# Logstash Monitoring Error

**URL:** <https://discuss.elastic.co/t/logstash-monitoring-error/126482>\
**Category:** Logstash\
**Created:** [April 3, 2018, 12:39am UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482 "2018-04-03T00:39:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 3, 2018, 12:40am UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/1 "2018-04-03T00:40:00Z")

</div>

My ElasticStack decided to go haywire today and I really have no idea what went wrong. After reinstalling the services, Logstash now logs this error message non-stop:

`[2018-04-02T19:33:52,358][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://logstash_system:xxxxxx@localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@localhost:9200/][Manticore::SocketException] Connection refused: connect"}`

My logstash.yml looks like this:

```
 node.name: Server.FQDN
 path.data: D:/ElasticStack/Data/LogStash
 config.reload.automatic: true
 config.reload.interval: 5s
 pipeline.workers: 12
 pipeline.batch.size: 250
 http.host: "192.168.1.1"
 http.port: 9600
 xpack.monitoring.elasticsearch.username: logstash_system
 xpack.monitoring.elasticsearch.password: logstash
 slowlog.threshold.warn: 2s
 slowlog.threshold.info: 1s
 slowlog.threshold.debug: 500ms
 slowlog.threshold.trace: 100ms
# log.level: debug
 path.logs: D:/ElasticStack/Logs/LogStash

```

My Elasticsearch.yml looks like this:

```
cluster.name: ElasticStack
node.name: Server.FQDN
path.data: D:/ElasticStack/Data/ElasticSearch
path.logs: D:/ElasticStack/Logs/ElasticSearch
bootstrap.memory_lock: true
network.host: 192.168.1.1
http.port: 9200

```

As expected, monitoring in Kibana for Logstash does not appear. Why is the monitoring engine trying to connect on localhost?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 3, 2018, 6:39am UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/2 "2018-04-03T06:39:40Z")

</div>

The default values for `xpack.monitoring.elasticsearch.*` are for localhost, so if it fails to find specific configurations in your logstash.yml, it will fall back to the default values.

My guess is that your uninstall/reinstall removed the config yaml and we're back to the default config that ships with Logstash.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [April 3, 2018, 8:48am UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/3 "2018-04-03T08:48:49Z")

</div>

Either change Elasticsearch to listen on all IPs (which would include localhost) by setting `network.host: 0.0.0.0` in `elasticsearch.yml`.

OR...

Tell Logstash monitoring where to find Elasticsearch by adding the following to `logstash.yml`:

```auto
xpack.monitoring.elasticsearch.url: ["http://192.168.1.1:9200"]

```

The latter would also be required if Elasticsearch and Logstash on separate nodes.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 3, 2018, 12:29pm UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/4 "2018-04-03T12:29:26Z")

</div>

> [@yaauie](#):
>
> The default values for `xpack.monitoring.elasticsearch.*` are for localhost, so if it fails to find specific configurations in your logstash.yml, it will fall back to the default values.
> 
> My guess is that your uninstall/reinstall removed the config yaml and we're back to the default config that ships with Logstash.

I only uninstalled the Windows services, never removed the actual files. The configs posted above were direct copy/paste of what's there.

> [@rcowart](#):
>
> Either change Elasticsearch to listen on all IPs (which would include localhost) by setting `network.host: 0.0.0.0` in `elasticsearch.yml`.
> 
> OR...
> 
> Tell Logstash monitoring where to find Elasticsearch by adding the following to `logstash.yml`:
> 
> ```auto
> xpack.monitoring.elasticsearch.url: ["http://192.168.1.1:9200"]
> 
> ```
> 
> The latter would also be required if Elasticsearch and Logstash on separate nodes.

I actually had it set to `0.0.0.0` originally. I changed it to `192.168.1.1` to try and force a specific interface to listen on. I will add the xpack.monitoring config line and give that a shot.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 3, 2018, 6:22pm UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/5 "2018-04-03T18:22:58Z")

</div>

Setting xpack.monitoring.elasticsearch.url fixed it for me. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2018, 6:23pm UTC](https://discuss.elastic.co/t/logstash-monitoring-error/126482/6 "2018-05-01T18:23:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
