# Need some help setting up a "simple" ELK stack

**URL:** <https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465>\
**Category:** Rancher 1.x\
**Created:** [January 14, 2016, 4:51pm UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465 "2016-01-14T16:51:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebishop](https://avatars.discourse-cdn.com/v4/letter/e/9dc877/32.png) [@ebishop](https://forums.suse.com/u/ebishop)\
**Post date:** [January 14, 2016, 4:51pm UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465/1 "2016-01-14T16:51:35Z")

</div>

I’m trying to create a simple docker elk stack to run in Rancher.  
All of the containers should run on the same host, so that’s what I’m  
setting the host\_label.

The reason for my post here is that I can run this with docker-compose, on the same VM Host, and  
kibana comes up and connects to elasticsearch. But in Rancher, on the same VM Host,  
I get the following error:

kibana\_1 |  
log [16:11:16.888]  
[error][status][plugin:elasticsearch] Status changed from yellow to red -  
Request Timeout after 1500ms

I’ve tried running this docker-ocmpose file with the rancher-compose CLI and as a custom catalog entry and the results are the same.

I did try a little guessing from looking around in your ELK catalog entries, but they are much more complex (and I’m sure very well thought out), but I just want something very simple.

Please, advise…

====== docker-compose.yml =========

```auto
elasticsearch:
  image: elasticsearch:latest
  ports:
    - "9200:9200"
    - "9300:9300"
  expose:
    - "9200"
    - "9300"
  volumes:
    - "/var/esdata:/usr/share/elasticsearch/data"
  labels:
    io.rancher.container.pull_image: always
    io.rancher.scheduler.affinity:host_label: ${HOST_LABEL}
    io.rancher.container.hostname_override: container_name
kibana:
  image: kibana:latest
  command: 
    - kibana
  ports:
    - "5601:5601"
  expose:
    - "5601"
  links:
    - elasticsearch:elasticsearch
  environment:
    ELASTICSEARCH_URL: "http://elasticsearch:9200"
  labels:
    io.rancher.container.pull_image: always
    io.rancher.scheduler.affinity:host_label: ${HOST_LABEL}
    io.rancher.container.hostname_override: container_name
 logstash:
  image: rcdn6-vm67-9.cisco.com/dot-logstash
  command: 
    - /docker-entrypoint.sh 
    - -f 
    - /etc/logstash/conf.d/*.conf
  ports:
    - "5000:5000"
  expose:
    - "5000"
  links:
    - elasticsearch:elasticsearch
  labels:
    io.rancher.container.pull_image: always
    io.rancher.scheduler.affinity:host_label: ${HOST_LABEL}
    io.rancher.container.hostname_override: container_name

```

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [January 22, 2016, 4:47am UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465/2 "2016-01-22T04:47:30Z")

</div>

I’m not an ELK expert, but running any docker-compose.yml in the CLI and using a custom catalog entry and even dumping it into the “Add Stack” page will all perform the same action. 🙂 They are all using rancher-compose to launch items.

Another tip is when pasting your compose files, it’s much easier to read (and allow you to format so that we could try it out) if you put in three backticks at the beginning and end of your code. I’ve done it above for your existing code block.

---

<div class="post-metadata">

**Author:** ![sjiveson](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/sjiveson/32/966_2.png) [@sjiveson](https://forums.suse.com/u/sjiveson)\
**Post date:** [January 22, 2016, 11:16am UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465/3 "2016-01-22T11:16:20Z")

</div>

Shouldn’t the port for Logstash be 9292?

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [January 26, 2016, 10:03pm UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465/4 "2016-01-26T22:03:25Z")

</div>

Also, since this is all on the same host, could it be hairpin NAT issue?

> <https://github.com/rancher/rancher/issues/1920>
>
> Requests from the host to the public IP and back to the host do not work.

---

<div class="post-metadata">

**Author:** ![ebishop](https://avatars.discourse-cdn.com/v4/letter/e/9dc877/32.png) [@ebishop](https://forums.suse.com/u/ebishop)\
**Post date:** [January 26, 2016, 10:20pm UTC](https://forums.suse.com/t/need-some-help-setting-up-a-simple-elk-stack/1465/5 "2016-01-26T22:20:09Z")

</div>

I installed v56 of Rancher this morning, and my simple ELK stack works.

Thanks
