# Error in shipping logs from Logstash to Elasticsearch

**URL:** <https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346>\
**Category:** Logstash\
**Created:** [February 10, 2016, 3:51am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346 "2016-02-10T03:51:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [February 10, 2016, 3:51am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/1 "2016-02-10T03:51:30Z")

</div>

Error while forwarding filebeat indexed logs from Logstash to Elasticsearch. Following is the content ¨Beats input: the pipeline is blocked, temporary refusing new connection.¨

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 4:33am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/2 "2016-02-10T04:33:42Z")

</div>

You've not really given us much to help with. How about providing some proper information?

What LS/ES/FB version?  
What does your LS config look like?

---

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [February 10, 2016, 4:43am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/3 "2016-02-10T04:43:47Z")

</div>

I am using Logstash 2.1, Filebeat 1.0.1.  
Following is the output file configuration of Logstash  
output {  
elasticsearch {  
hosts =\> ["172.27.59.93:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Also, I tried adding protocol =\> http, but on configtest, it gives me an error

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 5:33am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/4 "2016-02-10T05:33:43Z")

</div>

What's the error.

Please, provide more information like the full errors you see, otherwise it will end up us asking a million questions to get the information.

---

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [February 10, 2016, 5:35am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/5 "2016-02-10T05:35:36Z")

</div>

{:timestamp=\>"2016-02-10T11:05:04.274000+0530", :message=\>"CircuitBreaker::rescuing exceptions", :name=\>"Beats input", :exception=\>LogStash::SizedQueueTimeout::TimeoutError, :level=\>:warn}  
{:timestamp=\>"2016-02-10T11:05:04.275000+0530", :message=\>"Beats input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover.", :exception=\>LogStash::CircuitBreaker::HalfOpenBreaker, :level=\>:warn}  
{:timestamp=\>"2016-02-10T11:05:04.389000+0530", :message=\>"Beats input: the pipeline is blocked, temporary refusing new connection.", :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 28, 2016, 9:51pm UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/6 "2016-04-28T21:51:09Z")

</div>

any help in this problem ??

---

<div class="post-metadata">

**Author:** ![mnhan](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@mnhan](https://discuss.elastic.co/u/mnhan)\
**Post date:** [April 29, 2016, 3:07pm UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/7 "2016-04-29T15:07:15Z")

</div>

Does increasing the memory of the logstash host and its java heap help alleviate the issue? Not much to go on based on the error. Something is causing the pipeline to stall/slow down. Could be the logstash host is undersize. Is any output reaching the elasticsearch server? How busy is the elasticsearch host? is it keeping up with LS? Can you provide more info on your setup?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/error-in-shipping-logs-from-logstash-to-elasticsearch/41346/8 "2017-07-06T04:59:58Z")

</div>


