# MasterNotDiscoveredException with RHEL 7 Firewall on LS 1.4.2 & ES 1.2.1

**URL:** <https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568>\
**Category:** Logstash\
**Created:** [October 20, 2015, 12:24pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568 "2015-10-20T12:24:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [October 20, 2015, 12:24pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/1 "2015-10-20T12:24:27Z")

</div>

After opening ports 9200 and 9300-9400 for TCP & UDP, I get this error from Logstash. I am running both on the same Red Hat Enterprise Linux 7.0 server and can successfully log data when the firewall (firewalld) is disabled - not long term solution.

I tried with default ES configuration and with "discovery.zen.ping.multicast.enabled: false" and "discovery.zen.ping.unicast.hosts: " set to my IP address - got same error.

Here is my logstash command with output (works when firewall is disabled):  
$ ./logstash --verbose --debug -e 'input { stdin { } } output { stdout { } elasticsearch { cluster =\> "scribe\_bld5" } }'  
Pipeline started {:level=\>:info}  
log4j, [2015-10-16T10:14:13.109] INFO: org.elasticsearch.node: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] version[1.1.1], pid[25486], build[f1585f0/2014-04-16T14:27:12Z]  
log4j, [2015-10-16T10:14:13.111] INFO: org.elasticsearch.node: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] initializing ...  
log4j, [2015-10-16T10:14:13.130] INFO: org.elasticsearch.plugins: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] loaded [], sites []  
log4j, [2015-10-16T10:14:17.472] INFO: org.elasticsearch.node: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] initialized  
log4j, [2015-10-16T10:14:17.473] INFO: org.elasticsearch.node: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] starting ...  
log4j, [2015-10-16T10:14:17.638] INFO: org.elasticsearch.transport: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] bound\_address {inet[/0:0:0:0:0:0:0:0:9301]}, publish\_address {inet[/166.17.25.142:9301]}  
log4j, [2015-10-16T10:14:47.679] WARN: org.elasticsearch.discovery: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] waited for 30s and no initial state was set by the discovery  
log4j, [2015-10-16T10:14:47.680] INFO: org.elasticsearch.discovery: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] scribe\_bld5/mn5UU6dLS8epxlrw-BAfbA  
log4j, [2015-10-16T10:14:47.698] INFO: org.elasticsearch.node: [logstash-elovftardisbld5.labs.isgs.lmco.com-25486-2010] started  
New Elasticsearch output {:cluster=\>"scribe\_bld5", :host=\>nil, :port=\>"9300-9305", :embedded=\>false, :protocol=\>"node", :level=\>:info}  
Automatic template management enabled {:manage\_template=\>"true", :level=\>:info}  
Using mapping template {:template=\>"{ "template" : "logstash-", "settings" : { "index.refresh\_interval" : "5s" }, "mappings" : { "default" : { "\_all" : {"enabled" : true}, "dynamic\_templates" : [{ "string\_fields" : { "match" : "", "match\_mapping\_type" : "string", "mapping" : { "type" : "string", "index" : "analyzed", "omit\_norms" : true, "fields" : { "raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256} } } } }], "properties" : { "@version": { "type": "string", "index": "not\_analyzed" }, "geoip" : { "type" : "object", "dynamic": true, "path": "full", "properties" : { "location" : { "type" : "geo\_point" } } } } } }}", :level=\>:info}  
Exception in thread "\>output" org.elasticsearch.discovery.MasterNotDiscoveredException: waited for [30s]  
at org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(org/elasticsearch/action/support/master/TransportMasterNodeOperationAction.java:180)  
at org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(org/elasticsearch/cluster/service/InternalClusterService.java:492)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1145)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(java/lang/Thread.java:745)

I've tried with Logstash's host/port and bind\_host/bind\_port settings (where port was 9200 and 9300) - still not getting through.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 20, 2015, 2:34pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/2 "2015-10-20T14:34:24Z")

</div>

Since you've disabled multicast on the ES side you have to point Logstash's elasticsearch output to one of the ES nodes with the `host` option.

Logstash 2.0 makes HTTP the default protocol for talking to ES. Many of the Logstash/ES connectivity issues that one can experience will disappear when using HTTP.

---

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [October 21, 2015, 12:42pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/3 "2015-10-21T12:42:59Z")

</div>

Must multicast be disabled (shouldn't matter to me)? If so must unicast hosts be enabled?

