Docker环境下Logstash无法连接Elasticsearch求助
问题:Logstash无法连接Docker环境中的Elasticsearch,报错Connection refused
我在Docker容器中为Django应用部署了Elasticsearch与Logstash日志系统,日志可成功发送至Logstash,但无法转发至Elasticsearch,出现如下连接错误:
[2023-04-26T11:48:07,870][INFO ][logstash.outputs.elasticsearch][main] Failed to perform request {:message=>"Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused", :exception=>Manticore::SocketException, :cause=>#<Java::OrgApacheHttpConn::HttpHostConnectException: Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused>} [2023-04-26T11:48:07,870][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://elasticsearch:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [http://elasticsearch:9200/][Manticore::SocketException] Connect to elasticsearch:9200 [elasticsearch/172.25.0.6] failed: Connection refused"}
相关docker-compose配置(省略无关卷与容器),使用外部Docker网络git-reverse-proxy,本地开发环境可正常运行,怀疑是网络配置问题:
version: "3.8" services: logstash: image: docker.elastic.co/logstash/logstash:8.7.0 depends_on: - elasticsearch ports: - 9600:9600 - 5959:5959 volumes: - logs_volume:/logs:ro - ./logstash/logstash.conf:/usr/share/logstash/pipeline/logstash.conf networks: - git-reverse-proxy elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:8.7.0 hostname: elasticsearch environment: - xpack.security.enabled=false ports: - 9200:9200 volumes: - elasticsearch_volume:/usr/share/elasticsearch/data networks: - git-reverse-proxy kibana: image: docker.elastic.co/kibana/kibana:8.7.0 restart: always ports: - 5601:5601 depends_on: - elasticsearch networks: - git-reverse-proxy networks: git-reverse-proxy: external: true
logstash.conf配置:
input { tcp { port => 5959 codec => json } } output { elasticsearch { hosts => ["elasticsearch:9200"] index => "amcr" ssl_certificate_verification => false } }
排查与解决方案
1. 确保Elasticsearch服务完全就绪
depends_on仅保证容器启动顺序,不确保ES服务已初始化完成。可以通过以下方式处理:
- 给Elasticsearch添加健康检查,确保服务就绪后再启动Logstash:
修改docker-compose中elasticsearch的配置:
同时修改logstash的depends_on:elasticsearch: # ... 原有配置 healthcheck: test: ["CMD-SHELL", "curl -s http://localhost:9200/_cluster/health | grep -q '\"status\":\"green\"'"] interval: 10s timeout: 10s retries: 5logstash: depends_on: elasticsearch: condition: service_healthy - 手动验证:进入Logstash容器执行
curl http://elasticsearch:9200,若返回ES的JSON响应,说明网络连通;若失败,说明ES未完全启动或存在其他问题。
2. 验证容器在同一Docker网络
确认Logstash和Elasticsearch都加入了git-reverse-proxy网络:
- 执行
docker network inspect git-reverse-proxy,查看Containers列表是否包含两个容器。 - 若某容器不在网络中,可手动添加:
docker network connect git-reverse-proxy <容器名称>,或重启容器让其自动加入。
3. 调整Elasticsearch网络绑定配置
Elasticsearch默认可能仅绑定localhost,导致同网络的其他容器无法访问。需添加以下环境变量:
elasticsearch: environment: - xpack.security.enabled=false - network.host=0.0.0.0 # 监听所有网卡 - discovery.type=single-node # 单节点部署模式,避免集群发现问题
4. 优化Logstash输出配置
显式指定HTTP协议并关闭SSL(当前ES未启用SSL),避免配置歧义:
output { elasticsearch { hosts => ["http://elasticsearch:9200"] index => "amcr" ssl => false ssl_certificate_verification => false } }
5. 排查端口占用与防火墙
- 检查宿主机9200端口是否被其他进程占用:执行
netstat -tulpn | grep 9200。 - 确认宿主机防火墙未阻止容器间的9200端口通信(Docker网络内部默认互通,除非自定义了iptables规则)。
内容的提问来源于stack exchange,提问作者Jiří Pešek
相关产品推荐
相关产品推荐

