# Logstash throwing 406 when running as Service on Linux

**URL:** <https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976>\
**Category:** Logstash\
**Created:** [April 2, 2019, 11:44am UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976 "2019-04-02T11:44:10Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![kumarvivek633](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumarvivek633/32/43303_2.png) [@kumarvivek633](https://discuss.elastic.co/u/kumarvivek633)\
**Post date:** [April 2, 2019, 11:44am UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/1 "2019-04-02T11:44:11Z")

</div>

I had setup Elk on Linux box with Filebeat as data shipper. I am getting very weird issue there. When i am running logstash as service with service logstash start in that case it is getting the data from file beat but throwing below exception while pushing to ES.

`{:timestamp=>"2019-04-02T06:08:36.447000-0400", :message=>"Attempted to send a bulk request to Elasticsearch configured at '[\"http://localhost:9200/\"]', but an error occurred and it failed! Are you sure you can reach elasticsearch from this machine using the configuration provided?", :error_message=>"[406] {\"error\":\"Content-Type header [text/plain; charset=ISO-8859-1] is not supported\",\"status\":406}", :error_class=>"Elasticsearch::Transport::Transport::Errors::NotAcceptable", :backtrace=>["/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/base.rb:146:in`\_\_raise\_transport\_error'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/base.rb:256:in `perform_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/transport/http/manticore.rb:54:in`perform\_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.15/lib/elasticsearch/transport/client.rb:125:in `perform_request'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.15/lib/elasticsearch/api/actions/bulk.rb:87:in`bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http\_client.rb:53:in `non_threadsafe_bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http_client.rb:38:in`bulk'", "org/jruby/ext/thread/Mutex.java:149:in `synchronize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/http_client.rb:38:in`bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/common.rb:163:in `safe_bulk'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/common.rb:101:in`submit'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/common.rb:86:in `retrying_submit'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/common.rb:29:in`multi\_receive'", "org/jruby/RubyArray.java:1653:in `each_slice'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.5.5-java/lib/logstash/outputs/elasticsearch/common.rb:28:in`multi\_receive'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/output\_delegator.rb:130:in `worker_multi_receive'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/output_delegator.rb:114:in`multi\_receive'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:293:in `output_batch'", "org/jruby/RubyHash.java:1342:in`each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:293:in `output_batch'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:224:in`worker\_loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:193:in `start_workers'"], :client_config=>{:hosts=>["http://localhost:9200/"], :ssl=>nil, :transport_options=>{:socket_timeout=>0, :request_timeout=>0, :proxy=>nil, :ssl=>{}}, :transport_class=>Elasticsearch::Transport::Transport::HTTP::Manticore, :logger=>nil, :tracer=>nil, :reload_connections=>false, :retry_on_failure=>false, :reload_on_failure=>false, :randomize_hosts=>false}, :level=>:error}`

But when i am running that as foregroud service /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf then it is able to write data to ES.

ElK version is as follows:

Elastic Search: 6.4.0  
Kibana : 6.4.0  
Logstash: 6.4.0  
Filebeat: 6.6.1

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 2, 2019, 1:07pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/2 "2019-04-02T13:07:52Z")

</div>

What does the output configuration look like?

---

<div class="post-metadata">

**Author:** ![kumarvivek633](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumarvivek633/32/43303_2.png) [@kumarvivek633](https://discuss.elastic.co/u/kumarvivek633)\
**Post date:** [April 2, 2019, 1:31pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/3 "2019-04-02T13:31:36Z")

</div>

Here is my output configuration..

output {

```
elasticsearch {
hosts => ["http://localhost:9200"]
index => "%{[fields][application]}-%{+YYYY.MM.dd}"

```

}

Also its working without any issue when i run in foreground from /usr/share/logstash/bin.

---

<div class="post-metadata">

**Author:** ![RogMay](https://avatars.discourse-cdn.com/v4/letter/r/a88e4f/32.png) [@RogMay](https://discuss.elastic.co/u/RogMay)\
**Post date:** [April 2, 2019, 4:08pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/4 "2019-04-02T16:08:26Z")

</div>

Hi, I'm experiencing exactly the same behaviour on Centos 7. Logstash and Filebeat latest versions freshly installed. Test by configuring filebeat to monitor simple log file and send to logstash. Logstash errors with error\_message [406] as described by kumarvivek633

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [April 2, 2019, 10:16pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/5 "2019-04-02T22:16:12Z")

</div>

What user is the daemon starting as? And what user are you running the foreground test as? Do you have SELinux enabled?

---

<div class="post-metadata">

**Author:** ![RogMay](https://avatars.discourse-cdn.com/v4/letter/r/a88e4f/32.png) [@RogMay](https://discuss.elastic.co/u/RogMay)\
**Post date:** [April 3, 2019, 7:34am UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/6 "2019-04-03T07:34:02Z")

</div>

On my system, Logstash daemon is running under logstash userid. Input test is from Filebeat, currently installed on the same machine, running as root. SELinux is disabled

---

<div class="post-metadata">

**Author:** ![kumarvivek633](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumarvivek633/32/43303_2.png) [@kumarvivek633](https://discuss.elastic.co/u/kumarvivek633)\
**Post date:** [April 3, 2019, 10:08am UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/7 "2019-04-03T10:08:21Z")

</div>

I fixed the issue. Actually it was a very basic problem. There were two instances of logstash installed on the server and the service was pointing to older version. So i fixed that.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [April 3, 2019, 12:49pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/8 "2019-04-03T12:49:49Z")

</div>

Have you tried running it it the foreground as logstash? Give logstash a shell so you can su to it.

---

<div class="post-metadata">

**Author:** ![RogMay](https://avatars.discourse-cdn.com/v4/letter/r/a88e4f/32.png) [@RogMay](https://discuss.elastic.co/u/RogMay)\
**Post date:** [April 3, 2019, 3:24pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/9 "2019-04-03T15:24:31Z")

</div>

I did, but I've found the problem - I had an older version of Logstash communicating with a newer version of Elasticsearch. Re installed and its now working.  
Thanks for your replies and assistance 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2019, 3:24pm UTC](https://discuss.elastic.co/t/logstash-throwing-406-when-running-as-service-on-linux/174976/10 "2019-05-01T15:24:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
