# ERR Failed to publish events caused by: read tcp IP:40634-\>IP:5044: i/o timeout

**URL:** <https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-ip-40634-ip-5044-i-o-timeout/90355>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 21, 2017, 8:12pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-ip-40634-ip-5044-i-o-timeout/90355 "2017-06-21T20:12:50Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 23, 2017, 10:18am UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-ip-40634-ip-5044-i-o-timeout/90355/6 "2017-06-23T10:18:36Z")

</div>

A slow/stale logstash should not result into an i/o timeout error. As Logstash should send a heartbeat signal every 5 seconds if a batch of events is in progress.

Where are filebeat and logstash running and how are they connected? Any firewalls, NAT, other network equipment in the middle, potentially closing/dropping connections?

As workaround, increase the `timeout` setting in the filebeat logstash output (defaults to 60 seconds). And see how it goes. I wonder if it's due to LS not sending the heartbeat, or network equipment.

---

_[View the full topic](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-ip-40634-ip-5044-i-o-timeout/90355)._
