# Logstash within docker container trying to connect to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335>\
**Category:** Logstash\
**Created:** [April 23, 2017, 8:20pm UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335 "2017-04-23T20:20:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![holt](https://avatars.discourse-cdn.com/v4/letter/h/9fc29f/32.png) [@holt](https://discuss.elastic.co/u/holt)\
**Post date:** [April 23, 2017, 8:20pm UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335/1 "2017-04-23T20:20:45Z")

</div>

There was a similar post on this, but the replies have been deleted:

When I run a elasticsearch 5.3.1 from a docker container it tries to connect to elasticsearch even though my pipeline only has a udp port as the output. My Dockerfile has:

RUN rm -f /usr/share/logstash/pipeline/\*

as the command right after FROM (specifying 5.3.1)

I think that would get rid of all pipeline config files.

I then

ADD my\_pipeline/ /usr/share/logstash/pipeline/

I can see my pipeline being executed correctly, but logstash is also stuck trying to connect to elasticsearch, which I don't need. How can this behavior be changed?  
Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335/2 "2017-04-24T05:27:32Z")

</div>

If you increase Logstash's log level it should give you more clues about what configuration it loads and where that configuration comes from.

---

<div class="post-metadata">

**Author:** ![holt](https://avatars.discourse-cdn.com/v4/letter/h/9fc29f/32.png) [@holt](https://discuss.elastic.co/u/holt)\
**Post date:** [April 24, 2017, 2:51pm UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335/3 "2017-04-24T14:51:05Z")

</div>

So the theory is that xpack is somehow bundled with the docker logstash image. I don't know much about xpack, but 1: is that true?  
2: why would that not be documented?  
3: how does bundling xpack cause an assumption that logstash should be connecting to an elasticsearch service?

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2017, 3:01pm UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335/4 "2017-04-24T15:01:37Z")

</div>

Poking around in [https://github.com/elastic/logstash-docker](https://github.com/elastic/logstash-docker) it looks like it by default configures X-Pack monitoring to Elasticsearch (via logstash.yml) but the pipeline only contains a stdout output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2017, 3:10pm UTC](https://discuss.elastic.co/t/logstash-within-docker-container-trying-to-connect-to-elasticsearch/83335/5 "2017-05-22T15:10:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
