Rails应用使用ELK栈时遇Logstash连接拒绝问题求助
Hey there, let's work through this connection issue step by step—this error almost always means Logstash can't reach your Elasticsearch instance. Here's what to check:
1. Verify Elasticsearch is Running First
The most common cause is Elasticsearch isn't even started. Test this by running:
curl localhost:9200
If you get a JSON response like this, ES is up and running:
{ "name" : "your-node-name", "cluster_name" : "elasticsearch", "cluster_uuid" : "...", "version" : { ... }, "tagline" : "You Know, for Search" }
If you get a "connection refused" here too, start Elasticsearch based on your system:
- Mac (Homebrew):
brew services start elasticsearch - Linux (systemd):
sudo systemctl start elasticsearch - Direct binary: Navigate to your Elasticsearch install directory and run
bin/elasticsearch
2. Check Elasticsearch's Network Configuration
Sometimes Elasticsearch is configured to listen on a different address than localhost. Open your elasticsearch.yml file (usually in /usr/share/elasticsearch/config/ or your install's config/ folder) and verify these settings:
# Ensure this is set to localhost (or an IP Logstash can reach) network.host: localhost # Confirm the port matches what's in your Logstash config http.port: 9200
If you make changes here, restart Elasticsearch to apply them.
3. Check for Firewall/Port Blocking
Local firewalls or security tools might be blocking traffic on port 9200. For testing, try temporarily disabling your firewall, or add an allow rule for the port. On Linux, you can run:
sudo ufw allow 9200/tcp
4. Double-Check Your Logstash Output Configuration
Make sure your Logstash config's Elasticsearch output has no typos in the host/port:
output { elasticsearch { hosts => ["localhost:9200"] } # No typos here! stdout { codec => rubydebug } }
Even a small mistake (like 920 instead of 9200) will trigger this connection error.
Quick Side Note for Your Rails Logs
Once you fix the connection issue, keep in mind your current grok pattern uses %{COMBINEDAPACHELOG}—this is designed for Apache web logs, not Rails' default log format. You'll need to update the grok match to fit Rails logs, either by using a pre-defined %{RAILSLOG} pattern (if you have the relevant grok patterns installed) or creating a custom pattern that matches your Rails log structure.
内容的提问来源于stack exchange,提问作者Nonsense

