# Logstash monitoring warning

**URL:** <https://discuss.elastic.co/t/logstash-monitoring-warning/244835>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [August 13, 2020, 9:24am UTC](https://discuss.elastic.co/t/logstash-monitoring-warning/244835 "2020-08-13T09:24:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gsk](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gsk](https://discuss.elastic.co/u/gsk)\
**Post date:** [August 13, 2020, 9:24am UTC](https://discuss.elastic.co/t/logstash-monitoring-warning/244835/1 "2020-08-13T09:24:40Z")

</div>

Hi all,

I have a cluster of three master-eligible nodes, which are also data nodes, and one coordinating node which also runs a kibana instance. There's also a pipeline node. It's about 7.8.0 version.

All the cluster components are sending monitoring data to the coordinating node over port 9200/tcp. I can see components health in the kibana monitoring page. However, for logstash monitoring I get the following warning:

`[WARN][logstash.outputs.elasticsearchmonitoring][.monitoring-logstash] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"https://logstash_system:xxxxxx@my-mastereligible-data-node.mydomain.tld:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [https://logstash_system:xxxxxx@my-mastereligible-data-node.mydomain.tld:9200/][Manticore::SocketException] No route to host (Host unreachable)"}`

I get this warning for each master-eligible/data node. If I open the port 9200 the connections are established and the warnings are gone.

My question is why logstash needs to communicate over port 9200 with master-eligible/data nodes. I was expecting the communication with the coordinating node over port 9200 being enough. What makes it strange to me is the fact that (as mentioned above) I can see logstash health in kibana page, which means monitoring is working. Am I missing something?

---

<div class="post-metadata">

**Author:** ![gsk](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gsk](https://discuss.elastic.co/u/gsk)\
**Post date:** [August 15, 2020, 9:04am UTC](https://discuss.elastic.co/t/logstash-monitoring-warning/244835/2 "2020-08-15T09:04:06Z")

</div>

Another question rising up after the previous one is how logstash knows about the master-eligible/data nodes in my cluster, since the only node configured for logstash to send data to is the coordinating node. To my understanding, logstash is not a cluster node, it doesn't join the cluster, instead it is just in charge of pipeline functionalities. Shouldn't logshtash know nothing about the other nodes in the cluster?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2020, 9:04am UTC](https://discuss.elastic.co/t/logstash-monitoring-warning/244835/3 "2020-09-12T09:04:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
