# Unable to start logstash service error code in log

**URL:** <https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812>\
**Category:** Logstash\
**Created:** [April 4, 2018, 7:51pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812 "2018-04-04T19:51:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 4, 2018, 7:51pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/1 "2018-04-04T19:51:01Z")

</div>

Hi there,

When I try to start logstash "systemctl start logstash" I see these error messages in the log:

[2018-04-04T21:46:39,189][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://127.0.0.1:9200/](http://127.0.0.1:9200/)"}  
[2018-04-04T21:46:43,902][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[https://elasticsearch](https://elasticsearch):changeme@:9200/, :path=\>"/"}  
[2018-04-04T21:46:43,909][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[https://elasticsearch](https://elasticsearch):changeme@:9200/", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[https://elasticsearch](https://elasticsearch):changeme@:9200/][Manticore::ClientProtocolException] URI does not specify a valid host name: https:/"}  
[2018-04-04T21:46:48,912][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[https://elasticsearch](https://elasticsearch):changeme@:9200/, :path=\>"/"}

---

<div class="post-metadata">

**Author:** ![camarar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camarar/32/20476_2.png) [@camarar](https://discuss.elastic.co/u/camarar)\
**Post date:** [April 5, 2018, 12:50am UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/2 "2018-04-05T00:50:18Z")

</div>

Hi Erik,

Could you post some informations?

- What version of Logstash?
- How did you install Logstash (e.g., package from [elastic.co](http://elastic.co), from source, deb or rpm package etc)?
- What is your operating system?

Could you post your output config from logstash config file?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 5, 2018, 1:22am UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/3 "2018-04-05T01:22:13Z")

</div>

> [@heskez](#):
>
> ```auto
> https://elasticsearch:changeme@:9200/
> 
> ```

The above is not a valid URL; it contains no hostname. Do you have a module configured incorrectly your `logstash.yml`?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 5, 2018, 12:24pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/4 "2018-04-05T12:24:01Z")

</div>

Thank you both for the reply. Considering questions about versions and operating system:

- Logstash version 6.2.3
- install base is a yum repo "baseurl=https://artifacts.elastic.co/packages/6.x/yum"
- OS is CentOS Linux release 7.4.1708 (Core)

Output config:

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

logstash.yml:

Everything is commented out except:

path.data: /var/lib/logstash  
path.logs: /var/log/logstash

It makes sense that the URL is not valid. But I can't find where it's defined?

---

<div class="post-metadata">

**Author:** ![Arpit\_Gulati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arpit_gulati/32/48349_2.png) [@Arpit\_Gulati](https://discuss.elastic.co/u/Arpit_Gulati)\
**Post date:** [April 5, 2018, 1:07pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/5 "2018-04-05T13:07:27Z")

</div>

check the logs of filebeat or run filebeat -e -d "\*" command on the terminal.  
check whether logstash is getting input or not. and also the check the pattern in that output logstash config file .

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 5, 2018, 1:31pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/6 "2018-04-05T13:31:53Z")

</div>

Hello, filebeat doesn't return anything, no matter what command for example "filebeat version" nothing returned. It look's like filebeat needs reinstalling. Is there a way to bypass filebeat in the logstash output?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 5, 2018, 6:35pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/7 "2018-04-05T18:35:51Z")

</div>

Eh, actually I've found another output file in /logstash/conf.d/

output {  
elasticsearch {  
hosts =\> ["https:localhost:5601"]  
user =\> "elasticsearch"  
password =\> "changeme"  
index =\> "syslog-%{+YYYY.MM.dd}"  
document\_type =\> "system\_logs"  
}  
stdout { codec =\> rubydebug }  
}

Notice the typo @hosts 😊

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 5, 2018, 8:57pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/8 "2018-04-05T20:57:52Z")

</div>

I took out the user and password from the config file and changed https into http.

No the error message I get is : [[http://localhost:5601/](http://localhost:5601/)][Manticore::SocketException] Connection refused

Next I do : curl [http://localhost:9200](http://localhost:9200) all good..

---

<div class="post-metadata">

**Author:** ![camarar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camarar/32/20476_2.png) [@camarar](https://discuss.elastic.co/u/camarar)\
**Post date:** [April 5, 2018, 9:27pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/9 "2018-04-05T21:27:16Z")

</div>

@heskez this url for hosts is wrong because this url is the Kibana.  
On logstash output is necessary to config an elasticsearch url valid like hosts =\> ["localhost:9200"].

I suggest you change the hosts for hosts =\> ["localhost:9200"] in this logstash config file and try again.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 5, 2018, 10:29pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/10 "2018-04-05T22:29:07Z")

</div>

Changed the port to 9200 and done no more error messages. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2018, 10:29pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-service-error-code-in-log/126812/11 "2018-05-03T22:29:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
