# 125: SSL client failed to connect with: dial tcp 192.168.37.147:5044: getsockopt: connection refused

**URL:** <https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 20, 2018, 12:37pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161 "2018-08-20T12:37:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rituraj](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rituraj](https://discuss.elastic.co/u/rituraj)\
**Post date:** [August 20, 2018, 12:37pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/1 "2018-08-20T12:37:43Z")

</div>

Hi Team,

I am getting below errro while fetching logs by using filebeat .  
Details are mentioned below

[root@nagios-core ~]# systemctl status filebeat  
● filebeat.service - filebeat  
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; vendor preset: disabled)  
Active: active (running) since Mon 2018-08-20 17:15:38 IST; 1s ago  
Docs: [https://www.elastic.co/guide/en/beats/filebeat/current/index.html](https://www.elastic.co/guide/en/beats/filebeat/current/index.html)  
Main PID: 2531 (filebeat)  
CGroup: /system.slice/filebeat.service  
└─2531 /usr/bin/filebeat -c /etc/filebeat/filebeat.yml

Aug 20 17:15:38 nagios-core systemd[1]: Started filebeat.  
Aug 20 17:15:38 nagios-core systemd[1]: Starting filebeat...  
Aug 20 17:15:38 nagios-core /usr/bin/filebeat[2531]: transport.go:125: SSL client failed to connect with: dial tcp 192.168.37.147:5044: getsockopt: connection refused  
[root@nagios-core ~]#

Elasticsearch server:-

[root@node1 conf.d]# netstat -ntulpn  
Active Internet connections (only servers)  
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name  
tcp 0 0 0.0.0.0:5601 0.0.0.0:\* LISTEN 683/node  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN 1049/sshd  
tcp 0 0 127.0.0.1:25 0.0.0.0:\* LISTEN 1330/master  
tcp6 0 0 :::9200 :::\* LISTEN 1053/java  
tcp6 0 0 :::9300 :::\* LISTEN 1053/java  
tcp6 0 0 :::22 :::\* LISTEN 1049/sshd  
tcp6 0 0 ::1:25 :::\* LISTEN 1330/master  
udp 0 0 0.0.0.0:68 0.0.0.0:\* 867/dhclient  
[root@node1 conf.d]#

[root@node1 conf.d]# systemctl status logstash  
● logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: disabled)  
Active: active (running) since Mon 2018-08-20 17:14:27 IST; 22s ago  
Main PID: 5634 (java)  
CGroup: /system.slice/logstash.service  
└─5634 /bin/java -Xms1g -Xmx1g -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.aw...

Aug 20 17:14:27 node1 systemd[1]: Started logstash.  
Aug 20 17:14:27 node1 systemd[1]: Starting logstash...

Please help me to fix this issue.

Regards,  
Rituraj

---

<div class="post-metadata">

**Author:** ![\_Alex](https://avatars.discourse-cdn.com/v4/letter/_/54ee81/32.png) [@\_Alex](https://discuss.elastic.co/u/_Alex)\
**Post date:** [August 20, 2018, 12:58pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/2 "2018-08-20T12:58:15Z")

</div>

Filebeat is trying to connect to 192.168.37.147 on port 5044 but it is not able to:

```
dial tcp 192.168.37.147:5044: getsockopt: connection refused

```

Can you perform a telnet to this address with `telnet 192.168.37.147 5044`? If not then this indicates a network problem. Confirm the host you're connecting to is listening on port 5044, and if it is then begin troubleshooting network connectivity.

---

<div class="post-metadata">

**Author:** ![rituraj](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rituraj](https://discuss.elastic.co/u/rituraj)\
**Post date:** [August 20, 2018, 2:33pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/3 "2018-08-20T14:33:31Z")

</div>

> [@\_Alex](#):
>
> telnet 192.168.37.147 5044

this is my client machine where i have installed filebeat  
[root@nagios-core ~]# telnet 192.168.37.147 5044  
Trying 192.168.37.147...  
telnet: connect to address 192.168.37.147: Connection refused  
[root@nagios-core ~]#

---

<div class="post-metadata">

**Author:** ![\_Alex](https://avatars.discourse-cdn.com/v4/letter/_/54ee81/32.png) [@\_Alex](https://discuss.elastic.co/u/_Alex)\
**Post date:** [August 20, 2018, 2:35pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/4 "2018-08-20T14:35:18Z")

</div>

> [@rituraj](#):
>
> telnet: connect to address 192.168.37.147: Connection refused

Are you trying to connect filebeat to logstash? If so you need to find out what port the logstash `input` is configured as and use that one.

---

<div class="post-metadata">

**Author:** ![rituraj](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rituraj](https://discuss.elastic.co/u/rituraj)\
**Post date:** [August 20, 2018, 2:42pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/5 "2018-08-20T14:42:36Z")

</div>

Yes Alex ..I am trying to connect filebeat to logstash.  
In ELK server the Input.conf i have provided as below

[root@node1 conf.d]# cat input.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
[root@node1 conf.d]#

It was working fine before suddenly it stop working , i am not sure why issue occurs.

