# Error connection Logstash

**URL:** <https://discuss.elastic.co/t/error-connection-logstash/206760>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [November 6, 2019, 9:07am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760 "2019-11-06T09:07:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonny3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny3/32/50275_2.png) [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Post date:** [November 6, 2019, 9:07am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760/1 "2019-11-06T09:07:05Z")

</div>

Hi everyone, I started a few weeks ago to work with ELK and Filebeat in a Docker system for an university project. I have working the ELK, Kibana detect everything, including Beats, now I'm configuring Filebeat to send the logs to Logstash but I have an error when Filebeat tries to send something.

> ERROR [centralmgmt.event\_reporter] api/event\_reporter.go:90 could not send events, error: 1 error: Beat "id\_number" not found

The id\_number of my Filebeat and the id\_number that Kibana give me when I enroll Beats are different. I read about it and I think that I can't put that number in a manual way, it's automatic, and I don't know how to resolve this.

I put my Filebeat configuration, maybe I have things wrong.

```
management:
  enabled: true
  period: 1m0s
  events_reporter:
    period: 30s
    max_batch_size: 1000
  access_token: (Kibana_enroll_number)
  kibana:
    protocol: http
    host: localhost:5601
    ssl: null
    timeout: 10s
    ignoreversion: true
  blacklist:
    output: console|file

filebeat.inputs:
- type: log
  enabled: true
  paths:
    - (...)\logs\*.log
output.logstash:
  hosts: ["localhost:5000"] < The port usually is 5044 but I put this.

```

Greetings.

---

<div class="post-metadata">

**Author:** ![Jeremy\_Gachet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_gachet/32/50275_2.png) [@Jeremy\_Gachet](https://discuss.elastic.co/u/Jeremy_Gachet)\
**Post date:** [November 11, 2019, 9:51am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760/2 "2019-11-11T09:51:00Z")

</div>

Same issue here, do you find any answer ?

---

<div class="post-metadata">

**Author:** ![Jonny3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny3/32/50275_2.png) [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Post date:** [November 15, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760/3 "2019-11-15T11:12:24Z")

</div>

I already solved my problem, I honestly don't understand exactly the error, maybe I modified too much without knowing, I started again, I _enroll_ again and without touching anything of the Filebeat configuration (_.yml_ files), it worked, I configured the input and output of the Beat in Kibana and I had no more problems.

In Kibana, in the Beat section, you have the "Enrolled Beats" and the "Configuration tags", the last one is used to create configurations of the output, input, modules, etc. (_Configuration blocks_) and use them as a tag for enrolled beats.

I think I didn't change anything else.

I use this command for send the logs with Filebeat and it works, I see in Kibana the Logs.

> C:\Program Files\Filebeat\> ./filebeat -c filebeat.yml -e

Greetings and good luck.

(My English is not the best 🙂 )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2019, 11:12am UTC](https://discuss.elastic.co/t/error-connection-logstash/206760/4 "2019-12-13T11:12:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
