# Logstash is freaking out!

**URL:** <https://discuss.elastic.co/t/logstash-is-freaking-out/163021>\
**Category:** Logstash\
**Created:** [January 5, 2019, 2:10am UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021 "2019-01-05T02:10:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 5, 2019, 2:10am UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/1 "2019-01-05T02:10:57Z")

</div>

So I left the house for a little bit and I came back to seeing this on the screen. I am not sure what happened.

[2019-01-04T20:52:50,872][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-01-04T20:52:52,105][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-01-04T20:53:59,021][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2019-01-04T20:53:59,068][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2019-01-04T20:53:59,594][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-01-04T20:55:01,244][WSending Logstash logs to /var/log/logstash which is now configured via log4j2.properties  
[2019-01-04T20:52:35,914][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-01-04T20:52:36,134][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.5.4"}  
[2019-01-04T20:52:47,235][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2019-01-04T20:52:48,298][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-01-04T20:52:49,079][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-01-04T20:52:49,300][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2019-01-04T20:52:49,306][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2019-01-04T20:52:49,469][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://localhost:9200](http://localhost:9200)"]}  
[2019-01-04T20:52:49,682][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2019-01-04T20:52:49,776][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2019-01-04T20:52:50,519][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2110e6cf run\>"}  
[2019-01-04T20:52:50,755][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-01-04T20:52:50,872][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-01-04T20:52:52,105][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-01-04T20:53:59,021][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2019-01-04T20:53:59,068][WARN][logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://localhost:9200/](http://localhost:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
[2019-01-04T20:53:59,594][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-01-04T20:56:05,667][INFO][logstash.outputs.elasticsearch] retrying failed action with response code: 503 ({"type"=\>"unavailable\_shards\_exception", "reason"=\>"[INDEXNAME][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[INDEXNAME][0]] containing [31] requests]"})

Full Error: [https://pastebin.com/jQjzmqQn](https://pastebin.com/jQjzmqQn)

I have tried the following

- Restarting
- Restarting
- I can connect to localhost:9200 and everything works just fine.

| name | "azn9SLJ" |
| --- | --- |
| cluster\_name | "elasticsearch" |
| cluster\_uuid | "OIklYobCT6CW9Q9HhbwQDA" |
| version | |
| number | "6.5.4" |
| build\_flavor | "default" |
| build\_type | "deb" |
| build\_hash | "d2ef93d" |
| build\_date | "2018-12-17T21:17:40.758843Z" |
| build\_snapshot | false |
| lucene\_version | "7.5.0" |
| minimum\_wire\_compatibility\_version | "5.6.0" |
| minimum\_index\_compatibility\_version | "5.0.0" |
| tagline | "You Know, for Search" |

Kibana says `Kibana server is not ready yet`

any help would be great.

---

<div class="post-metadata">

**Author:** ![bloke](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@bloke](https://discuss.elastic.co/u/bloke)\
**Post date:** [January 5, 2019, 4:50am UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/2 "2019-01-05T04:50:40Z")

</div>

Has your Elasticsearch server recovered yet? This is behavior for when ES is not ready to ingest.

whats the output from command

`curl -X GET "localhost:9200/_cluster/health?pretty"`

---

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 5, 2019, 4:09pm UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/3 "2019-01-05T16:09:04Z")

</div>

> [@bloke](#):
>
> curl -X GET "localhost:9200/\_cluster/health?pretty"

Here is my output

[![](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f73af6eb0f08cc30eb6fdc92da70e7aeecfad85.png)](https://imgbb.com/)

Everything seems to be fine now. Its on its 19th file. I just wish I could speed it up. Its taking 3 days to ingest 19 files that are roughly 300 meg csv files.

---

<div class="post-metadata">

**Author:** ![bloke](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@bloke](https://discuss.elastic.co/u/bloke)\
**Post date:** [January 5, 2019, 10:40pm UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/4 "2019-01-05T22:40:36Z")

</div>

you can get stats in ingest like this

```
 curl -X GET 'localhost:9200/_nodes/stats/ingest?pretty'

```

maybe you need to make an ES cluster with more nodes to make it go faster

---

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 6, 2019, 4:44am UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/5 "2019-01-06T04:44:13Z")

</div>

That would be awesome if I could but currently I am running on a dell 2950 server and its the only one I have.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2019, 4:44am UTC](https://discuss.elastic.co/t/logstash-is-freaking-out/163021/6 "2019-02-03T04:44:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
