# Error connection between filebeat and logstash

**URL:** <https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 13, 2019, 10:08am UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782 "2019-05-13T10:08:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gionata\_Donati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gionata_donati/32/46074_2.png) [@Gionata\_Donati](https://discuss.elastic.co/u/Gionata_Donati)\
**Post date:** [May 13, 2019, 10:08am UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782/1 "2019-05-13T10:08:51Z")

</div>

Hello, everyone,  
I have a problem with the communication of filebeat and elasticsearch.

I have recently configured SSL for communication between filebeat and logstash.  
As from the site the certificates have been set correctly 🙂  
`curl -v --cacert /etc/filebeat/logstash.crt https://10.164.88.7:504`

- Rebuilt URL to: [https://10.164.88.7:5044/](https://10.164.88.7:5044/)
- Trying 10.164.88.7...
- TCP\_NODELAY set
- Connected to 10.164.88.7 (10.164.88.7) port 5044 (#0)
- ALPN, offering h2
- ALPN, offering http/1.1
- successfully set certificate verify locations:
- CAfile: /etc/filebeat/logstash.crt  
CApath: /etc/ssl/certs
- TLSv1.2 (OUT), TLS handshake, Client hello (1):
- TLSv1.2 (IN), TLS handshake, Server hello (2):
- TLSv1.2 (IN), TLS handshake, Certificate (11):
- TLSv1.2 (IN), TLS handshake, Server key exchange (12):
- TLSv1.2 (IN), TLS handshake, Server finished (14):
- TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
- TLSv1.2 (OUT), TLS change cipher, Client hello (1):
- TLSv1.2 (OUT), TLS handshake, Finished (20):
- TLSv1.2 (IN), TLS handshake, Finished (20):
- SSL connection using TLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384
- ALPN, server did not agree to a protocol
- Server certificate:
- subject: C=AU; ST=Some-State; O=Internet Widgits Pty Ltd
- start date: May 13 09:19:34 2019 GMT
- expire date: May 12 09:19:34 2020 GMT
- subjectAltName: host "10.164.88.7" matched cert's IP address!
- issuer: C=AU; ST=Some-State; O=Internet Widgits Pty Ltd
- SSL certificate verify ok.

> GET / HTTP/1.1  
> Host: 10.164.88.7:5044  
> User-Agent: curl/7.58.0  
> Accept: _/_

- TLSv1.2 (IN), TLS alert, Client hello (1):
- Empty reply from server
- Connection #0 to host 10.164.88.7 left intact  
curl: (52) Empty reply from server

But when I try to visualize the data on Kibana, the logs do not arrive  
So I tried to understand the problem.

2019/05/13 10:04:31.080358 beat.go:297: INFO Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
2019/05/13 10:04:31.080397 beat.go:192: INFO Setup Beat: filebeat; Version: 5.6.16  
2019/05/13 10:04:31.080497 metrics.go:23: INFO Metrics logging every 30s  
2019/05/13 10:04:31.080754 logstash.go:91: INFO Max Retries set to: 3  
2019/05/13 10:04:31.080810 outputs.go:108: INFO Activated logstash as output plugin.  
2019/05/13 10:04:31.080893 publish.go:300: INFO Publisher name: client8818  
2019/05/13 10:04:31.081083 async.go:63: INFO Flush Interval set to: 1s  
2019/05/13 10:04:31.081097 async.go:64: INFO Max Bulk Size set to: 2048  
2019/05/13 10:04:31.081346 beat.go:233: INFO filebeat start running.  
2019/05/13 10:04:31.081388 registrar.go:85: INFO Registry file set to: /var/lib/filebeat/registry  
2019/05/13 10:04:31.081421 registrar.go:106: INFO Loading registrar data from /var/lib/filebeat/registry  
2019/05/13 10:04:31.081796 registrar.go:123: INFO States Loaded from registrar: 10  
2019/05/13 10:04:31.081837 crawler.go:38: INFO Loading Prospectors: 1  
2019/05/13 10:04:31.081927 registrar.go:236: INFO Starting Registrar  
2019/05/13 10:04:31.081936 sync.go:41: INFO Start sending events to output  
2019/05/13 10:04:31.081978 prospector\_log.go:65: INFO Prospector with previous states loaded: 10  
2019/05/13 10:04:31.082073 spooler.go:63: INFO Starting spooler: spool\_size: 2048; idle\_timeout: 5s  
2019/05/13 10:04:31.082104 prospector.go:124: INFO Starting prospector of type: log; id: 17005676086519951868  
2019/05/13 10:04:31.082127 crawler.go:58: INFO Loading and starting Prospectors completed. Enabled prospectors: 1  
2019/05/13 10:04:51.083662 log.go:91: INFO Harvester started for file: /var/log/auth.log  
2019/05/13 10:05:01.080934 metrics.go:39: INFO Non-zero metrics in the last 30s: filebeat.harvester.open\_files=1 filebeat.harvester.running=1 filebeat.harvester.started=1 libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_bytes=1425 libbeat.logstash.publish.write\_bytes=746 libbeat.logstash.published\_and\_acked\_events=3 libbeat.publisher.published\_events=3 publish.events=14 registrar.states.current=10 registrar.states.update=14 registrar.writes=2

I don't understand why, I have activated both on SSL logstash and on the Filebeat configuration file.

Filebeat.yml:

\</\>###################### Filebeat Configuration Example #########################

# This file is an example configuration file highlighting only the most common

# options. The filebeat.full.yml file from the same directory contains all the

# supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [Filebeat Reference | Elastic](https://www.elastic.co/guide/en/beats/filebeat/index.html)

#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

- input\_type: log

#================================ Outputs =====================================

# Configure what outputs to use when sending the data collected by the beat.

# Multiple outputs may be used.

#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["10.164.88.7:5044"]  
ssl.certificate\_authorities: ["/etc/filebeat/logstash.crt"]

# ssl.certificate\_authorities: ["/etc/ca.crt"]

# ssl.certificate: "/etc/beat.crt"

# ssl.key: "/etc/beat.key"

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/ca.crt"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/beat.crt"

# Client Certificate Key

#ssl.key: "/etc/beat.key"

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: critical, error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]

02-beats-input.conf:  
\</\> input {  
beats {  
port =\> 5044  
codec =\> "json\_lines"  
ssl =\> true  
ssl\_certificate =\> "/etc/logstash/logstash.crt"  
ssl\_key =\> "/etc/logstash/logstash.key"  
client\_inactivity\_timeout =\> "86400"  
}  
}

Could you help me? Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 13, 2019, 12:27pm UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782/2 "2019-05-13T12:27:24Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

I'm moving your post to #beats:filebeat

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 14, 2019, 1:57pm UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782/3 "2019-05-14T13:57:06Z")

</div>

Please properly format your post, it's really hard to follow.

Filebeat did actually send events. And 3 have been ACKed by Logstash.

From logs it looks like you are using Filebeat 1.x or 5.x. Both are End of Life. I'd recomment to switch to Filebeat 7 or 6.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2019, 1:57pm UTC](https://discuss.elastic.co/t/error-connection-between-filebeat-and-logstash/180782/4 "2019-06-11T13:57:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
