# Logstash trying to connect to 127.0.0.1:9200 which is not there

**URL:** <https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089>\
**Category:** Logstash\
**Created:** [September 26, 2018, 9:14pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089 "2018-09-26T21:14:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 26, 2018, 9:14pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089/1 "2018-09-26T21:14:59Z")

</div>

After setting up everything. suddenly logstash just keep trying to connect to 127.0.0.1  
my ES is running on IP address

[2018-09-26T16:09:48,981][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>256, "pipeline.batch.delay"=\>50}  
[2018-09-26T16:09:49,505][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://10.29.248.229:9200/](http://10.29.248.229:9200/)]}}  
[2018-09-26T16:09:49,505][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://127.0.0.1:9200/](http://127.0.0.1:9200/)]}}  
[2018-09-26T16:09:49,517][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://127.0.0.1:9200/](http://127.0.0.1:9200/), :path=\>"/"}  
[2018-09-26T16:09:49,519][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://10.29.248.229:9200/](http://10.29.248.229:9200/), :path=\>"/"}  
[2018-09-26T16:09:49,720][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://127.0.0.1:9200/](http://127.0.0.1:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://127.0.0.1:9200/](http://127.0.0.1:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}  
[2018-09-26T16:09:49,737][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://10.29.248.229:9200/](http://10.29.248.229:9200/)"}  
[2018-09-26T16:09:49,752][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//127.0.0.1](https://127.0.0.1)"]}  
[2018-09-26T16:09:49,825][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-09-26T16:09:49,832][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-09-26T16:09:49,838][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://10.29.248.229:9200](http://10.29.248.229:9200)"]}  
[2018-09-26T16:09:50,057][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://10.29.248.229:9200/](http://10.29.248.229:9200/)]}}  
[2018-09-26T16:09:50,058][INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://10.29.248.229:9200/](http://10.29.248.229:9200/), :path=\>"/"}  
[2018-09-26T16:09:50,063][WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=\>"[http://10.29.248.229:9200/](http://10.29.248.229:9200/)"}  
[2018-09-26T16:09:50,069][INFO][logstash.licensechecker.licensereader] ES Output version determined {:es\_version=\>6}  
[2018-09-26T16:09:50,069][WARN][logstash.licensechecker.licensereader] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-09-26T16:09:50,125][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x65177419 run\>"}

[2018-09-26T16:09:50,296][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x3353a003@/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:46 sleep\>"}  
[2018-09-26T16:09:50,357][INFO][logstash.agent] Pipelines running {:count=\>2, :running\_pipelines=\>[:main, :".monitoring-logstash"], :non\_running\_pipelines=\>[]}  
[2018-09-26T16:09:50,379][INFO][logstash.inputs.metrics] Monitoring License OK

[2018-09-26T16:09:51,075][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-09-26T16:09:54,739][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://127.0.0.1:9200/](http://127.0.0.1:9200/), :path=\>"/"}

why it is keep going to 127.0.0.1  
where is that configure? I try to look for all dir and see if there is any default one going there.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 26, 2018, 9:45pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089/2 "2018-09-26T21:45:48Z")

</div>

look at logstash config files.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 27, 2018, 1:00pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089/3 "2018-09-27T13:00:28Z")

</div>

Like I said. there is no entry that I made for 127.0.0.1 or localhost anywhere in config file.  
nor can I find it.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 27, 2018, 2:09pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089/4 "2018-09-27T14:09:13Z")

</div>

Fixed

It is weird but I added Host =\> entry on logstash conf file on output section.  
By default it should pick up host from logstash.yml file but it wasn't

Once I added this entry it stop going to 127.0.0.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 2:09pm UTC](https://discuss.elastic.co/t/logstash-trying-to-connect-to-127-0-0-1-9200-which-is-not-there/150089/5 "2018-10-25T14:09:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
