# Can't etablish connection with logstash and my filebeat 7.17.1

**URL:** <https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [June 8, 2022, 3:47pm UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722 "2022-06-08T15:47:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dreinale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dreinale/32/106570_2.png) [@Dreinale](https://discuss.elastic.co/u/Dreinale)\
**Post date:** [June 8, 2022, 3:47pm UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/1 "2022-06-08T15:47:07Z")

</div>

Hi all,

I want to do a monitoring of my log but i don't understand why my logstash doesn't"t work with filebeat.

For now i have Elasticsearch:  
**Elasticsearch.yml**

```auto
node.name: master-node-1
node.master: true
cluster.initial_master_nodes:
  - master-node-1

path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch

network.host: 192.168.66.11
http.port: 9200

```

kibana:  
**kibana.yml**

```auto
server.port: 5601
server.host: "192.168.66.11"

```

logstash:  
**pipelines.yml**

```auto
- pipeline.id: main
  path.config: "/etc/logstash/conf.d/*.conf"
  pipeline.workers: 1

```

**logstash-beat-electric.conf**

```auto
input {
  beats {
    port => 5044
    id => "from_filebeat"
  }
}
output {
  elasticsearch {
    hosts => ["http://192.168.66.11:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
  }
}
filter {
...
}

```

filebeat:  
**filebeat.yml**

```auto
- type: log

  enabled: true

  paths:
    - /home/ttc/epnp-docker-share/bowl-automotive/tmp/reference-data/*.log
  tags: ["iocore_data"]

- type: filestream
  enabled: false
  paths:
    - /var/log/*.log
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1

setup.kibana:
  host: "192.168.66.11:5601"

output.logstash:
  hosts: ["192.168.66.11:5044"]

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

when i start filebeat i got this:

```auto
juin 08 17:36:13 pcttc filebeat[226686]: 2022-06-08T17:36:13.128+0200 ERROR [publisher_pipeline_output] pipeline/output.go:154 Failed to connect to backoff(async(tcp://192.168.66.11:5044)): dial tcp 192.168.66.11:5044: connect: no route to host>

```

for logstash:

```auto
juin 08 16:09:06 cluster logstash[8194]: [2022-06-08T16:09:06,383][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
juin 08 16:09:06 cluster logstash[8194]: [2022-06-08T16:09:06,405][INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
juin 08 16:09:06 cluster logstash[8194]: [2022-06-08T16:09:06,405][INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
juin 08 16:09:06 cluster logstash[8194]: [2022-06-08T16:09:06,492][WARN][logstash.javapipeline][main] 'pipeline.ordered' is enabled and is likely less efficient, consider disabling if preserving event order is not necessary
juin 08 16:09:07 cluster logstash[8194]: [2022-06-08T16:09:07,679][INFO][logstash.inputs.beats][main] Starting input listener {:address=>"0.0.0.0:5044"}
Juin 08 16:09:07 cluster logstash[8194]: [2022-06-08T16:09:07,694][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
juin 08 16:09:07 cluster logstash[8194]: [2022-06-08T16:09:07,862][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
juin 08 16:09:07 cluster logstash[8194]: [2022-06-08T16:09:07,904][INFO][org.logstash.beats.Server][main][from_filebeat] Starting server on port: 5044

```

Here is my "log"

 ![Capture d’écran_2022-06-08_17-45-28](https://us1.discourse-cdn.com/elastic/original/3X/2/0/2048ef186042921c2d41324e99847212053f5de8.png)

As we can see metricbeat is working so Elasticsearch and kibana works i think.

First of all i don't understand why logstash listen: _address=\>"0.0.0.0:5044"_

and i don't know why my logstash or filebeat doesn't work.

Can i have some help pls ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 8, 2022, 3:56pm UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/2 "2022-06-08T15:56:30Z")

</div>

> [@Dreinale](#):
>
> First of all i don't understand why logstash listen: _address=\>"0.0.0.0:5044"_

0.0.0.0 is usually interpreted by the TCP stack as "all public addresses", although some stacks have slightly different interpretations. You could explicitly set the host option on the beats input to match the IP address you set in filebeat.

---

<div class="post-metadata">

**Author:** ![Dreinale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dreinale/32/106570_2.png) [@Dreinale](https://discuss.elastic.co/u/Dreinale)\
**Post date:** [June 8, 2022, 4:10pm UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/3 "2022-06-08T16:10:25Z")

</div>

When you say

> the beats input

it's in the logstash ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 8, 2022, 4:25pm UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/4 "2022-06-08T16:25:52Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Dreinale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dreinale/32/106570_2.png) [@Dreinale](https://discuss.elastic.co/u/Dreinale)\
**Post date:** [June 9, 2022, 10:58am UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/5 "2022-06-09T10:58:08Z")

</div>

I try but it's the same result,  
So i install a logstach into another computer and it's work...  
I do exactly the same as before but I don't understand why I'm getting this:

my logstash that doesn't work:

