# Logstash cant connect to Elasticsearch on localhost

**URL:** <https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699>\
**Category:** Logstash\
**Created:** [December 14, 2017, 7:41am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699 "2017-12-14T07:41:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bittujindani](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@bittujindani](https://discuss.elastic.co/u/bittujindani)\
**Post date:** [December 14, 2017, 7:41am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/1 "2017-12-14T07:41:23Z")

</div>

Hi,

I have setup Logstash, ES and Kibana on EC2 server and used localhost:9200 in all three setup yml file. curl command is also working fine. but once I am pushing msg using jdbc I am getting below error.

JDBC working file and displaying the result on local screen using below code snippet

"output {  
stdout { codec =\> json\_lines }  
}"

conf.d -

input {  
jdbc {  
jdbc\_connection\_string =\> "jdbc:postgresql://oratopg.cspwou0nzxz1.us-east-1.rds.amazonaws.com:5432/postgres"  
jdbc\_user =\> "dhairyaj"  
jdbc\_password =\> "Rsadmin11"  
jdbc\_validate\_connection =\> true  
jdbc\_driver\_library =\> "/home/ubuntu/jdbc/postgresql-9.4.1209.jar"  
jdbc\_driver\_class =\> "org.postgresql.Driver"  
statement =\> "SELECT \* from pg\_stat\_activity"  
schedule =\> "\* \* \* \* \*"  
}  
}  
output {  
elasticsearch {

# protocol =\> "http"

```
     index => "pg_stat_activity"
    document_type => "pg_stat_activity"
    document_id => "%{uid}"
    hosts => ["http://localhost:9200"]
}

```

}

I have also tried both localhost and 127.0.0.1:9200 in conf file but its not working.

error:

Attempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200](http://localhost:9200)"]', but an error occurred and it failed! Are you sure you can reach elasticsearch from this machine using the configuration provided? {:error\_message=\>"[406] {"error":"Content-Type header [text/plain; charset=ISO-8859-1] is not supported","status":406}", :error\_class=\>"Elasticsearch ::Transport::Transport::Errors::NotAcceptable", :backtrace=\>["/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/ transport/transport/base.rb:201:in `__raise_transport_error'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearc h/transport/transport/base.rb:312:in`perform\_request'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/tran sport/transport/http/manticore.rb:67:in `perform_request'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/t ransport/client.rb:128:in`perform\_request'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.18/lib/elasticsearch/api/actions/bulk.rb:9 0:in `bulk'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http_client.rb:53:in`non\_threadsafe\_bulk'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/http\_clie nt.rb:38:in `bulk'", "org/jruby/ext/thread/Mutex.java:149:in`synchronize'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7 .1-java/lib/logstash/outputs/elasticsearch/http\_client.rb:38:in `bulk'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-j ava/lib/logstash/outputs/elasticsearch/common.rb:172:in`safe\_bulk'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java /lib/logstash/outputs/elasticsearch/common.rb:101:in `submit'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/l ogstash/outputs/elasticsearch/common.rb:86:in`retrying\_submit'", "/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 14, 2017, 10:03am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/2 "2017-12-14T10:03:00Z")

</div>

I think your LS version is not the same as the elasticsearch one.  
Upgrade Logstash.

---

<div class="post-metadata">

**Author:** ![bittujindani](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@bittujindani](https://discuss.elastic.co/u/bittujindani)\
**Post date:** [December 14, 2017, 10:17am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/3 "2017-12-14T10:17:51Z")

</div>

Thanks for replying. I already tried that. My ES, LS and Kibana all three are on same version.