With ES config set with  
discovery.zen.ping.multicast.enabled: false  
discovery.zen.ping.unicast.hosts: ["166.17.25.142"]

And the logstash command of  
./logstash --verbose --debug -e 'input { stdin { } } output { stdout { } elasticsearch { host =\> "166.17.25.142" protocol =\> "http" } }'

Here is my output:  
Pipeline started {:level=\>:info}  
New Elasticsearch output {:cluster=\>nil, :host=\>"166.17.25.142", :port=\>"9200", :embedded=\>false, :protocol=\>"http", :level=\>:info}  
Automatic template management enabled {:manage\_template=\>"true", :level=\>:info}  
Using mapping template {:template=\>"{ "template" : "logstash-_", "settings" : { "index.refresh\_interval" : "5s" }, "mappings" : { "default" : { "\_all" : {"enabled" : true}, "dynamic\_templates" : [{ "string\_fields" : { "match" : "_", "match\_mapping\_type" : "string", "mapping" : { "type" : "string", "index" : "analyzed", "omit\_norms" : true, "fields" : { "raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256} } } } }], "properties" : { "@version": { "type": "string", "index": "not\_analyzed" }, "geoip" : { "type" : "object", "dynamic": true, "path": "full", "properties" : { "location" : { "type" : "geo\_point" } } } } } }}", :level=\>:info}  
asdf  
asdf

Faraday::TimeoutError: Timeout::Error  
call at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/adapter/net\_http.rb:56  
build\_response at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/rack\_builder.rb:139  
run\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/faraday-0.9.0/lib/faraday/connection.rb:377  
perform\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.2/lib/elasticsearch/transport/transport/http/faraday.rb:24  
call at org/jruby/RubyProc.java:271  
perform\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.2/lib/elasticsearch/transport/transport/base.rb:187  
perform\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.2/lib/elasticsearch/transport/transport/http/faraday.rb:20  
perform\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-transport-1.0.2/lib/elasticsearch/transport/client.rb:102  
perform\_request at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.2/lib/elasticsearch/api/namespace/common.rb:21  
get\_template at /opt/scribe\_1.0.1/logstash/vendor/bundle/jruby/1.9/gems/elasticsearch-api-1.0.2/lib/elasticsearch/api/actions/indices/get\_template.rb:28  
template\_exists? at /opt/scribe\_1.0.1/logstash/lib/logstash/outputs/elasticsearch/protocol.rb:132  
template\_install at /opt/scribe\_1.0.1/logstash/lib/logstash/outputs/elasticsearch/protocol.rb:21  
register at /opt/scribe\_1.0.1/logstash/lib/logstash/outputs/elasticsearch.rb:259  
each at org/jruby/RubyArray.java:1613  
outputworker at /opt/scribe\_1.0.1/logstash/lib/logstash/pipeline.rb:220  
start\_outputs at /opt/scribe\_1.0.1/logstash/lib/logstash/pipeline.rb:152

Any assistance is appreciated (may need detailed steps for this to work on RHEL 7)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 2:54pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/4 "2015-10-21T14:54:34Z")

</div>

Hmm, looks like a connection timeout. Does `curl 166.17.25.142:9200` work?

---

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [October 22, 2015, 11:41am UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/5 "2015-10-22T11:41:54Z")

</div>

No, did not work with multicast or unicast

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 22, 2015, 11:47am UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/6 "2015-10-22T11:47:27Z")

</div>

Well, sounds like you have a network issue then.

---

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [October 22, 2015, 3:00pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/7 "2015-10-22T15:00:01Z")

</div>

So is this an Elasticsearch problem (works when firewalld is disabled)?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 23, 2015, 5:47am UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/8 "2015-10-23T05:47:37Z")

</div>

If your firewall is configured to drop connections to Elasticsearch I'd say you need to adjust your firewall configuration if you want to run Elasticsearch.

---

<div class="post-metadata">

**Author:** ![mdconner](https://avatars.discourse-cdn.com/v4/letter/m/898d66/32.png) [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Post date:** [October 23, 2015, 5:39pm UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/9 "2015-10-23T17:39:14Z")

</div>

After opening port 54328, I was able to get the :"curl" command to work. This topic can be closed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/masternotdiscoveredexception-with-rhel-7-firewall-on-ls-1-4-2-es-1-2-1/32568/10 "2017-07-06T05:25:36Z")

</div>


