# Logstash not outputting logs to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225>\
**Category:** Logstash\
**Created:** [February 8, 2016, 9:33pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225 "2016-02-08T21:33:49Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gen\_Ohta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gen_ohta/32/7660_2.png) [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Post date:** [February 8, 2016, 9:33pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/1 "2016-02-08T21:33:49Z")

</div>

Hello,

When I set up Elasticsearch, Logstash, Kibana and Filebeat, I used this [tutorial](https://www.elastic.co/guide/en/beats/libbeat/1.1/getting-started.html).

Unfortunately, Logstash is not attempting to output to Elasticsearch at the correct IP address. This is shown in the log message below.

{:timestamp=\>"2016-02-08T16:27:58.572000-0500", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200/](http://localhost:9200/)"]', but Elasticsearch appears to be unreachable or down!", :client\_config=\>{:hosts=\>["[http://localhost:9200/](http://localhost:9200/)"], :ssl=\>nil, :transport\_options=\>{:socket\_timeout=\>0, :request\_timeout=\>0, :proxy=\>nil, :ssl=\>{}}, :transport\_class=\>Elasticsearch::Transport::Transport::HTTP::Manticore, :logger=\>nil, :tracer=\>nil, :reload\_connections=\>false, :retry\_on\_failure=\>false, :reload\_on\_failure=\>false, :randomize\_hosts=\>false}, :error\_message=\>"Connection refused", :class=\>"Manticore::SocketException", :level=\>:error}

My configuration files are below:

/etc/elasticsearch/elasticsearch.yml  
`network.host: PRIVATE_IP_ADDRESS`

/opt/logstash/conf.d/logstash.conf

```
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => ["PRIVATE_IP_ADDRESS:9200"]
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

I have the same file at /etc/logstash/conf.d/logstash.conf because I didn't know where to put the logstash configuration file.

When I run `curl PRIVATE_IP_ADDRESS:9200`, I get the following output

```
{
  "name" : "Gabriel Summers",
  "cluster_name" : "elasticsearch",
  "version" : {
    "number" : "2.1.1",
    "build_hash" : "40e2c53a6b6c2972b3d13846e450e66f4375bd71",
    "build_timestamp" : "2015-12-15T13:05:55Z",
    "build_snapshot" : false,
    "lucene_version" : "5.3.1"
  },
  "tagline" : "You Know, for Search"
}

```

How can I configure Logstash to output to the Elasticsearch at PRIVATE\_IP\_ADDRESS:9200 instead of localhost:92000?

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![w0lverine](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Post date:** [February 9, 2016, 11:38am UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/2 "2016-02-09T11:38:37Z")

</div>

Take the brackets off of:  
`hosts => "Private_IP_ADDRESS:9200"`

Since ES is up and is properly querying results the problem rests in your logstash configuration file. Or unless you have a firewall up and is blocking that specific port. If you think this is a problem use nmap and scan 9200 port and if filtered than you know it is blocked by a firewall or something.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2016, 12:15pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/3 "2016-02-09T12:15:12Z")

</div>

> Take the brackets off of:  
> `hosts => "Private_IP_ADDRESS:9200"`

No, that's not the problem. The `hosts` option is an array.

@Gen_Ohta, make sure you don't have other config files in /opt/logstash/conf.d. Logstash will read _every_ file. Starting Logstash with `--versbose` (or maybe `--debug` is required) will show exactly which configuration files are read and what they contain.

---

<div class="post-metadata">

**Author:** ![Gen\_Ohta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gen_ohta/32/7660_2.png) [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Post date:** [February 9, 2016, 2:37pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/4 "2016-02-09T14:37:56Z")

</div>

Thank you both for your replies.

@magnusbaeck there aren't any more config files in the /opt/logstash/conf.d/ directory.

From the /opt/logstash/ directory I ran  
`bin/logstash -f /opt/logstash/conf.d/logstash.conf --debug` and there were no errors in the output.

Could you please tell me how to run my actual Logstash instance in verbose mode to show which config files it's reading and what they contain?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2016, 2:40pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/5 "2016-02-09T14:40:06Z")

</div>

> Could you please tell me how to run my actual Logstash instance in verbose mode to show which config files it's reading and what they contain?

It depends on how you run Logstash, but your init script (or similar) probably reads /etc/sysconfig/logstash or /etc/default/logstash, where you should find the LS\_OPTS variable (which might be commented out).

---

<div class="post-metadata">

**Author:** ![Gen\_Ohta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gen_ohta/32/7660_2.png) [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Post date:** [February 9, 2016, 3:13pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/6 "2016-02-09T15:13:22Z")

</div>

Thank you. When I first looked at the /etc/sysconfig/logstash, everything was commented out except the last line. I changed my /etc/sysconfig/logstash to look like the following:

