# ERR Failed to publish events caused by: write tcp - Filebeat

**URL:** <https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 19, 2017, 6:27pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983 "2017-06-19T18:27:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhilpawar1985](https://avatars.discourse-cdn.com/v4/letter/n/e68b1a/32.png) [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Post date:** [June 19, 2017, 6:27pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983/1 "2017-06-19T18:27:52Z")

</div>

Hey guys ,

Can someone please please help me resolve this . I am new to this trying to implement it prod environment ASAP .

017-06-19T14:16:10-04:00 **ERR Failed to publish events caused by: write tcp** 10.140.76.11:35266-\>10.140.223.89:5044: **write: connection reset by peer**  
2017-06-19T14:16:10-04:00 INFO Error publishing events (retrying): write tcp 10.140.76.11:35266-\>10.140.223.89:5044: write: connection reset by peer  
2017-06-19T14:16:10-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.write\_errors=1 libbeat.logstash.published\_but\_not\_acked\_events=2 libbeat.publisher.published\_events=2  
2017-06-19T14:16:40-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=6 libbeat.logstash.publish.write\_bytes=410 libbeat.logstash.published\_and\_acked\_events=2 publish.events=2 registrar.states.update=2 registrar.writes=1  
2017-06-19T14:17:10-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=6 libbeat.logstash.publish.write\_bytes=421 libbeat.logstash.published\_and\_acked\_events=2 libbeat.publisher.published\_events=2 publish.events=2 registrar.states.update=2 registrar.writes=1  
2017-06-19T14:17:40-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=6 libbeat.logstash.publish.write\_bytes=396 libbeat.logstash.published\_and\_acked\_events=4 libbeat.publisher.published\_events=4 publish.events=4 registrar.states.update=4 registrar.writes=1  
2017-06-19T14:18:10-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=6 libbeat.logstash.publish.write\_bytes=411 libbeat.logstash.published\_and\_acked\_events=2 libbeat.publisher.published\_events=2 publish.events=2 registrar.states.update=2 registrar.writes=1  
2017-06-19T14:18:40-04:00 INFO No non-zero metrics in the last 30s  
2017-06-19T14:19:10-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=6 libbeat.logstash.publish.write\_bytes=405 libbeat.logstash.published\_and\_acked\_events=2 libbeat.publisher.published\_events=2 publish.events=2 registrar.states.update=2 registrar.writes=1  
2017-06-19T14:19:40-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=2 libbeat.logstash.publish.read\_bytes=12 libbeat.logstash.publish.write\_bytes=1070 libbeat.logstash.published\_and\_acked\_events=12 libbeat.publisher.published\_events=12 publish.events=12 registrar.states.update=12 registrar.writes=2  
2017-06-19T14:20:10-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=2 libbeat.logstash.publish.read\_bytes=12 libbeat.logstash.publish.write\_bytes=1054 libbeat.logstash.published\_and\_acked\_events=10 libbeat.publisher.published\_events=10 publish.events=10 registrar.states.update=10 registrar.writes=2  
2017-06-19T14:20:40-04:00 INFO No non-zero metrics in the last 30s  
2017-06-19T14:21:10-04:00 ERR Failed to publish events caused by: write tcp 10.140.76.11:35456-\>10.140.223.89:5044: write: connection reset by peer  
2017-06-19T14:21:10-04:00 INFO Error publishing events (retrying): write tcp 10.140.76.11:35456-\>10.140.223.89:5044: write: connection reset by peer

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 20, 2017, 9:32am UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983/2 "2017-06-20T09:32:11Z")

</div>

please properly format logs and configuration files using the `</>` button in the toolbar.

Which filebeat version are you using?

Which logstash version are you using?

Can you share filebeat output configuration and logstash input configuration?

The error message indicates that Logstash, the host logstash is running (e.g. firewall) or some other network device did close the connection while filebeat did try to publish events. Filebeat will reconnect in this case and continue sending. Updating Logstash, the logstash-input-beats plugin might help. Also increase the `client_connectivity_timeout` setting for the beats input plugin in logstash.

---

<div class="post-metadata">

**Author:** ![Nikhilpawar1985](https://avatars.discourse-cdn.com/v4/letter/n/e68b1a/32.png) [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Post date:** [June 20, 2017, 2:07pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983/3 "2017-06-20T14:07:35Z")

</div>

Thanks  
lient\_connectivity\_timeout fixed the issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2017, 2:07pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-write-tcp-filebeat/89983/4 "2017-07-18T14:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
