# Problems getting started ELK centos7

**URL:** <https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233>\
**Category:** Logstash\
**Created:** [June 24, 2015, 6:20am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233 "2015-06-24T06:20:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![eheb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eheb/32/3450_2.png) [@eheb](https://discuss.elastic.co/u/eheb)\
**Post date:** [June 24, 2015, 6:20am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/1 "2015-06-24T06:20:20Z")

</div>

I am on centos7 minima version on a vm virtualbox, @IP=10.82.136.52 in local network. I have no public IP 192.168.xxx, no FQDN. I install all ELK on this server with default config but not ngnix,

- elasticsearch wget [http://localhost:9200](http://localhost:9200) =\> connection refused
- kibana wget [http://localhost:5601](http://localhost:5601) =\> connection refused
- logstash : not started. how to get log files and put debug mode  
Would you please helping me to solve these issues. Best regards.

---

<div class="post-metadata">

**Author:** ![eheb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eheb/32/3450_2.png) [@eheb](https://discuss.elastic.co/u/eheb)\
**Post date:** [June 24, 2015, 6:35am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/2 "2015-06-24T06:35:47Z")

</div>

I follow this tutorial

> **[How To Install Elasticsearch, Logstash, and Kibana (ELK Stack) on CentOS 7 |...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-centos-7)**
>
> In this tutorial, we will go over the installation of the Elasticsearch ELK Stack on CentOS 7—that is, Elasticsearch 2.1.x, Logstash 2.1.x, and Kibana 4.3.x. We will also show you how to configure it to gather and visualize the syslogs of your...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 24, 2015, 7:20am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/3 "2015-06-24T07:20:41Z")

</div>

Are the processes actually running? Are they listening to the loopback interface? Is there any firewall that might be blocking the traffic?

---

<div class="post-metadata">

**Author:** ![eheb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eheb/32/3450_2.png) [@eheb](https://discuss.elastic.co/u/eheb)\
**Post date:** [June 25, 2015, 8:16am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/4 "2015-06-25T08:16:07Z")

</div>

nginx is not running, firewall-cmd is not running. And i define proxy config for all ressources : wget, bash-profile, .... I except use of proxy for : localhost, 127.0.0.1 and 10.82.136.52 my ip adress of my centos7 machine

---

<div class="post-metadata">

**Author:** ![vassav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassav/32/3430_2.png) [@vassav](https://discuss.elastic.co/u/vassav)\
**Post date:** [June 25, 2015, 9:26am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/5 "2015-06-25T09:26:19Z")

</div>

You can try my test ELK for example on VirtualBox Centos6.5:

eth0 inet addr:192.168.xxx.xxx - bridge for inet  
eth1 inet addr:10.1.1.9 - virtual adapter for local

elasticsearch 1.6:  
elasticsearch.yml  
cluster.name: test  
node.name: "elk"

Can see in Chrome via [http://192.168.xxx.xxx:9200/](http://192.168.xxx.xxx:9200/) or curl -XGET '10.1.1.9:9200/'

Kibana4:  
kibana.yml  
port: 5601  
host: "0.0.0.0"  
elasticsearch\_url: "[http://10.1.1.9:9200](http://10.1.1.9:9200)"

Can see in Chrome via [http://192.168.xxx.xxx:5601/](http://192.168.xxx.xxx:5601/) or curl -XGET '10.1.1.9:5601'

nginx.conf - add  
log\_format logstash '$remote\_addr [$time\_local] "$request" $status $body\_bytes\_sent "$http\_referer" "$http\_user\_agent" $request\_time';  
access\_log /var/log/nginx/access2.log logstash;

logstash-nginx3.conf  
input {  
file {  
path =\> "/var/log/nginx/access2.log"  
type =\> syslog  
}  
}

filter {  
mutate {  
replace =\> { "type" =\> "nginx\_access" }  
}

grok {  
match =\> ["message", "%{IPORHOST:clientip} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent} %{NUMBER:request\_time:float}" ]  
}

date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
}

geoip {  
source =\> "clientip"  
}  
}  
elasticsearch {  
cluster =\> "test"  
protocol =\> "http"  
host =\> "10.1.1.9"  
port =\> "9200"  
index =\> "logstash-%{+YYYY.MM.dd}"  
workers =\> 5  
}  
stdout { codec =\> rubydebug }  
}

interesting way for finding problem: try in shell /opt/logstash/bin/logstash -f ./logstash-nginx3.conf --debug

---

<div class="post-metadata">

**Author:** ![eheb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eheb/32/3450_2.png) [@eheb](https://discuss.elastic.co/u/eheb)\
**Post date:** [June 26, 2015, 1:02pm UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/6 "2015-06-26T13:02:48Z")

</div>

Thanks you for your help. I resume the situation : I follow the tutorial : [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-4-on-centos-7](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-4-on-centos-7)  
I am on centos7 minima version on a vm virtualbox, @IP=10.82.136.52 in local network. I have no public IP 192.168.xxx, no FQDN. I instal all ELK on this server with default config but no ngnix, no firewall-cmd (not started)

- elasticsearch 1.4.4 : [http://10.82.136.52:9200](http://10.82.136.52:9200) =\> json output. log : zen-disco-join(elected as master) config = network.host=10.xxxxxx  
-logstash : SERVICE\_UNAVAILABLE no master log.err : INFO started
- kibana [http://10.xxxxx:5601](http://10.xxxxx:5601) =\> Settings/Indices config index pattern page with NO DEFAULT INDEX PATTERN  
conf= host : "0.0.0.0" elasticsearch\_url:"[http://10.xxxx:9200](http://10.xxxx:9200)"  
log =\> html response= statuscode 404 GET /logstatsh-\*/\_mapping
- logstash-forwarder : connected 10.xxx:5000  
Would you please helping me to solve these issues ? We are so near of the good results 🙂 Best regards.

---

<div class="post-metadata">

**Author:** ![vassav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vassav/32/3430_2.png) [@vassav](https://discuss.elastic.co/u/vassav)\
**Post date:** [June 29, 2015, 12:39pm UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/7 "2015-06-29T12:39:13Z")

</div>

no ideas.

Elasticsearch looks run ok in single node mode,  
Check status in :9200/\_cluster/health?human&pretty  
and :9200/\_cat/nodes?v&ts=0  
If it you first and single Elasticsearch then change (if not comment on)

```
index.number_of_replicas: 1 

```

logstash - check exists and rights of /var/log/logstash.  
1.4.x - can have got chroot problems in /etc/init/logstash, check in bash under root.

kibana - sea logs. May be index creating only in browsers)

```
"Unable to connect to elasticsearch"

```

must has been changing to

```
Found kibana index
Listening on 0.0.0.0:5601

```

check proxy, may be needed

```
unset http_proxy
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/problems-getting-started-elk-centos7/24233/8 "2017-07-06T05:36:09Z")

</div>