[root@node1 conf.d]# netstat -ntulpn  
Active Internet connections (only servers)  
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name  
tcp 0 0 0.0.0.0:5601 0.0.0.0:\* LISTEN 683/node  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN 1049/sshd  
tcp 0 0 127.0.0.1:25 0.0.0.0:\* LISTEN 1330/master  
tcp6 0 0 :::9200 :::\* LISTEN 1053/java  
tcp6 0 0 :::9300 :::\* LISTEN 1053/java  
tcp6 0 0 :::22 :::\* LISTEN 1049/sshd  
tcp6 0 0 ::1:25 :::\* LISTEN 1330/master  
udp 0 0 0.0.0.0:68 0.0.0.0:\* 867/dhclient  
[root@node1 conf.d]#

I was able to fetch logs some time back suddenly it stops

[root@node1 conf.d]# curl -XGET '[http://localhost:9200/filebeat-\*/\_search?pretty](http://localhost:9200/filebeat-*/_search?pretty)'  
{  
"took" : 9,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 25,  
"successful" : 25,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : 4304,  
"max\_score" : 1.0,  
"hits" : [  
{  
"\_index" : "filebeat-2018.08.07",  
"\_type" : "syslog",  
"\_id" : "cDuGKGUBXvLb450j9lyH",  
"\_score" : 1.0,  
"\_source" : {  
"program" : "sshd",  
"tags" : [  
"beats\_input\_codec\_plain\_applied"  
],  
"@timestamp" : "2018-08-07T09:17:30.000Z",  
"@version" : "1",  
"timestamp" : "Aug 7 14:47:30",  
"offset" : 1437,  
"input\_type" : "log",  
"beat" : {  
"hostname" : "nagios-core",  
"name" : "nagios-core"  
},  
"host" : "nagios-core",  
"message" : [  
"Aug 7 14:47:30 nagios-core sshd[16544]: Connection closed by 127.0.0.1 [preauth]",  
"Connection closed by 127.0

---

<div class="post-metadata">

**Author:** ![\_Alex](https://avatars.discourse-cdn.com/v4/letter/_/54ee81/32.png) [@\_Alex](https://discuss.elastic.co/u/_Alex)\
**Post date:** [August 20, 2018, 3:08pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/6 "2018-08-20T15:08:39Z")

</div>

It looks like your logstash instance is not running, check the logstash logs to see if there are any useful errors there.

---

<div class="post-metadata">

**Author:** ![rituraj](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rituraj](https://discuss.elastic.co/u/rituraj)\
**Post date:** [August 20, 2018, 3:16pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/7 "2018-08-20T15:16:31Z")

</div>

Logstash instance is running but as per logstash logs looks like need to do some changes in output.conf.Please confirm .  
Details are mentioned below

[root@node1 logstash]# systemctl status logstash  
● logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: disabled)  
Active: active (running) since Mon 2018-08-20 19:56:06 IST; 24s ago  
Main PID: 11312 (java)  
CGroup: /system.slice/logstash.service  
└─11312 /bin/java -Xms1g -Xmx1g -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.a...

Aug 20 19:56:06 node1 systemd[1]: Started logstash.  
Aug 20 19:56:06 node1 systemd[1]: Starting logstash...  
[root@node1 logstash]#  
[2018-08-20T19:53:10,518][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[[//192.168.37.141:9200](https://192.168.37.141:9200)], sniffing=\>true, manage\_template=\>false, index=\>"%{[@metadata][beat]}-%{+YYYY.MM.dd}", document\_type=\>"%{[@metadata][type]}", id=\>"0f51209746cb88fdf644cd89b62965f0d2b4a2e49339980339634a9798b9ee20", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_9ab4aa9a-0a93-4bf3-bef9-5f0dcd429a50", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[2018-08-20T19:53:10,539][INFO][logstash.runner] Using config.test\_and\_exit mode. Config Validation Result: OK. Exiting Logstash  
[2018-08-20T19:53:59,809][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
^C  
[root@node1 logstash]# ls

[root@node1 conf.d]# cat input.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
[root@node1 conf.d]# cat output.conf  
output {  
elasticsearch {  
hosts =\> ["192.168.37.141:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
[root@node1 conf.d]# cat filter.conf  
filter {  
if [type] == "apachelog\_test" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
date {  
match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
[root@node1 conf.d]#

---

<div class="post-metadata">

**Author:** ![\_Alex](https://avatars.discourse-cdn.com/v4/letter/_/54ee81/32.png) [@\_Alex](https://discuss.elastic.co/u/_Alex)\
**Post date:** [August 20, 2018, 3:25pm UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/8 "2018-08-20T15:25:03Z")

</div>

> [@rituraj](#):
>
> [2018-08-20T19:53:10,539][INFO][logstash.runner] Using config.test\_and\_exit mode. Config Validation Result: OK. Exiting Logstash

This indicates your logstash config is running in a test mode - so it is starting up, validating the config is OK, then exiting. Do you have `config.test_and_exit = true` set in your `logstash.yml`? If so remove this and re-test.

---

<div class="post-metadata">

**Author:** ![rituraj](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@rituraj](https://discuss.elastic.co/u/rituraj)\
**Post date:** [August 21, 2018, 6:53am UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/9 "2018-08-21T06:53:20Z")

</div>

Thank you very much Alex/Team.

It is working after commented config.test\_and\_exit = true in logstash.yml.

Regards,  
Rituraj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2018, 6:53am UTC](https://discuss.elastic.co/t/125-ssl-client-failed-to-connect-with-dial-tcp-192-168-37-147-getsockopt-connection-refused/145161/10 "2018-09-18T06:53:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