```auto
[WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[INFO][logstash.outputs.elasticsearch][main] Using a default mapping template {:es_version=>7, :ecs_compatibility=>:disabled}
[INFO][logstash.javapipeline][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>8, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>1000, "pipeline.sources"=>["/etc/logstash/conf.d/logstash-beat-electic.conf"], :thread=>"#<Thread:0x46e88eda run>"}
[INFO][logstash.javapipeline][main] Pipeline Java execution initialization time {"seconds"=>1.26}
[INFO][logstash.inputs.beats][main] Starting input listener {:address=>"0.0.0.0:5044"}
[INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
[INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[INFO][org.logstash.beats.Server][main][from_filebeat] Starting server on port: 5044

```

and the another logstash but it work:

```auto
juin 09 12:19:21 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:21,121][WARN][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
juin 09 12:19:21 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:21,255][INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
juin 09 12:19:21 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:21,257][INFO][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
juin 09 12:19:21 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:21,296][INFO][logstash.outputs.elasticsearch][main] Using a default mapping template {:es_version=>7, :ecs_compatibility=>:disabled}
juin 09 12:19:21 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:21,348][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>16, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>2000, "pipeline.sources"=>["/etc/logstash/conf.d/logstash-beat-electric.conf"], :thread=>"#<Thread:0x725c9ca4 run>"}
juin 09 12:19:22 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:22,157][INFO][logstash.javapipeline][main] Pipeline Java execution initialization time {"seconds"=>0.8}
juin 09 12:19:22 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:22,182][INFO][logstash.inputs.beats][main] Starting input listener {:address=>"0.0.0.0:5044"}
juin 09 12:19:22 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:22,194][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
juin 09 12:19:22 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:22,241][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
juin 09 12:19:22 EB-epicnpoc logstash[21949]: [2022-06-09T12:19:22,313][INFO][org.logstash.beats.Server][main][from_filebeat] Starting server on port: 5044

```

As we can see it doesn't have the same setting

> "pipeline.workers"=\>16, "pipeline.max\_inflight"=\>2000, :thread=\>"#\<Thread:0x725c9ca4 run\>  
> "pipeline.workers"=\>8, "pipeline.max\_inflight"=\>1000, :thread=\>"#\<Thread:0x46e88eda run\>

It can be that ?

---

<div class="post-metadata">

**Author:** ![Dreinale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dreinale/32/106570_2.png) [@Dreinale](https://discuss.elastic.co/u/Dreinale)\
**Post date:** [June 9, 2022, 11:15am UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/6 "2022-06-09T11:15:48Z")

</div>

Ok i found the problem it's because i used

```auto
sudo firewall-cmd --add-port=9200/tcp --permanent

```

for the last Elasticsearch 8.2 now I need to do that for port 5044.

```auto
sudo firewall-cmd --add-port=5044/tcp --permanent
sudo firewall-cmd --add-port=9200/udp --permanent

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2022, 11:16am UTC](https://discuss.elastic.co/t/cant-etablish-connection-with-logstash-and-my-filebeat-7-17-1/306722/7 "2022-07-07T11:16:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
