# Filebeat - 127.0.0.1:5044: write: connection reset by peer

**URL:** <https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321>\
**Category:** Beats\
**Created:** [May 2, 2017, 8:03pm UTC](https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321 "2017-05-02T20:03:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wb303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wb303/32/17625_2.png) [@wb303](https://discuss.elastic.co/u/wb303)\
**Post date:** [May 2, 2017, 8:03pm UTC](https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321/1 "2017-05-02T20:03:43Z")

</div>

For some reason, when I have logstash running locally on the same server as the beat service I get constant connection resets. There is no SSL configured and the only input. There is no firewall running. This is the current beats and logstash 5.3.

input {  
beats {  
port =\> 5044  
}

And only one output:  
output {  
amazon\_es {  
hosts =\> ["[xxx.us-east-1.es.amazonaws.com](http://xxx.us-east-1.es.amazonaws.com)"]  
region =\> "us-east-1"  
# aws\_access\_key\_id, aws\_secret\_access\_key optional if instance profile is configured  
aws\_access\_key\_id =\> 'xxxx'  
aws\_secret\_access\_key =\> 'xxxx'  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}

On the same server metricbeat is successfully running connecting to the same port.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 3, 2017, 4:14am UTC](https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321/2 "2017-05-03T04:14:17Z")

</div>

It's probably the [client\_inactivity\_timeout](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-client_inactivity_timeout) at work. Can you try increasing the value.

---

<div class="post-metadata">

**Author:** ![wb303](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wb303/32/17625_2.png) [@wb303](https://discuss.elastic.co/u/wb303)\
**Post date:** [May 3, 2017, 4:27pm UTC](https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321/3 "2017-05-03T16:27:34Z")

</div>

Changing /etc/logstash/conf.d/inputs to

input {  
beats {  
port =\> 5044  
client\_inactivity\_timeout =\> 240  
}

Seems to alleviate the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 8:17pm UTC](https://discuss.elastic.co/t/filebeat-127-0-0-1-5044-write-connection-reset-by-peer/84321/4 "2017-05-23T20:17:35Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
