# Connection Reset to Logstash

**URL:** <https://discuss.elastic.co/t/connection-reset-to-logstash/337242>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [June 29, 2023, 8:53pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242 "2023-06-29T20:53:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 29, 2023, 8:53pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242/1 "2023-06-29T20:53:07Z")

</div>

Trying to send Metricbeat to Logstash. Metricbeat logs don't throw any errors, but Logstash shows the following:

```auto
[2023-06-29T15:30:02,110][INFO][org.logstash.beats.BeatsHandler] [local: 192.168.1.78:5045, remote: 192.168.1.77:55099] Handling exception: java.net.SocketException: Connection reset (caused by: java.net.SocketException: Connection reset)
[2023-06-29T15:30:02,111][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
java.net.SocketException: Connection reset
	at sun.nio.ch.SocketChannelImpl.throwConnectionReset(SocketChannelImpl.java:394) ~[?:?]
	at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:426) ~[?:?]
	at io.netty.buffer.PooledByteBuf.setBytes(PooledByteBuf.java:256) ~[netty-buffer-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.buffer.AbstractByteBuf.writeBytes(AbstractByteBuf.java:1132) ~[netty-buffer-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.socket.nio.NioSocketChannel.doReadBytes(NioSocketChannel.java:357) ~[netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:151) ~[netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:788) ~[netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:724) ~[netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:650) ~[netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:562) [netty-transport-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:997) [netty-common-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-common-4.1.93.Final.jar:4.1.93.Final]
	at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-common-4.1.93.Final.jar:4.1.93.Final]
	at java.lang.Thread.run(Thread.java:833) [?:?]

```

My metricbeat.yml is:

```auto
metricbeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
http:
  enabled: true
  port: 5067
setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 0
  index.codec: best_compression
setup.dashboards.enabled: false
setup.kibana:
  host: "https://<redacted fqdn>:443"
  space.id: monitor-test
  username: "<redacted>"
  password: "<redacted>"
output.logstash:
  hosts: ["<redacted fqdn>:5045"]
processors:
  - add_host_metadata: ~
#logging.level: debug
monitoring:
  cluster_uuid: <redacted>
  elasticsearch:
    hosts: ["<redacted fqdn>:9200"]
    username: "<redacted>"
    password: "<redacted>"
    protocol: "https"
    ssl:
      enabled: true
      certificate_authorities:
        - |
          -----BEGIN CERTIFICATE-----
<redacted>
          -----END CERTIFICATE-----

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 30, 2023, 12:45pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242/2 "2023-06-30T12:45:15Z")

</div>

You should check [this](https://www.elastic.co/guide/en/beats/filebeat/current/publishing-ls-fails-connection-reset-by-peer.html) Params are explained [here](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#_ttl).

On the LS side, only param to set is [`client_inactivity_timeout`](https://github.com/logstash-plugins/logstash-input-beats/edit/main/docs/index.asciidoc). Default value is 60sec

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [June 30, 2023, 7:23pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242/3 "2023-06-30T19:23:01Z")

</div>

The reference documentation is usually my first stop.

> [@](#):
>
> make sure the firewall is not closing connections between Filebeat and Logstash, or set the `ttl` value in the [Logstash output](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html) to a value that’s lower than the maximum time allowed by the firewall, and set `pipelining` to 0 (pipelining cannot be enabled when `ttl` is used).

- Both client and server are on the same subnet, no firewall involved.
- TTL isn't explicitly set so it's using the default value of 0.
- The connection reset is occurring only on initial start of metricbeat before the agent has fully started, no data has yet been sent when the error occurs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2023, 9:23pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242/4 "2023-07-28T21:23:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
