# Logstash and elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-and-elasticsearch/88393>\
**Category:** Logstash\
**Created:** [June 6, 2017, 10:10am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393 "2017-06-06T10:10:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 6, 2017, 10:10am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/1 "2017-06-06T10:10:44Z")

</div>

Hi there,  
i am using EL and LS of the same version 5.4.0 and filbeat version 5.4.1.there is the configuration.  
--------------elasticsearch.yml  
[cluster.name](http://cluster.name): elasticsearch  
[node.name](http://node.name): node1  
node.attr.rack: r1  
path.data: /path/to/data  
path.logs: /path/to/logs  
bootstrap.memory\_lock: true  
network.host: 0.0.0.0  
http.port: 9200  
discovery.zen.ping.unicast.hosts: ["127.0.0.1:9200", "127.0.0.1:9200"]  
discovery.zen.minimum\_master\_nodes: 3  
gateway.recover\_after\_nodes: 3  
action.destructive\_requires\_name: true  
----------filebeat.yml  
filebeat.prospectors:  
input\_type: log  
paths:  
- c:\logstash-tutorial.log  
output.logstash:  
hosts: ["localhost:5044"]  
--------------pipeline.conf-----  
input {  
beats {  
port =\> "5044"  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
}  
geoip {  
source =\> "clientip"  
}  
}  
output {  
elasticsearch {  
hosts =\>"localhost:9200"  
}  
stdout { codec =\> rubydebug }  
}  
Note:the LS and ES are runing at the port 6900 and 9200 well.but i get those errors:  
for filebeat: ERR Connecting error publishing events (retrying): dial tcp 127.0.0.1:5044: connectex: Aucune connexion n’a pu être établie car l’ordinateur cible l’a expressément refusée.  
for logstash:error=\>"Got response code '503' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)  
Please how can i solve this probleme?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 10:18am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/2 "2017-06-06T10:18:17Z")

</div>

> [@baha1](#):
>
> ```
> discovery.zen.ping.unicast.hosts: ["127.0.0.1:9200", "127.0.0.1:9200"]
> discovery.zen.minimum_master_nodes: 3
> 
> ```

This appear incorrect. The unicast list should hold hostnames and transport port of other nodes in the cluster so that the nodes in the cluster can find each other. It is common to list the host and port of all master eligible nodes in the cluster. Port 9200 is however for HTTP, so this should instead be 9300, which is the default.

How many nodes do you have in the cluster? `minimum_master_nodes` should be set to `floor(N/2)+1`, where N is the number of master eligible nodes in the cluster. Setting it to 3 would therefore be appropriate if you have 4 or 5 master eligible nodes.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 6, 2017, 10:32am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/3 "2017-06-06T10:32:40Z")

</div>

@Christian_Dahlqvist, thank you so match for your answer.the discovery.zen.ping.unicast.hosts: ["127.0.0.1:9200", "127.0.0.1:9200"] are the hosts are elasticsearch is runing on.for master\_nodes excuse me,i am beginner at LS and [ES.So](http://ES.So) what i should to change?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 11:08am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/4 "2017-06-06T11:08:42Z")

</div>

Do you have multiple nodes running on the same host? If so, how many?

If the nodes are running on different hosts, they need to bind to a public IP, not 127.0.0.1 (which is not accessible from other hosts), and it is this public IP that needs to go into the unicast host list.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 6, 2017, 11:14am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/5 "2017-06-06T11:14:13Z")

</div>

i have just one of ES is runing at 127.0.0.1.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 11:22am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/6 "2017-06-06T11:22:15Z")

</div>

Then you do not need to populate the unicast list as the node has nothing to connect to.

> [@baha1](#):
>
> discovery.zen.minimum\_master\_nodes: 3  
> gateway.recover\_after\_nodes: 3

You should also either remove these settings or set the to 1.

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 6, 2017, 11:33am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/7 "2017-06-06T11:33:22Z")

</div>

Thank you so mutch,it is working.but i get this error when i run`curl -XGET "localhost:9200/logstash-$DATE/_search?pretty&q=response=200"`  
"root\_cause" : [  
{  
"type" : "index\_not\_found\_exception",  
"reason" : "no such index",  
"resource.type" : "index\_or\_alias",  
"[resource.id](http://resource.id)" : "logstash-$DATE",  
"index\_uuid" : "_na_",  
"index" : "logstash-$DATE"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 6, 2017, 11:35am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/8 "2017-06-06T11:35:31Z")

</div>

It is apparent from the error message that $DATE does not evaluate to a valid date. What happens if you correctly specify the full index name or perhaps use a wildcard, e.g. `log stash-*`?

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [June 6, 2017, 11:39am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/9 "2017-06-06T11:39:44Z")

</div>

It works now,thank you verry much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2017, 11:50am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch/88393/10 "2017-07-04T11:50:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