```
    # Set a home directory
    LS_HOME=/opt/logstash

    # Arguments to pass to logstash agent
    LS_OPTS=""

    # logstash configuration directory
    LS_CONF_DIR=/opt/logstash/conf.d
    
    KILL_ON_STOP_TIMEOUT=0

```

However I am still getting the same log message after I restart logstash, which is reproduced below.

{:timestamp=\>"2016-02-09T10:05:46.847000-0500", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200/](http://localhost:9200/)"]', but Elasticsearch appears to be unreachable or down!", :client\_config=\>{:hosts=\>["[http://localhost:9200/](http://localhost:9200/)"], :ssl=\>nil, :transport\_options=\>{:socket\_timeout=\>0, :request\_timeout=\>0, :proxy=\>nil, :ssl=\>{}}, :transport\_class=\>Elasticsearch::Transport::Transport::HTTP::Manticore, :logger=\>nil, :tracer=\>nil, :reload\_connections=\>false, :retry\_on\_failure=\>false, :reload\_on\_failure=\>false, :randomize\_hosts=\>false}, :error\_message=\>"Connection refused", :class=\>"Manticore::SocketException", :level=\>:error}

I also ran `sudo /etc/rc.d/init.d/logstash configtest` and the output was "Configuration OK"

Is there anything else I should change about the /etc/sysconfig/logstash file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2016, 3:18pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/7 "2016-02-09T15:18:26Z")

</div>

Add `--verbose` or even `--debug` to LS\_OPTS and start Logstash again. I still suspect you have an extra config file that contains `hosts => "localhost"` or similar.

---

<div class="post-metadata">

**Author:** ![Gen\_Ohta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gen_ohta/32/7660_2.png) [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Post date:** [February 9, 2016, 3:33pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/8 "2016-02-09T15:33:41Z")

</div>

I made LS\_OPTS="--debug" in the /etc/sysconfig/logstash file. Unfortunately, there was nothing in the logs that said which configuration file Logstash was reading. A sample of the logs from when the Logstash was restarted is below.

{:timestamp=\>"2016-02-09T10:38:31.643000-0500", :message=\>"SIGTERM received. Shutting down the pipeline.", :level=\>:warn}  
{:timestamp=\>"2016-02-09T10:38:32.329000-0500", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200/](http://localhost:9200/)"]', but Elasticsearch appears to be unreachable or down!", :client\_config=\>{:hosts=\>["[http://localhost:9200/](http://localhost:9200/)"], :ssl=\>nil, :transport\_options=\>{:socket\_timeout=\>0, :request\_timeout=\>0, :proxy=\>nil, :ssl=\>{}}, :transport\_class=\>Elasticsearch::Transport::Transport::HTTP::Manticore, :logger=\>nil, :tracer=\>nil, :reload\_connections=\>false, :retry\_on\_failure=\>false, :reload\_on\_failure=\>false, :randomize\_hosts=\>false}, :error\_message=\>"Connection refused", :class=\>"Manticore::SocketException", :level=\>:error}  
{:timestamp=\>"2016-02-09T10:38:34.341000-0500", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[http://localhost:9200/](http://localhost:9200/)"]', but Elasticsearch appears to be unreachable or down!", :client\_config=\>{:hosts=\>["[http://localhost:9200/](http://localhost:9200/)"], :ssl=\>nil, :transport\_options=\>{:socket\_timeout=\>0, :request\_timeout=\>0, :proxy=\>nil, :ssl=\>{}}, :transport\_class=\>Elasticsearch::Transport::Transport::HTTP::Manticore, :logger=\>nil, :tracer=\>nil, :reload\_connections=\>false, :retry\_on\_failure=\>false, :reload\_on\_failure=\>false, :randomize\_hosts=\>false}, :error\_message=\>"Connection refused", :class=\>"Manticore::SocketException", :level=\>:error}  
{:timestamp=\>"2016-02-09T10:38:34.796000-0500", :level=\>:warn, "INFLIGHT\_EVENT\_COUNT"=\>{"input\_to\_filter"=\>20, "filter\_to\_output"=\>20, "total"=\>40}, "STALLING\_THREADS"=\>{["LogStash::Outputs::ElasticSearch", {"hosts"=\>"localhost:9200", "manage\_template"=\>"false", "index"=\>"%{[@metadata][beat]}-%{+YYYY.MM.dd}", "document\_type"=\>"%{[@metadata][type]}"}]=\>[{"thread\_id"=\>19, "name"=\>"\>output", "current\_call"=\>"[...]/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.2.0-java/lib/logstash/outputs/elasticsearch/buffer.rb:63:in `synchronize'"}]}}

I ran `grep -r "localhost:9200"` in my `/opt/logstash` directory and there are many places in the `vendor/bundle/jruby/1.9/gems/` directory where `"localhost:9200"` is referenced. Does it make any sense to change all of those to use my private ip address?

If not, could you please tell me what else I should try?

---

<div class="post-metadata">

**Author:** ![Gen\_Ohta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gen_ohta/32/7660_2.png) [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Post date:** [February 9, 2016, 5:47pm UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/9 "2016-02-09T17:47:30Z")

</div>

It turns out that when I was restarting logstash all of the processes weren't being terminated. My config files weren't the problem.

Here are the commands I ran to solve this:

```
ps -ef | grep logstash 
sudo kill EACH_PID 
sudo kill -9 PID_THAT_WASNT_KILLED_BEFORE 
sudo /etc/init.d/logstash start

```

Thank you @magnusbaeck for all of your time and help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/logstash-not-outputting-logs-to-elasticsearch/41225/10 "2017-07-06T05:12:25Z")

</div>


