# Problems getting started w/ log stash and elasticsearch

**URL:** <https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797>\
**Category:** Logstash\
**Created:** [May 17, 2015, 4:01am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797 "2015-05-17T04:01:35Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcc/32/44833_2.png) [@jcc](https://discuss.elastic.co/u/jcc)\
**Post date:** [May 17, 2015, 4:01am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/1 "2015-05-17T04:01:35Z")

</div>

Hello,

I just installed elasticsearch and logstash on a Mac (Java 1.7). Elasticsearch seems to be running as expected and while logstash works with the simplest examples, it fails when I try to connect it to elastic search:

```
puma:logstash-1.5.0 jcc$ logstash -e 'input { stdin { } } output { elasticsearch { host => localhost } }'

testing 1,2,3...
log4j, [2015-05-16T21:39:32.070] WARN: org.elasticsearch.discovery: [logstash- puma.local-89867-2010] waited for 30s and no initial state was set by the discovery
Exception in thread ">output" org.elasticsearch.discovery.MasterNotDiscoveredException: waited for [30s]
at org.elasticsearch.action.support.master.TransportMasterNodeOperationAction$3.onTimeout(org/elasticsearch/action/support/master/TransportMasterNodeOperationAction.java:180)
at org.elasticsearch.cluster.service.InternalClusterService$NotifyTimeout.run(org/elasticsearch/cluster/service/InternalClusterService.java:492)
at java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:615)
at java.lang.Thread.run(java/lang/Thread.java:745)

```

This log stash 1.5.0 and elastic search 1.5.2 on OS X 10.9.5 w/ JDK 1.7.0\_60.

Can anyone point out what I'm missing here?

Thanks!

--john

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2015, 11:40pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/2 "2015-05-17T23:40:29Z")

</div>

Do you know ES has started, have you tried checking the status?

---

<div class="post-metadata">

**Author:** ![jcc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcc/32/44833_2.png) [@jcc](https://discuss.elastic.co/u/jcc)\
**Post date:** [May 18, 2015, 3:33am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/3 "2015-05-18T03:33:08Z")

</div>

Thanks for your reply Mark. Yes, ES is running and seems to respond normally to http input via cURL. Using the same versions of ES and LogStash, I was able to run the same example on linux.

—john

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 18, 2015, 4:43am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/4 "2015-05-18T04:43:14Z")

</div>

This could be a misconfiguration problem.

Try adding protocol =\> http to your output and trying again.

---

<div class="post-metadata">

**Author:** ![jcc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcc/32/44833_2.png) [@jcc](https://discuss.elastic.co/u/jcc)\
**Post date:** [May 20, 2015, 3:28am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/5 "2015-05-20T03:28:01Z")

</div>

thanks for the suggestion, but

```
echo "hello world" | ./bin/logstash -e 'input { stdin { } } output { elasticsearch { host => localhost protocol => http } }'

```

still doesn't seem to be getting anything over to ES. Any special considerations for OS X that I should be aware of?

--john

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 20, 2015, 5:30am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/6 "2015-05-20T05:30:44Z")

</div>

That command should work. Try enabling verbose logging by passing `--verbose` or even `--debug` to get Logstash to log more information about what it's doing.

---

<div class="post-metadata">

**Author:** ![Priyanku\_konar](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@Priyanku\_konar](https://discuss.elastic.co/u/Priyanku_konar)\
**Post date:** [May 27, 2015, 5:27pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/7 "2015-05-27T17:27:05Z")

</div>

## I have a similar issue as above while connecting to elasticsearch from logstash using stdin input ,

## attaching the dump with --debug flag in logstash

Logstash startup completed  
send this message from stdin to Elasticsearch  
←[36moutput received {:event=\>{"message"=\>"send this message from stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=

