# Failed to connect to backoff elasticsearch

**URL:** <https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 27, 2019, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921 "2019-01-27T23:29:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gleon](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gleon](https://discuss.elastic.co/u/gleon)\
**Post date:** [January 27, 2019, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921/1 "2019-01-27T23:29:19Z")

</div>

Hello all, i'm begginer with ELK and having trouble shipping log events from filebeat to logstash.

The scenario consists in:  
Machine 1) Linux ubuntu 18.04 running oracle virtual box.  
Machine 2) Linux centos 7 virtualized machine on oracle virtual box; running logstash, elasticsearch and kibana.  
Machine 3) Linux centos 6 virtualized machine on oracle virtual box; running Mongo DB and filebeat with mongo module enabled,

Command "ping" for testing communication between the 3 machines succesfull.

The filebeat log reports:

ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://192.168.43.165:5044](http://192.168.43.165:5044))): Get [http://192.168.43.165:5044](http://192.168.43.165:5044): read tcp 192.168.43.200:38382-\>192.168.43.165:5044: read: connection reset by peer

I have this configuration on /etc/logstash/conf.d/logstash.conf  
input {  
beats {  
port =\> "5044"  
host =\> "192.168.43.165"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["192.168.43.165:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

The command netstat -tulnp on Linux centos 7 reports:  
tcp6 0 0 192.168.43.165:9200 :::\* LISTEN 1233/java  
tcp6 0 0 192.168.43.165:5044 :::\* LISTEN 5161/java  
tcp6 0 0 192.168.43.165:9300 :::\* LISTEN 1233/java

The command wget [http://192.168.43.165:5044](http://192.168.43.165:5044) executed on Machine 2 and 3 reports the following:  
--2019-01-27 20:23:13-- [http://192.168.43.165:5044/](http://192.168.43.165:5044/)  
Connecting to 192.168.43.165:5044... connected.  
HTTP request sent, awaiting response... Read error (Connection reset by peer) in headers.

¿why communication can not be established between filebeat and logstash ?

SOLVED:

the error was in file: /etc/filebeat/filebeat.yml

The line: output.elasticsearch: was uncommented and the line: output.logstash: was commented; so it was applying the logstash configuration to elasticsearch

Now it looks like this:

#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["192.168.43.165:5044"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2019, 11:29pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch/165921/2 "2019-02-24T23:29:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