root@ip-10-0-1-113:/etc/logstash-6.0.1# bin/logstash --version  
logstash 6.0.1

root@ip-10-0-1-113:/etc/logstash-6.0.1# curl -XGET localhost:9200/\_nodes/\_all/process?pretty  
{  
"\_nodes" : {  
"total" : 1,  
"successful" : 1,  
"failed" : 0  
},  
"cluster\_name" : "globo-monitoring",  
"nodes" : {  
"GuiTz9rlTQWprv0kYuBh3Q" : {  
"name" : "globo-es01",  
"transport\_address" : "127.0.0.1:9300",  
"host" : "localhost",  
"ip" : "127.0.0.1",  
"version" : "6.0.1",  
"build\_hash" : "601be4a",  
"roles" : [  
"master",  
"data",  
"ingest"  
],  
"process" : {  
"refresh\_interval\_in\_millis" : 1000,  
"id" : 29972,  
"mlockall" : false  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 14, 2017, 3:07pm UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/4 "2017-12-14T15:07:08Z")

</div>

Did you upgrade Logstash ?

This look weird to me:

```
etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.18/lib/elasticsearch/ transport/transport/base.rb:201:in

```

See the 2.3.4 dir name?

That said I’m moving the question to #logstash

---

<div class="post-metadata">

**Author:** ![bittujindani](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@bittujindani](https://discuss.elastic.co/u/bittujindani)\
**Post date:** [December 15, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/5 "2017-12-15T05:37:12Z")

</div>

> [@dadoonet](#):
>
> plugin/logstash-2.3.4/

I have installed LS plugin and version is 2.3.4. Details are below. Pls let me know if is this not correct way.

Tried below but it won't working :  
root@ip-10-0-1-113:/etc/logstash-6.0.1/bin# /etc/logstash-6.0.1/bin/logstash --config /etc/logstash-6.0.1/conf.d/kibana.conf  
ERROR: Unrecognised option '--config'

It's working fine :

root@ip-10-0-1-113:/etc/logstash-6.0.1/bin# /etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/bin/logstash --config /etc/logstash-6.0.1/conf.d/kibana.conf  
Settings: Default pipeline workers: 4  
Pipeline main started

Below are the plugin details  
root@ip-10-0-1-113:/etc/logstash-6.0.1/plugin/plugin# ls -ltr  
total 140496  
-rw-r--r-- 1 root root 143859279 Jul 16 2016 logstash-all-plugins-2.3.4.tar.gz  
drwxr-xr-x 6 root root 4096 Dec 12 12:05 logstash-2.3.4

root@ip-10-0-1-113:/etc/logstash-6.0.1/plugin/plugin/logstash-2.3.4/bin# ls -ltr  
total 44  
-rw-rw-r-- 1 root root 2947 Jun 27 2016 setup.bat  
-rw-rw-r-- 1 root root 245 Jun 27 2016 rspec.bat  
-rwxrwxr-x 1 root root 322 Jun 27 2016 rspec  
-rw-rw-r-- 1 root root 251 Jun 27 2016 logstash-plugin.bat  
-rw-rw-r-- 1 root root 203 Jun 27 2016 plugin.bat  
-rwxrwxr-x 1 root root 199 Jun 27 2016 plugin  
-rwxrwxr-x 1 root root 439 Jun 27 2016 logstash-plugin  
-rwxrwxr-x 1 root root 5330 Jun 27 2016 logstash.lib.sh  
-rw-rw-r-- 1 root root 689 Jun 27 2016 logstash.bat  
-rwxrwxr-x 1 root root 1854 Jun 27 2016 logstash

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [December 15, 2017, 8:02am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/6 "2017-12-15T08:02:14Z")

</div>

> [@bittujindani](#):
>
> protocol =\> "http"

I don't think that this is a valid setting for the elasticsearch output plugin!

> **[Elasticsearch output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html)**

Regards,  
Nachiket Vartak

---

<div class="post-metadata">

**Author:** ![bittujindani](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@bittujindani](https://discuss.elastic.co/u/bittujindani)\
**Post date:** [December 15, 2017, 10:15am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/7 "2017-12-15T10:15:03Z")

</div>

Yes, got it. Thanks for pointing out this issue. I have started the LS as below and now it's working fine.

/etc/logstash-6.0.1/bin/logstash -f /etc/logstash-6.0.1/conf.d/kibana.conf

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2018, 10:15am UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch-on-localhost/111699/8 "2018-01-12T10:15:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
