# Logstash.outputs.elasticsearch is trying to connect to another elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526>\
**Category:** Logstash\
**Created:** [September 22, 2017, 6:14pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526 "2017-09-22T18:14:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 22, 2017, 6:14pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/1 "2017-09-22T18:14:42Z")

</div>

I'm following [Running Logstash on Docker | Logstash Reference [5.X] | Elastic](https://www.elastic.co/guide/en/logstash/current/docker.html)

here is my logstash's pipeline configuration:

```
# cat ./usr/share/logstash/pipeline/test.conf
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => "elasticsearch1:9200"
    user => "elastic"
    password => "changeme"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
  stdout { codec => rubydebug }
}
#

```

and here are logs:

```
[INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/modules/fb_apache/configuration"}
[INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/modules/netflow/configuration"}
[INFO][logstash.modules.scaffold] Initializing module {:module_name=>"arcsight", :directory=>"/usr/share/logstash/vendor/bundle/jruby/1.9/gems/x-pack-5.6.1-java/modules/arcsight/configuration"}
[INFO][logstash.setting.writabledirectory] Creating directory {:setting=>"path.queue", :path=>"/usr/share/logstash/data/queue"}
[INFO][logstash.setting.writabledirectory] Creating directory {:setting=>"path.dead_letter_queue", :path=>"/usr/share/logstash/data/dead_letter_queue"}
[INFO][logstash.agent] No persistent UUID file found. Generating new UUID {:uuid=>"5556e81c-1552-4422-81bd-59f121141b2b", :path=>"/usr/share/logstash/data/uuid"}
[INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://logstash_system:xxxxxx@elasticsearch:9200/]}}
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://logstash_system:xxxxxx@elasticsearch:9200/, :path=>"/"}
[WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://logstash_system:xxxxxx@elasticsearch:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch: Name or service not known"}
[INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://elasticsearch:9200"]}
[INFO][logstash.pipeline] Starting pipeline {"id"=>".monitoring-logstash", "pipeline.workers"=>1, "pipeline.batch.size"=>2, "pipeline.batch.delay"=>5, "pipeline.max_inflight"=>2}
[INFO][logstash.pipeline] Pipeline .monitoring-logstash started
[INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://elastic:xxxxxx@elasticsearch1:9200/]}}
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://elastic:xxxxxx@elasticsearch1:9200/, :path=>"/"}
[WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"http://elastic:xxxxxx@elasticsearch1:9200/"}
[INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//elasticsearch1:9200"]}
[INFO][logstash.pipeline] Starting pipeline {"id"=>"main", "pipeline.workers"=>8, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>5, "pipeline.max_inflight"=>1000}
[INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=>"0.0.0.0:5044"}
[INFO][logstash.pipeline] Pipeline main started
[INFO][org.logstash.beats.Server] Starting server on port: 5044
[INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://logstash_system:xxxxxx@elasticsearch:9200/, :path=>"/"}
[WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://logstash_system:xxxxxx@elasticsearch:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch"}
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://logstash_system:xxxxxx@elasticsearch:9200/, :path=>"/"}
[WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://logstash_system:xxxxxx@elasticsearch:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch: Name or service not known"}
[logstash.outputs.elasticsearch] Marking url as dead. Last error: [LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch {:url=>http://logstash_system:xxxxxx@elasticsearch:9200/, :error_message=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch", :error_class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}
[ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error_message=>"Elasticsearch Unreachable: [http://logstash_system:xxxxxx@elasticsearch:9200/][Manticore::ResolutionFailure] elasticsearch", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError", :will_retry_in_seconds=>2}
[WARN][logstash.outputs.elasticsearch] UNEXPECTED POOL ERROR {:e=>#<LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError: No Available connections>}
[ERROR][logstash.outputs.elasticsearch] Attempted to send a bulk request to elasticsearch, but no there are no living connections in the connection pool. Perhaps Elasticsearch is unreachable or down? {:error_message=>"No Available connections", :class=>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError", :will_retry_in_seconds=>4}

```

why is logstash.outputs.elasticsearch trying to connect to _elasticsearch:9200_ instead of _elasticsearch1:9200_?

Please advise.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 25, 2017, 7:37pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/2 "2017-09-25T19:37:42Z")

</div>

Check the monitoring configuration in logstash.yml.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 25, 2017, 8:20pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/3 "2017-09-25T20:20:55Z")

</div>

If I understood correctly (from reading [Running Logstash on Docker](https://www.elastic.co/guide/en/logstash/current/docker.html)), by providing my own volume with pipeline configuration, I override existing configuration...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2017, 5:14am UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/4 "2017-09-26T05:14:14Z")

</div>

Correct, although logstash.yml is the settings file and not part of the pipeline configuration. If you provide additional details like how you're starting the container it'll be easier to help.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [October 6, 2017, 7:14pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/5 "2017-10-06T19:14:33Z")

</div>

@magnusbaeck

I'm looking over [Settings File | Logstash Reference [5.6] | Elastic](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html) and I'm unable to find which setting (variable) would I need to adjust to point _logstash_ to another _elasticsearch_?

I'm getting same errors even if I comment out my pipeline volume, like following:

```
root@app11:/opt/elastic/logstash# grep -v ^# docker-compose.yml 

version: '3'
services:
        logstash:
                image: docker.elastic.co/logstash/logstash:5.6.2
                container_name: logstash11
root@app11:/opt/elastic/logstash#
```

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [October 6, 2017, 9:48pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/6 "2017-10-06T21:48:11Z")

</div>

This isn't the "elasticserach output" in your pipeline configuration.

This extra elasticsearch output is from Logstash x-pack monitoring which comes by default with our docker image.

The implementation details may explain the behavior:

- Logstash is an ETL data flow system
- Exporting metrics to Elasticsearch from Logstash requires a connector _to_ Elasticsearch
- The Logstash Elasticsearch output plugin is a well-travelled connector to Elasticsearch
- So, for x-pack monitoring, Logstash will reuse the ELasticsearch output plugin as a library.

The impact:

- If you have Logstash x-pack enabled, you will _always_ have an Elasticsearch output (in a separate pipeline controlled by x-pack) that is exporting metrics to Elasticsearch.
- This uses `logstash_system` as the user for x-pack Elasticsearch.

Hopefull this helps explain.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [October 7, 2017, 6:51pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/7 "2017-10-07T18:51:40Z")

</div>

@magnusbaeck, thank you for such a detailed reply..

going by what you're saying, I went ahead and disabled xpack monitoring:

```
# grep -A1 environment docker-compose.override.yml 
                environment:
                        - "XPACK_MONITORING_ENABLED=false"
# 

```

and error is no longer there...

however, if xpack monitoring enabled is _true_, how does one adjust it to something that isn't _elasticsearch_?

Thanks in advance)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2017, 6:51pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-is-trying-to-connect-to-another-elasticsearch/101526/8 "2017-11-04T18:51:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
