Not sure if netstat will show a port as listening even if your firewall is not configured?
The command would vary depending on your OS, for me it’s “firewall-cmd --list-all”
Have you edited the elasticsearch.yml file?
What does your Graylog config specify as the url for elasticsearch? Mine is still default, I still only have a single dev server, so using default localhost works fine.
#List of Elasticsearch hosts Graylog should connect to.
# Need to be specified as a comma-separated list of valid URIs for the http ports of your elasticsearch nodes.
# If one or more of your elasticsearch hosts require authentication, include the credentials in each node URI that
# requires authentication.
# Default: http://127.0.0.1:9200
#elasticsearch_hosts = http://node1:9200,http://user:password@node2:19200