# Node logstash join to the ELK cluster

**URL:** <https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917>\
**Category:** Logstash\
**Created:** [April 20, 2016, 1:50pm UTC](https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917 "2016-04-20T13:50:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [April 20, 2016, 1:50pm UTC](https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917/1 "2016-04-20T13:50:52Z")

</div>

Hello Guys,  
I'm using the last ELK version and the last Logstash version.  
I'm checking the ELK cluster with Kopf and Elastic-HQ and with both plugins I can see my 4 data ELK nodes.  
I created a new server with Logstash and I am trying see this server in the plugins Kopf and HQ, with the following steps:

1- I created a new file in the logstash server named elasticsearch.yaml in the path :  
/etc/logstash/elasticsearch.yaml  
The content is:

```
cluster.name: elasticsearch.xxx.com
node.name: logstash-01
node.data: false
node.master: false
discovery.zen.ping.multicast.enabled: false
discovery.zen.ping.unicast.hosts: ["node-01", "node-02", "node-03", "node-04", "localhost"]

```

2- In the file /etc/init.d/logstash , I added the following line:

```
`LS_JAVA_OPTS="-Djava.io.tmpdir=${LS_HOME} -Des.config=/etc/logstash/elasticsearch.yml"`

```

3- I restarted my 4 ELK nodes and I added the discovery.zen.unicast.hosts the node of Logstash.

But it doesn't work.

Some one knows who can see the server with Elasticsearch with Plugins Kof or HQ.

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2016, 1:57pm UTC](https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917/2 "2016-04-20T13:57:03Z")

</div>

Nowadays Logstash doesn't join the ES cluster with the elasticsearch output plugin. It only uses HTTP. If you really want the legacy behavior you need to use the elasticsearch\_java plugin.

---

<div class="post-metadata">

**Author:** ![Juan\_Andres\_Ramirez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_andres_ramirez/32/9467_2.png) [@Juan\_Andres\_Ramirez](https://discuss.elastic.co/u/Juan_Andres_Ramirez)\
**Post date:** [April 20, 2016, 6:54pm UTC](https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917/3 "2016-04-20T18:54:18Z")

</div>

Understood thank you Magnus.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/node-logstash-join-to-the-elk-cluster/47917/4 "2017-07-06T05:01:22Z")

</div>


