# Logstash sends to elasticsearch cluster failed

**URL:** https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303
**Category:** Logstash
**Created:** [March 12, 2020, 9:53am UTC](https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303 "2020-03-12T09:53:19Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![RAM\_NATHAN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_nathan/32/50393_2.png) [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)
#### Post date: [March 12, 2020, 9:53am UTC](https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303/1 "2020-03-12T09:53:19Z")

</div>

I have configured logstash output with three elasticsearch nodes which is in a cluster as below

```
        elasticsearch 
        { 
           hosts => ["http://ip1:9200","http://ip2:9200","http://ip3:9200"]
           document_id => "%{sessionid}"
           index => "index"
        }

```

For testing, if I manually stop one of the nodes I'm getting below error

[WARN][logstash.outputs.elasticsearch][events] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://ip1:9200/](http://ip1:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://ip1:9200/](http://ip1:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}

I thought even if one of the nodes is inaccessible , other nodes will get data from logstash

Isn't it expected behaviour?? How should I make sure events are getting written to active elasticsearch nodes, even if one of nodes is not reachable??

---

<div class="post-metadata">

### Author: ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)
#### Post date: [March 12, 2020, 3:30pm UTC](https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303/2 "2020-03-12T15:30:01Z")

</div>

A 3-node cluster is a very peculiar situation. Now, how is the cluster configured? What is the `minimum_master_nodes` value? Because if you only have one master eligible node and that is the one you're shutting down, you obviously will have problems reaching the cluster. If you have a `minimum_master_nodes` equal to 2 and you shut down one of the two master eligible nodes, you will have problems as well. If all of your nodes are master eligible, with `minimum_master_nodes` equal to 1, if you shit down the master, with only 2 remaining master-eligible nodes you risk the `split-brain- phenomenon, which will cause problems as well.

---

<div class="post-metadata">

### Author: ![RAM\_NATHAN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ram_nathan/32/50393_2.png) [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)
#### Post date: [March 13, 2020, 5:01am UTC](https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303/3 "2020-03-13T05:01:10Z")

</div>

I have configured as all are master eligible and data nodes as well. minimum\_master\_nodes set to 2. I'm in a situation where i cant use more than 3 nodes.Will that be fine??

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 10, 2020, 5:01am UTC](https://discuss.elastic.co/t/logstash-sends-to-elasticsearch-cluster-failed/223303/4 "2020-04-10T05:01:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
