# Xpack and Logstas: Elasticsearch Unreachable: \[http://localhost:9200/\]

**URL:** <https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048>\
**Category:** Elasticsearch\
**Created:** [November 24, 2017, 3:27pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048 "2017-11-24T15:27:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [November 24, 2017, 3:27pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/1 "2017-11-24T15:27:51Z")

</div>

Hi

I installed x-pack on logstash. logstash was running successfully before x-pack. After installation of x-pack, I disable seucirty in elasticseach and logstash by using below command in .yml file  
xpack.security.enabled: false

I directed logstash as below  
xpack.monitoring.elasticsearch.url: ["[http://x.x.x.x:9200](http://x.x.x.x:9200)"]

x.x.x.x is the elasticsearch server

Logstash is not running and when I run the below command for test

bin/logstash -f /etc/logstash/conf.d/sample.conf

The result is as below  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused  
[ERROR] 2017-11-24 09:17:41.606 [[.monitoring-logstash]-pipeline-manager] licensemanager - Unable to retrieve license information from license server {:message=\>"Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError"}  
The stdin plugin is now waiting for input:  
[ERROR] 2017-11-24 09:17:43.431 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] metrics - Monitoring is not available: License information is currently unavailable. Please make sure you have added your production elasticsearch connection info in the xpack.monitoring.elasticsearch settings.  
No Available connections  
[ERROR] 2017-11-24 09:18:11.634 [monitoring-license-manager] licensemanager - Unable to retrieve license information from license server {:message=\>"No Available connections", :class=\>"LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError"}  
No Available connections

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 24, 2017, 5:20pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/2 "2017-11-24T17:20:47Z")

</div>

Hi @saad ,

As pointed out in the logs

> WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults

So logstash can't find the logstash.yml where you set the `xpack.monitoring.elasticsearch.url` and it attempts to use default value for the elasticsearch url, which is `http://localhost:9200` . No, nothing is listening on 9200 on your machine, hence you get a

> Elasticsearch Unreachable: [[http://localhost:9200/](http://localhost:9200/)][Manticore::SocketException] Connection refused

- Where is your logstash.yml located ?
- Are your `$LS_HOME` or `$LS_SETTINGS_DIR` environment variable set ? You can check with `echo $LS_HOME` or `echo $LS_SETTINGS_DIR`.

Alternatively you can try and pass the configuration dir path with  
`--path.settings=/path/to/your/logstash/config/dir/` , such as

`bin/logstash -f /etc/logstash/conf.d/sample.conf --path.settings=/path/to/your/logstash/config/dir/`

---

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [November 24, 2017, 7:40pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/3 "2017-11-24T19:40:03Z")

</div>

Thank you,

I am using the default directory /etc/logstash and the file is logstash.yml

I run bin/logstash -f /etc/logstash/conf.d/sample.conf --path.settings=/etc/logstash  
and was successful

Now, how can I run logstash from systemctl and let it go to that /etc/logstash to read the yml file?

---

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [November 24, 2017, 8:31pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/4 "2017-11-24T20:31:05Z")

</div>

$LS\_HOME and $LS\_SETTINGS\_DIR are empty with no values

by running echo $LS\_HOME

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 27, 2017, 7:48am UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/5 "2017-11-27T07:48:37Z")

</div>

> [@saad](#):
>
> how can I run logstash from systemctl

Assuming your OS is [supported](https://www.elastic.co/support/matrix#matrix_os), is it an option for you to install logstash using one of the [available packages](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html) for your distribution ? That way you can take advantage of the service conf files and [run it as a service using Systemd](https://www.elastic.co/guide/en/logstash/current/running-logstash.html)

---

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [November 27, 2017, 12:22pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/6 "2017-11-27T12:22:11Z")

</div>

i installed logstash by using rpm way. the OS i am using is Centos 7

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 27, 2017, 12:24pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/7 "2017-11-27T12:24:15Z")

</div>

Great, then as stated in the [documentation](https://www.elastic.co/guide/en/logstash/current/running-logstash.html#running-logstash-systemd), start logstash with

> sudo systemctl start logstash.service

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2017, 12:24pm UTC](https://discuss.elastic.co/t/xpack-and-logstas-elasticsearch-unreachable-http-localhost-9200/109048/8 "2017-12-25T12:24:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
