# Error while forwarding logs from one machine to another machine

**URL:** <https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [January 12, 2020, 4:08pm UTC](https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734 "2020-01-12T16:08:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![xiaozhoz](https://avatars.discourse-cdn.com/v4/letter/x/4bbf92/32.png) [@xiaozhoz](https://discuss.elastic.co/u/xiaozhoz)\
**Post date:** [January 12, 2020, 4:08pm UTC](https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734/1 "2020-01-12T16:08:12Z")

</div>

Hi everyone, I want to send docker logs from machine B to machine A but get some errors. Any reply will be appreciated. 😀  
on machine A (IP: 52.80.xx.xx):

1. I set up ELK framework through docker-elk

```auto
sudo docker run \
        --rm \
        --ulimit nofile=1024:65536 \
        -p 5601:5601 -p 9200:9200 -p 5044:5044 \
        -d \
        --name elk \
        elk:latest

```

1. I get in this container and modify `/etc/logstash/conf.d/02-beats-input.conf` to

```auto
input {
  beats {
    port => 5044
  }
}

```

(do i need to do something to make this config active?)

on machine B:

1. rpm install filebeat
2. modify /etc/filebeat/filebeat.yml

```auto
output:
  logstash:
    enabled: true
    hosts: ["52.80.xx.xx:5044"]
    timeout: 15

filebeat:
  inputs:
    -
      type: docker
      containers.ids: '*'
    -
      paths:
        - /var/log/syslog
        - /var/log/auth.log
      document_type: syslog

```

1. restart filebeat and debug, get error

```auto
2020-01-12T15:46:00.899Z INFO pipeline/output.go:105 Connection to backoff(async(tcp://52.80.xx.xx:5044)) established
2020-01-12T15:46:00.920Z ERROR logstash/async.go:256 Failed to publish events caused by: lumberjack protocol error
2020-01-12T15:46:00.923Z ERROR logstash/async.go:256 Failed to publish events caused by: client is not connected

```

switch to machine A, get exception

```auto
020-01-12T16:06:21,101][WARN][io.netty.channel.DefaultChannelPipeline][main] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2020, 4:08pm UTC](https://discuss.elastic.co/t/error-while-forwarding-logs-from-one-machine-to-another-machine/214734/2 "2020-02-09T16:08:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
