# Unable to connect to elasticstack from other machines

**URL:** <https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520>\
**Category:** Elasticsearch\
**Created:** [April 25, 2019, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520 "2019-04-25T18:42:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dhulem](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dhulem](https://discuss.elastic.co/u/Dhulem)\
**Post date:** [April 25, 2019, 6:42pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/1 "2019-04-25T18:42:12Z")

</div>

I am an elasticstack noob so sorry for the noob question. As the title says I am unable to connect to my elasticstack machine remotely, on the same subnet. I can open port 9200 locally on the machine but the server is rejecting my requests.

I found the following article, [https://www.elastic.co/guide/en/elasticsearch/reference/7.0/modules-network.html#network-interface-values](https://www.elastic.co/guide/en/elasticsearch/reference/7.0/modules-network.html#network-interface-values) which states that this is by default.

However I am unable to find any config file/yml that I can edit which has network.host location.

I assume this is why my winlogbeat data cannot make it to my server.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 26, 2019, 6:30am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/2 "2019-04-26T06:30:20Z")

</div>

The file you need to edit is the `elasticsearch.yaml` file. Depending how you installed Elasticsearch it might be in the directory you unpacked in the `config/` directory, or in `/etc/elasticsearch/` if you used one of the deb or rpm packages for installation.

---

<div class="post-metadata">

**Author:** ![Dhulem](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dhulem](https://discuss.elastic.co/u/Dhulem)\
**Post date:** [April 26, 2019, 6:12pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/3 "2019-04-26T18:12:26Z")

</div>

Sorry I did not mention I am running on windows.

I just tried installing on Linux ubuntu 19 and I can't even curl to localhost:9200

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 26, 2019, 7:52pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/4 "2019-04-26T19:52:49Z")

</div>

Elasticsearch is not started by default, you need to start it explicitely when installing the debian package.

That said, the behaviour to only listen on local network interfaces is the same under windows and linux. I am however not sure where the configuration file is placed under windows, how did you install Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Dhulem](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dhulem](https://discuss.elastic.co/u/Dhulem)\
**Post date:** [April 26, 2019, 8:07pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/5 "2019-04-26T20:07:47Z")

</div>

I installed with the MSI installer.

It is installed under the default locations.

BIN = C:\Program Files\Elastic\Elasticsearch\7.0.0  
Config = C:\ProgramData\Elastic\Elasticsearch

This is my elasticsearch.yml file, i just added network.host: after watching and reading more.

bootstrap.memory\_lock: false  
cluster.name: elasticsearch  
http.port: 9200  
node.data: true  
node.ingest: true  
node.master: true  
node.max\_local\_storage\_nodes: 1

node.name: GRFSEARCH  
path.data: C:\ProgramData\Elastic\Elasticsearch\data  
path.logs: C:\ProgramData\Elastic\Elasticsearch\logs  
network.host: 0.0.0.0  
transport.tcp.port: 9300  
xpack.license.self\_generated.type: basic  
xpack.security.enabled: false

I can ping from different computer without issue. Windows firewall is turned off I also tried opening port 9200 when the firewall was enabled.

I can get to [http://localhost:9200](http://localhost:9200) without issue.

---

<div class="post-metadata">

**Author:** ![kclubb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kclubb/32/45138_2.png) [@kclubb](https://discuss.elastic.co/u/kclubb)\
**Post date:** [April 26, 2019, 8:16pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/6 "2019-04-26T20:16:00Z")

</div>

I have the same problem: Windows 2016, firewall off, works local but not remote.

---

<div class="post-metadata">

**Author:** ![Dhulem](https://avatars.discourse-cdn.com/v4/letter/d/f04885/32.png) [@Dhulem](https://discuss.elastic.co/u/Dhulem)\
**Post date:** [April 26, 2019, 8:16pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/7 "2019-04-26T20:16:35Z")

</div>

I think I just found it for elasticsearch. Add http.host: 0.0.0.0 to the yml file.

---

<div class="post-metadata">

**Author:** ![kclubb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kclubb/32/45138_2.png) [@kclubb](https://discuss.elastic.co/u/kclubb)\
**Post date:** [April 26, 2019, 8:26pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/8 "2019-04-26T20:26:30Z")

</div>

that works for me too! thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 8:35pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticstack-from-other-machines/178520/9 "2019-05-24T20:35:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
