# Error connecting to Elasticsearch messages while starting filebeat

**URL:** <https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 30, 2019, 8:07am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806 "2019-10-30T08:07:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [October 30, 2019, 8:07am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/1 "2019-10-30T08:07:56Z")

</div>

Dear All,  
my instance details are

**Kibana version** : 7.4.1   
**Elasticsearch version** : 7.4.1  
\*\*filebeat version \*\* 7.4.1  
**APM Agent language and version** : NA  
**Logstash version** 7.4.1-1

From my clients, I can telnet to the port 5044 of the elasticsearch server

```
telnet 192.168.3.191 5044
Trying 192.168.3.191...
Connected to 192.168.3.191.
Escape character is '^]'.

```

ie logstash port is open, now from the client machine when I run filebeat I am getting the following error

> |019-10-30T11:51:36.757+0400|ERROR|elasticsearch/elasticsearch.go:260|Error connecting to Elasticsearch at [http://192.168.3.191:5044](http://192.168.3.191:5044): Get [http://192.168.3.191:5044](http://192.168.3.191:5044): read tcp 10.212.135.200:55782-\>192.168.3.191:5044: read: connection reset by peer|
> 
> |2019-10-30T11:51:36.757+0400|ERROR|fileset/factory.go:131|Error loading pipeline: Error creating Elasticsearch client: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch [http://192.168.3.191:5044](http://192.168.3.191:5044): Get [http://192.168.3.191:5044](http://192.168.3.191:5044): read tcp **10.212.135.200:55782-\>192.168.3.191:5044** : read: connection reset by peer]|
> 
> |2019-10-30T11:51:36.786+0400|ERROR|elasticsearch/elasticsearch.go:260|Error connecting to Elasticsearch at [http://192.168.3.191:5044](http://192.168.3.191:5044): Get [http://192.168.3.191:5044](http://192.168.3.191:5044): read tcp **10.212.135.200:55784-\>192.168.3.191:5044** : read: connection reset by peer|

When I observer this message, I could see an " **10.212.135.200**", why this IP is refered, I am doing the setup in my LAN enviornment, and I do not have a public IP address and how this **10.212.135.200** us coming in my log files

Advise requested to know why this IP occurrence and why my filebeat is not able to communicate to the logstash server (logstash server uou can telnet to port 5044)

thanks  
Joseph John

---

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [October 30, 2019, 8:23am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/2 "2019-10-30T08:23:34Z")

</div>

Like to update  
when I give route -n

route -n  
Kernel IP routing table  
Destination Gateway Genmask Flags Metric Ref Use Iface  
0.0.0.0 192.168.10.1 0.0.0.0 UG 600 0 0 wlp3s0  
169.254.0.0 0.0.0.0 255.255.0.0 U 1000 0 0 virbr0  
**192.168.3.0 10.212.135.200 255.255.255.0 UG 0 0 0 ppp0**  
192.168.10.0 0.0.0.0 255.255.255.0 U 600 0 0 wlp3s0  
192.168.122.0 0.0.0.0 255.255.255.0 U 0 0 0 virbr0  
217.165.140.179 192.168.10.1 255.255.255.255 UGH 0 0 0 wlp3s0

So it is reaching out to the gateway throuhh pp0

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 30, 2019, 8:40am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/3 "2019-10-30T08:40:45Z")

</div>

Based on the errors you have shared it seems that Filebeat is trying to Elasticsearch not Logstash. I assume you accidentally configured the ES output. But it is difficult to say anything without a configuration. Could you please share your configuration and format it using `</>`?

---

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [October 30, 2019, 10:53am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/4 "2019-10-30T10:53:31Z")

</div>

Hi Noemi,  
thanks, I am posting the conf files, first section I am posting the server conf and then at the clients side

Server Conf Details

Elasticsearch  
cat /etc/elasticsearch/elasticsearch.yml

> path.data: /var/lib/elasticsearch  
> path.logs: /var/log/elasticsearch  
> discovery.type: single-node  
> network.host: 192.168.3.191

Kibana  
cat /etc/kibana/kibana.yml

> server.host: "0.0.0.0"  
> elasticsearch.hosts: ["[http://192.168.3.191:9200](http://192.168.3.191:9200)"]

**LogStash (at elasticsearch server)**  
**cat /etc/logstash/logstash.yml**

> ```
> path.data: /var/lib/logstash
> http.host: "192.168.3.191"
> http.port: 9600-9700
> log.level: error
> path.logs: /var/log/logstash
> 
> ```

from the client for the filebeat and auditbeat  
**/etc/auditbeat/auditbeat.yml**

> auditbeat.modules:
> 
> - module: auditd  
> audit\_rule\_files: ['${path.config}/audit.rules.d/\*.conf']  
> audit\_rules: |
> - module: file\_integrity  
> paths:
> - /bin
> - /usr/bin
> - /sbin
> - /usr/sbin
> - /etc
> 
> - module: system  
> datasets:
> - host # General host information, e.g. uptime, IPs
> - login # User logins, logouts, and system boots.
> - package # Installed, updated, and removed packages
> - process # Started and stopped processes
> - socket # Opened and closed sockets
> - user # User information  
> state.period: 12h  
> user.detect\_password\_changes: true  
> login.wtmp\_file\_pattern: /var/log/wtmp\*  
> login.btmp\_file\_pattern: /var/log/btmp\*  
> setup.template.settings:  
> index.number\_of\_shards: 1  
> setup.kibana:  
> host: "192.168.3.191:5601"  
> _\> output.elasticsearch:_  
> _\> hosts: ["192.168.3.191:9200"]_  
> _\> hosts: ["192.168.3.191:5044"]_  
> processors:
> - add\_host\_metadata: ~
> - add\_cloud\_metadata: ~  
> logging.level: error

from the client filebeat  
**/etc/filebeat/filebeat.yml**

```
filebeat.inputs:
- type: log
  enabled: false
  paths:
    - /var/log/*.log
    #- c:\programdata\elasticsearch\logs\*
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
  host: "192.168.3.191:5601"
output.elasticsearch:
  hosts: ["192.168.3.191:9200"]
  hosts: ["192.168.3.191:5044"]
processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
logging.level: error

```

---

<div class="post-metadata">

**Author:** ![Joseph\_John](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_john/32/53907_2.png) [@Joseph\_John](https://discuss.elastic.co/u/Joseph_John)\
**Post date:** [October 30, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/5 "2019-10-30T11:12:21Z")

</div>

thanks for the lead , now I commented out the output to elasticsearch and enabled output to logstash and it is working now

> output.logstash:  
> hosts: ["192.168.3.191:5044"]

THANKS A LOT

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connecting-to-elasticsearch-messages-while-starting-filebeat/205806/6 "2019-11-27T11:12:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
