code that applied the prod config ( multi node) to my dev env that only has one node, so elastic was in fact not up.  
thanks again  
rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 6:08pm UTC](https://discuss.elastic.co/t/logstash-6-0-to-elasticsearch-5-6-4-get-a-503/108748/8 "2017-12-20T18:08:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