> "human", "inputsource"=\>"stdin", "host"=\>"PriyankuK-MSL"}, :level=\>:debug, :file=\>"(eval)", :line=\>"25", :method=\>"output\_func"}←[0m  
> 2015-05-27T17:08:37.742Z PriyankuK-MSL send this message from stdin to Elasticsearch  
> ←[36mFlushing output {:outgoing\_count=\>1, :time\_since\_last\_flush=\>50.355, :outgoing\_events=\>{nil=\>[["index", {:\_id=\>nil, :\_index=\>"logstash-2015.05.27", :\_type=  
> "human", :\_routing=\>nil}, #\<LogStash::Event:0x728bd4 @metadata\_accessors=#\<LogStash::Util::Accessors:0x777dffd4 @store={"retry\_count"=\>0}, @lut={}\>, @cancelled  
> =false, @data={"message"=\>"send this message from stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "input  
> source"=\>"stdin", "host"=\>"PriyankuK-MSL"}, @metadata={"retry\_count"=\>0}, @accessors=#\<LogStash::Util::Accessors:0x18ec3689 @store={"message"=\>"send this messag  
> e from stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "inputsource"=\>"stdin", "host"=\>"PriyankuK-MSL"},  
> @lut={"type"=\>[{"message"=\>"send this message from stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "inp  
> utsource"=\>"stdin", "host"=\>"PriyankuK-MSL"}, "type"], "inputsource"=\>[{"message"=\>"send this message from stdin to Elasticsearch\r", "@version"=\>"1", "@timest  
> amp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "inputsource"=\>"stdin", "host"=\>"PriyankuK-MSL"}, "inputsource"], "host"=\>[{"message"=\>"send this message fro  
> m stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "inputsource"=\>"stdin", "host"=\>"PriyankuK-MSL"}, "hos  
> t"], "message"=\>[{"message"=\>"send this message from stdin to Elasticsearch\r", "@version"=\>"1", "@timestamp"=\>"2015-05-27T17:08:37.742Z", "type"=\>"human", "in  
> putsource"=\>"stdin", "host"=\>"PriyankuK-MSL"}, "message"]}\>\>]]}, :batch\_timeout=\>1, :force=\>nil, :final=\>nil, :level=\>:debug, :file=\>"/Priyanku/elasticsearch/lo  
> gstash/logstash-1.5.0/vendor/bundle/jruby/1.9/gems/stud-0.0.19/lib/stud/buffer.rb", :line=\>"207", :method=\>"buffer\_flush"}←[0m  
> ←[36mSending bulk of actions to client[0]: localhost {:level=\>:debug, :file=\>"/Priyanku/elasticsearch/logstash/logstash-1.5.0/vendor/bundle/jruby/1.9/gems/logst  
> ash-output-elasticsearch-0.2.4-java/lib/logstash/outputs/elasticsearch.rb", :line=\>"461", :method=\>"flush"}←[0m  
> ←[31mGot error to send bulk of actions to elasticsearch server at localhost : blocked by: [SERVICE\_UNAVAILABLE/1/state not recovered / initialized];[SERVICE\_UNA  
> VAILABLE/2/no master]; {:level=\>:error, :file=\>"/Priyanku/elasticsearch/logstash/logstash-1.5.0/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-0.2.4  
> -java/lib/logstash/outputs/elasticsearch.rb", :line=\>"464", :method=\>"flush"}←[0m  
> ←[33mFailed to flush outgoing items {:outgoing\_count=\>1, :exception=\>org.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE\_UNAVAILABLE/1/s  
> tate not recovered / initialized];[SERVICE\_UNAVAILABLE/2/no master];, :backtrace=\>["org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(org/ela  
> sticsearch/cluster/block/ClusterBlocks.java:151)", "org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(org/elasticsearch/cluster/block/Cl  
> usterBlocks.java:141)", "org.elasticsearch.action.bulk.TransportBulkAction.executeBulk(org/elasticsearch/action/bulk/TransportBulkAction.java:210)", "org.elasti  
> csearch.action.bulk.TransportBulkAction.access$000(org/elasticsearch/action/bulk/TransportBulkAction.java:73)", "org.elasticsearch.action.bulk.TransportBulkActi  
> on$1.onFailure(org/elasticsearch/action/bulk/TransportBulkAction.java:148)", "org.elasticsearch.action.support.TransportAction$ThreadedActionListener$2.run(org/  
> elasticsearch/action/support/TransportAction.java:137)", "java.util.concurrent.ThreadPoolExecutor.runWorker(java/util/concurrent/ThreadPoolExecutor.java:1142)",  
> "java.util.concurrent.ThreadPoolExecutor$Worker.run(java/util/concurrent/ThreadPoolExecutor.java:617)", "java.lang.Thread.run(java/lang/Thread.java:745)"], :le  
> vel=\>:warn, :file=\>"/Priyanku/elasticsearch/logstash/logstash-1.5.0/vendor/bundle/jruby/1.9/gems/stud-0.0.19/lib/stud/buffer.rb", :line=\>"231", :method=\>"buffer  
> \_flush"}←[0m

---

<div class="post-metadata">

**Author:** ![Priyanku\_konar](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@Priyanku\_konar](https://discuss.elastic.co/u/Priyanku_konar)\
**Post date:** [May 27, 2015, 5:30pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/8 "2015-05-27T17:30:58Z")

</div>

## below is the logstash conf file

input {  
stdin {  
add\_field =\> {inputsource =\> "stdin"} # hash (optional), default: {}  
#codec =\> ... # codec (optional), default: "plain"  
#debug =\> ... # boolean (optional), default: false  
#tags =\> ... # array (optional)  
type =\> "human" # string (optional)  
}  
}

output {  
stdout {  
}

elasticsearch {  
host =\> localhost

}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 28, 2015, 7:11am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/9 "2015-05-28T07:11:32Z")

</div>

@Priyanku_konar please start your own thread for your question.

---

<div class="post-metadata">

**Author:** ![jpendry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpendry/32/634_2.png) [@jpendry](https://discuss.elastic.co/u/jpendry)\
**Post date:** [June 11, 2015, 9:51pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/10 "2015-06-11T21:51:41Z")

</div>

@jcc I was able to resolve a similar problem by adding the name of my elasticsearch cluster to the config file:

```auto
input { stdin { } }
output {
  elasticsearch {
    host => localhost
    cluster => elasticsearch_brew
  }
}

```

I suspect the problem has something to do with the default Elasticsearch configuration that results from installing Elasticsearch via Homebrew, but I haven't dug in much further.

Hope this isn't too late and helps!

---

<div class="post-metadata">

**Author:** ![OzWookiee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ozwookiee/32/3633_2.png) [@OzWookiee](https://discuss.elastic.co/u/OzWookiee)\
**Post date:** [July 9, 2015, 11:04pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/11 "2015-07-09T23:04:43Z")

</div>

I had to do the same thing when I was initially playing with ELK together.

---

<div class="post-metadata">

**Author:** ![Tory\_Berra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tory_berra/32/4227_2.png) [@Tory\_Berra](https://discuss.elastic.co/u/Tory_Berra)\
**Post date:** [August 17, 2015, 3:00pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/12 "2015-08-17T15:00:45Z")

</div>

Had to do same thing. Took a while to figure out from the lack of a useful error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797/13 "2017-07-06T05:31:46Z")

</div>


