# Beats input: the pipeline is blocked, temporary refusing new connection.",reconnect\_backoff\_sleep=\>0.5

**URL:** https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655
**Category:** Beats
**Tags:** filebeat
**Created:** [March 7, 2016, 1:08pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655 "2016-03-07T13:08:22Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![aryaray](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@aryaray](https://discuss.elastic.co/u/aryaray)
#### Post date: [March 7, 2016, 1:08pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/1 "2016-03-07T13:08:22Z")

</div>

Hi ,

We Setup ELK stack it's running fine 2 days before. But now We facing that logs are coming delayed . We check logstash log for identify issue. There we getting that

> Beats input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover

after some time

> Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep=\>0.5

Our filebeat version is 1.1.1 (amd64)

Please help .

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 7, 2016, 3:55pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/2 "2016-03-07T15:55:17Z")

</div>

I think the logs you posted are from Logstash, not Filebeat. This typically happens when components downstream (outputs in LS) cannot handle the load you are sending.

---

<div class="post-metadata">

### Author: ![aryaray](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@aryaray](https://discuss.elastic.co/u/aryaray)
#### Post date: [March 7, 2016, 4:04pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/3 "2016-03-07T16:04:33Z")

</div>

Yes you are correct . Can you tell me how we solve this issue ? We need to handle huge log daily basis . So, we need solution which can handle such huge log .

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [March 7, 2016, 5:53pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/4 "2016-03-07T17:53:07Z")

</div>

This can be a complex issue because there are a lot of variables in play. From a planning perspective I would identify what the maximum indexing rate is that you want the system to be able to handle without delay. Then in a dev environment independently test each component in the system to make sure that it can handle that load. For example if you are using Elasticsearch then [test](https://www.elastic.co/guide/en/elasticsearch/guide/current/indexing-performance.html#_test_performance_scientifically) to make sure it can handle X events per second. Do the same for Logstash (use the stdout output with dots codec and measure events per second with `bin/logstash --quiet -f myconfig.conf | pv -Wbart > /dev/null`).

If you find that a component cannot handle the load (and you cannot tolerate a processing delay) then scale up horizontally. Add more Logstash instances or more Elasticsearch instances as required.

With your current setup, you can check to see if any of the Logstash worker threads are maxing out the CPU. If this is the case then it could be an issue with your Logstash config, in which case you would want to get a stack trace of Logstash to see what's going on.

If it's not an issue with Logstash, then I would look at your outputs. If you are using Elasticsearch, then use Marvel to look at the percentage of documents being rejected. It is perfectly fine to have some documents rejected but anything higher then 10-15% on a regular basis is a good indication the cluster is overloaded.

---

<div class="post-metadata">

### Author: ![santhu227](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@santhu227](https://discuss.elastic.co/u/santhu227)
#### Post date: [June 6, 2016, 12:53pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/5 "2016-06-06T12:53:44Z")

</div>

Hi Guys.,

we are getting below error in logstash log

log:

Beats input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover  
Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep=\>0.5, :level=\>:warn

Note : Logstash instance was working fine for moderate load but when load increased drastically we are facing this issue and logstash is unable to come out of it. To avoid this  
we have increased logstash congestion\_threshold to 25 also increased -w to 10 for 4 core machine for logstash service still it is in same state.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [June 6, 2016, 2:13pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/6 "2016-06-06T14:13:45Z")

</div>

@santhu227 please create another topic to not mix contexts. Btw. your problem might not be related to logstash per se, but some output (e.g. database or elasticsearch) in logstash not processing events in time.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection-reconnect-backoff-sleep-0-5/43655/7 "2017-07-05T21:51:16Z")

</div>


