# Beats input: the pipeline is blocked, temporary refusing new connection

**URL:** <https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 8, 2016, 10:31pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764 "2016-01-08T22:31:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [January 8, 2016, 10:31pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/1 "2016-01-08T22:31:03Z")

</div>

I am using elasticsearch 1.7.1, logstash 1.5.4, and testing filebeat.  
It runs perfectly if I use filebeat to scan log files and use filebeat to output log data directly to elasticsearch as follows:  
logfiles -\> filebeat -\> elasticsearch

It also runs perfectly if I use filebeat to scan log files ouput to logstash, then use the logstash to output the data into another file as follows  
logfiles -\> filebeat -\>logstash -\> another file

But when I use the logstash to output to elasticsearch as such,  
logfiles -\>filebeat -\> logstash -\> elasticsearch  
It reports warning, and elasticsearch never gets the data

This is the warning from logstash side:  
**## Beats input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover. {:exception=\>LogStash::CircuitBreaker::OpenBreaker, :level=\>:warn}**  
**## Beats input: the pipeline is blocked, temporary refusing new connection. {:level=\>:warn}**

This is the error from filebeat side:  
...  
\*\* 2016/01/08 22:30:07.441115 single.go:121: INFO Connecting error publishing events (retrying): dial tcp 127.0.0.1:5044: getsockopt: connection refused\*\*  
2016/01/08 22:30:07.441146 single.go:143: INFO send fail  
2016/01/08 22:30:07.441159 single.go:150: INFO backoff retry: 4s  
...

Here is my conf file for logstash  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d3ba610e526406ea2d4c0a5a18f66b4ff808055f.png)

Here is my yml file for filebeat

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fe3343823d854211c0aad4c48da31babf901f426.png)

The elasticsearch log shows:  
[2016-01-08 17:55:59,831][WARN][http.netty] [dev-elkstack] Caught exception while handling client http traffic, closing connection [id: 0xe359725c, /10.100.16.221:52237 =\> /10.100.16.175:9200]  
java.lang.IllegalArgumentException: empty text  
at org.elasticsearch.common.netty.handler.codec.http.HttpVersion.(HttpVersion.java:89)  
at org.elasticsearch.common.netty.handler.codec.http.HttpVersion.valueOf(HttpVersion.java:62)  
at org.elasticsearch.common.netty.handler.codec.http.HttpRequestDecoder.createMessage(HttpRequestDecoder.java:75)  
at org.elasticsearch.common.netty.handler.codec.http.HttpMessageDecoder.decode(HttpMessageDecoder.java:191)  
at org.elasticsearch.common.netty.handler.codec.http.HttpMessageDecoder.decode(HttpMessageDecoder.java:102)  
at org.elasticsearch.common.netty.handler.codec.replay.ReplayingDecoder.callDecode(ReplayingDecoder.java:500)  
at org.elasticsearch.common.netty.handler.codec.replay.ReplayingDecoder.messageReceived(ReplayingDecoder.java:435)  
at org.elasticsearch.common.netty.channel.SimpleChannelUpstreamHandler.handleUpstream(SimpleChannelUpstreamHandler.java:70)  
at org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:564)  
at org.elasticsearch.common.netty.channel.DefaultChannelPipeline$DefaultChannelHandlerContext.sendUpstream(DefaultChannelPipeline.java:791)  
at org.elasticsearch.common.netty.OpenChannelsHandler.handleUpstream(OpenChannelsHandler.java:74)  
at org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:564)  
at org.elasticsearch.common.netty.channel.DefaultChannelPipeline.sendUpstream(DefaultChannelPipeline.java:559)  
at org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:268)  
at org.elasticsearch.common.netty.channel.Channels.fireMessageReceived(Channels.java:255)  
at org.elasticsearch.common.netty.channel.socket.nio.NioWorker.read(NioWorker.java:88)  
at org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.process(AbstractNioWorker.java:108)  
at org.elasticsearch.common.netty.channel.socket.nio.AbstractNioSelector.run(AbstractNioSelector.java:337)  
at org.elasticsearch.common.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:89)  
at org.elasticsearch.common.netty.channel.socket.nio.NioWorker.run(NioWorker.java:178)  
at org.elasticsearch.common.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:108)  
at org.elasticsearch.common.netty.util.internal.DeadLockProofWorker$1.run(DeadLockProofWorker.java:42)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:745)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2016, 3:50pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/2 "2016-01-09T15:50:25Z")

</div>

Your elasticsearch output configuration is incorrect; you're trying to use the node or transport protocol against ES's HTTP port. Since the node and transport protocols are deprecated and removed from the elasticsearch output plugin in Logstash 2.0 I suggest you switch to the HTTP protocol with `protocol => "http"`. Then the use of port 9200 will be correct.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 9, 2016, 10:14pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/3 "2016-01-09T22:14:39Z")

</div>

Also just as a general comment, try not to post images of text files, it's much better if you can paste and format them so that others can test (if need be), but also some images may not show (for whatever reason).

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [January 11, 2016, 10:16pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/4 "2016-01-11T22:16:08Z")

</div>

Thank you very much I used  
host =\> "dev-elkstack:9200"  
protocol =\> "http"  
it works!

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 11, 2016, 8:18am UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/5 "2016-07-11T08:18:59Z")

</div>

Hi Mark, I'm seeing the same problem, but i'm running elasticsearch 2.3.3 and logstash 2.3.2, with below logstash output configuration. With this latest ELK, it's default to HTTP protocol, so the solution doesn't really apply. what could be the other reason? thank you.

elasticsearch {  
hosts =\> ["server1", "server2","server3"]  
index =\> "app-%{+YYYY.MM.dd}"  
}

{:timestamp=\>"2016-07-08T18:15:32.204000+0800", :message=\>"Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep  
=\>0.5, :level=\>:warn}  
{:timestamp=\>"2016-07-08T18:15:32.205000+0800", :message=\>"CircuitBreaker::Open", :name=\>"Beats input", :level=\>:warn}  
{:timestamp=\>"2016-07-08T18:15:32.208000+0800", :message=\>"Beats input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is clo  
sing the current connection and rejecting new connection until the pipeline recover.", :exception=\>LogStash::Inputs::BeatsSupport::CircuitBreaker::OpenBreaker  
, :level=\>:warn}  
{:timestamp=\>"2016-07-08T18:15:32.707000+0800", :message=\>"Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep  
=\>0.5, :level=\>:warn}  
{:timestamp=\>"2016-07-08T18:15:33.210000+0800", :message=\>"Beats input: the pipeline is blocked, temporary refusing new connection.", :reconnect\_backoff\_sleep  
=\>0.5, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 11, 2016, 3:13pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/6 "2016-07-11T15:13:06Z")

</div>

please start another topic

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:51pm UTC](https://discuss.elastic.co/t/beats-input-the-pipeline-is-blocked-temporary-refusing-new-connection/38764/7 "2017-07-05T21:51:01Z")

</div>


