# Can't connect to Logstash port 5044 from Filebeat

**URL:** <https://discuss.elastic.co/t/cant-connect-to-logstash-port-5044-from-filebeat/253639>\
**Category:** Logstash\
**Created:** [October 29, 2020, 3:15am UTC](https://discuss.elastic.co/t/cant-connect-to-logstash-port-5044-from-filebeat/253639 "2020-10-29T03:15:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aloalo2242](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aloalo2242/32/78043_2.png) [@aloalo2242](https://discuss.elastic.co/u/aloalo2242)\
**Post date:** [October 29, 2020, 3:15am UTC](https://discuss.elastic.co/t/cant-connect-to-logstash-port-5044-from-filebeat/253639/1 "2020-10-29T03:15:27Z")

</div>

Hi all,

This is my config in `/etc/logstash/conf.d/01-logstash.conf` from ELK Server.

> input {  
> beats {  
> port =\> 5044  
> }  
> }
> 
> filter {  
> grok {  
> match =\> {  
> "message" =\> [  
> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:? %{SSH\_INVALID\_USER:message}"  
> ]  
> }  
> patterns\_dir =\> "/etc/logstash/patterns/sshd"  
> named\_captures\_only =\> true  
> remove\_tag =\> ["\_grokparsefailure"]  
> break\_on\_match =\> true  
> add\_tag =\> ["SSH", "SSH\_INVALID\_USER"]  
> add\_field =\> { "event\_type" =\> "SSH\_INVALID\_USER" }  
> overwrite =\> "message"  
> }  
> }
> 
> # Grok Filter for SSH Failed Password
> 
> filter{  
> grok {  
> match =\> {  
> "message" =\> [  
> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:? %{SSH\_FAILED\_PASSWORD:message}"  
> ]  
> }  
> patterns\_dir =\> "/etc/logstash/patterns/sshd"  
> named\_captures\_only =\> true  
> remove\_tag =\> ["\_grokparsefailure"]  
> break\_on\_match =\> true  
> add\_tag =\> ["SSH", "SSH\_FAILED\_PASSWORD"]  
> add\_field =\> { "event\_type" =\> "SSH\_FAILED\_PASSWORD" }  
> overwrite =\> "message"  
> }  
> }
> 
> filter {
> 
> # Grok Filter for SSH Password Accepted
> 
> ```
> grok {
> match => {
> "message" => [
> "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?:? %{SSH_ACCEPTED_PASSWORD}"
> ]
> }
> patterns_dir => "/etc/logstash/patterns/sshd"
> named_captures_only => true
> remove_tag => ["_grokparsefailure"]
> break_on_match => true
> add_tag => ["SSH", "SSH_ACCEPTED_PASSWORD"]
> add_field => { "event_type" => "SSH_ACCEPTED_PASSWORD" }
> }
> 
> ```
> 
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

When I use netstat, port 5044 isnt Listen although I've opend in both firewalld and iptables.  
So I can't connect from client(filebeat) to Logstash server

> ```
> filebeat test output
> logstash: 192.168.0.1:5044...
> connection...
> parse host... OK
> dns lookup... OK
> addresses: 192.168.0.1
> dial up... ERROR dial tcp 192.168.0.1:5044: connect: connection refused
> 
> ```

Please help me  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2020, 3:15am UTC](https://discuss.elastic.co/t/cant-connect-to-logstash-port-5044-from-filebeat/253639/2 "2020-11-26T03:15:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
