You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker环境下Logstash无法连接Elasticsearch求助

问题:Logstash无法连接Docker环境中的Elasticsearch,报错Connection refused

我在Docker容器中为Django应用部署了Elasticsearch与Logstash日志系统,日志可成功发送至Logstash,但无法转发至Elasticsearch,出现如下连接错误:

[2023-04-26T11:48:07,870][INFO ][logstash.outputs.elasticsearch][main] Failed to perform request {:message=>"Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused", :exception=>Manticore::SocketException, :cause=>#<Java::OrgApacheHttpConn::HttpHostConnectException: Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused>}
[2023-04-26T11:48:07,870][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://elasticsearch:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://elasticsearch:9200/][Manticore::SocketException] Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused"}

相关docker-compose配置(省略无关卷与容器),使用外部Docker网络git-reverse-proxy,本地开发环境可正常运行,怀疑是网络配置问题:

version: "3.8"

services:
  logstash:
    image: docker.elastic.co/logstash/logstash:8.7.0
    depends_on:
      - elasticsearch
    ports:
      - 9600:9600
      - 5959:5959
    volumes:
      - logs_volume:/logs:ro
      - ./logstash/logstash.conf:/usr/share/logstash/pipeline/logstash.conf
    networks:
      - git-reverse-proxy

  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:8.7.0
    hostname: elasticsearch
    environment:
      - xpack.security.enabled=false
    ports:
      - 9200:9200
    volumes:
      - elasticsearch_volume:/usr/share/elasticsearch/data
    networks:
      - git-reverse-proxy

  kibana:
    image: docker.elastic.co/kibana/kibana:8.7.0
    restart: always
    ports:
      - 5601:5601
    depends_on:
      - elasticsearch
    networks:
      - git-reverse-proxy

networks:
  git-reverse-proxy:
    external: true

logstash.conf配置:

input {
    tcp {
        port => 5959
        codec => json
    }
}

output {
    elasticsearch {
        hosts => ["elasticsearch:9200"]
        index => "amcr"
        ssl_certificate_verification => false
    }
}

排查与解决方案

1. 确保Elasticsearch服务完全就绪

depends_on仅保证容器启动顺序,不确保ES服务已初始化完成。可以通过以下方式处理:

  • 给Elasticsearch添加健康检查,确保服务就绪后再启动Logstash:
    修改docker-compose中elasticsearch的配置:
    elasticsearch:
      # ... 原有配置
      healthcheck:
        test: ["CMD-SHELL", "curl -s http://localhost:9200/_cluster/health | grep -q '\"status\":\"green\"'"]
        interval: 10s
        timeout: 10s
        retries: 5
    
    同时修改logstash的depends_on:
    logstash:
      depends_on:
        elasticsearch:
          condition: service_healthy
    
  • 手动验证:进入Logstash容器执行curl http://elasticsearch:9200,若返回ES的JSON响应,说明网络连通;若失败,说明ES未完全启动或存在其他问题。

2. 验证容器在同一Docker网络

确认Logstash和Elasticsearch都加入了git-reverse-proxy网络:

  • 执行docker network inspect git-reverse-proxy,查看Containers列表是否包含两个容器。
  • 若某容器不在网络中,可手动添加:docker network connect git-reverse-proxy <容器名称>,或重启容器让其自动加入。

3. 调整Elasticsearch网络绑定配置

Elasticsearch默认可能仅绑定localhost,导致同网络的其他容器无法访问。需添加以下环境变量:

elasticsearch:
  environment:
    - xpack.security.enabled=false
    - network.host=0.0.0.0  # 监听所有网卡
    - discovery.type=single-node  # 单节点部署模式,避免集群发现问题

4. 优化Logstash输出配置

显式指定HTTP协议并关闭SSL(当前ES未启用SSL),避免配置歧义:

output {
    elasticsearch {
        hosts => ["http://elasticsearch:9200"]
        index => "amcr"
        ssl => false
        ssl_certificate_verification => false
    }
}

5. 排查端口占用与防火墙

  • 检查宿主机9200端口是否被其他进程占用:执行netstat -tulpn | grep 9200。
  • 确认宿主机防火墙未阻止容器间的9200端口通信(Docker网络内部默认互通,除非自定义了iptables规则)。

内容的提问来源于stack exchange,提问作者Jiří Pešek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 12:48:13