# Logstash with X-Pack

**URL:** <https://discuss.elastic.co/t/logstash-with-x-pack/90230>\
**Category:** Logstash\
**Created:** [June 21, 2017, 8:51am UTC](https://discuss.elastic.co/t/logstash-with-x-pack/90230 "2017-06-21T08:51:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuanpembual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuanpembual/32/18893_2.png) [@tuanpembual](https://discuss.elastic.co/u/tuanpembual)\
**Post date:** [June 21, 2017, 8:51am UTC](https://discuss.elastic.co/t/logstash-with-x-pack/90230/1 "2017-06-21T08:51:02Z")

</div>

Dear All,

I have elk stack with difference machine  
[Client - beat] - [VM1 - Logstash | 192.168.33.101] - [VM2 - ES and Kibana | 192.168.33.102]

I have install x-pack plugin for logstash, es, and kibana.  
and have success test curl with this command.

`curl --user logstash_system:changeme '192.168.33.102:9200'`

but if running from logstash. if show error, logstash send log to localhost:9200 instead send to 192.168.33.102:9200.

Here the error:  
[2017-06-21T08:15:41,552][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://logstash\_system:xxxxxx@localhost:9200/](http://logstash_system:xxxxxx@localhost:9200/), :path=\>"/"}  
[2017-06-21T08:15:41,560][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>#\<URI::HTTP:0x790d79b0 URL:[http://logstash\_system:xxxxxx@localhost:9200/](http://logstash_system:xxxxxx@localhost:9200/)\>, :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://logstash\_system:xxxxxx@localhost:9200/](http://logstash_system:xxxxxx@localhost:9200/)][Manticore::SocketException] Connection refused (Connection refused)"}

Here my configure:

```
input {
  beats {
    port => 5044
  }
}
output {
  elasticsearch { 
    hosts => ["192.168.33.102:9200"]
    user => logstash_internal
    password => changeme
  }
  stdout {
    codec => rubydebug 
  }
}

```

can someone give me clue?

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 24, 2017, 7:00pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack/90230/2 "2017-06-24T19:00:16Z")

</div>

The username is different too (logstash\_system vs. logstash\_internal). Are you really running Logstash with the configuration you think?

---

<div class="post-metadata">

**Author:** ![tuanpembual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuanpembual/32/18893_2.png) [@tuanpembual](https://discuss.elastic.co/u/tuanpembual)\
**Post date:** [June 26, 2017, 12:36pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack/90230/3 "2017-06-26T12:36:24Z")

</div>

yes. I put right crendential. But thanks for reply my thread.

I solved this issue by disable health check in conf/logstash.yml  
just put this code in end of file;

`xpack.monitoring.enabled: false`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 12:36pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack/90230/4 "2017-07-24T12:36:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
