# Filebeat 5.0 unable to send/publish logs to Logstash 5.0

**URL:** <https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 1, 2016, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614 "2016-11-01T18:59:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![VIJAYP](https://avatars.discourse-cdn.com/v4/letter/v/9e8a1a/32.png) [@VIJAYP](https://discuss.elastic.co/u/VIJAYP)\
**Post date:** [November 1, 2016, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/1 "2016-11-01T18:59:15Z")

</div>

Hi,

I am trying to monitor logs using Filebeat 5.0 from same host where ELK 5.0 is configured.

I see **i/o timeout errors** in /var/log/filebeat/filebeat:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/ce02828ec0865f4ce61b1c6034f81df4702914f6.png)

This is happening on some hosts. I did verify the connectivity and it looks ok.

**My filebeat.yml is as follows**

filebeat.prospectors:  
input\_type: log  
paths:

- /var/log/message  
document\_type: log

filebeat.registry\_file: /var/lib/filebeat/registry

output.logstash:  
hosts: ["10.50.50.139:5044"]  
index: filebeat  
bulk\_max\_size: 2048

**Logstash Configurations is as shown below:**

![](https://us1.discourse-cdn.com/elastic/original/2X/2/2a8c04ae4968cd96c521103ab18ecba338c25f0f.png)

![](https://us1.discourse-cdn.com/elastic/original/2X/9/952e325a02f769c40ee36befc7af1f71bcdbbd28.png)

I really appreciate all your help.

Thank you.  
Vj.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 2, 2016, 8:37am UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/2 "2016-11-02T08:37:26Z")

</div>

Why do you use an external IP if filebeat and LS are running on the same host? Do you see the error constantly or only from time to time?

---

<div class="post-metadata">

**Author:** ![VIJAYP](https://avatars.discourse-cdn.com/v4/letter/v/9e8a1a/32.png) [@VIJAYP](https://discuss.elastic.co/u/VIJAYP)\
**Post date:** [November 2, 2016, 3:52pm UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/3 "2016-11-02T15:52:33Z")

</div>

Hi,

Thanks for your reply.

You are correct. LS and filebeat are running on the same host. I changed the configuration back to localhost:

**hosts: ["localhost:5044"]**

**NOTE:** NGINX is installed in same host and it's up and running.

Now, I see the "filebeat-\*" index got created in elastic search ( little progress) and able to see some logs in kibana. But this happens only after stopping and starting logstash and filebeat. Every time I restart them I see logs being pushed to Elastic search. Otherwise, nothing happening.

Here's the filebeat Log:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c9d430e4c8eb39e1d33a010ebebbe7f3f03d4c69.png)

Here's the Logstash Log (logstash-plain.log):

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1261f7a5971a21ff47387f59a05e582d03725fee.png)

Please let me know if you need any other information related to configuration.

Appreciate all your help.

Best regards  
Vj.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 3, 2016, 8:38am UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/4 "2016-11-03T08:38:47Z")

</div>

Can you please post your log files as text? Pictures are very hard to read and its not possible to search inside. If the log is too big, paste it into a gist and link it here.

---

<div class="post-metadata">

**Author:** ![VIJAYP](https://avatars.discourse-cdn.com/v4/letter/v/9e8a1a/32.png) [@VIJAYP](https://discuss.elastic.co/u/VIJAYP)\
**Post date:** [November 3, 2016, 2:41pm UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/5 "2016-11-03T14:41:02Z")

</div>

Hi,

Thanks for your reply.

After spending quite some time and doing multiple trail and errors I finally able to get logstash working.

In my logstash output plugin configuration I have " **SNIFFING**" set to true even though I don't have Elastic Cluster.

I set " **sniffing =\> false**" which fixed the issue.

Thank you  
Vj.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2016, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-5-0-unable-to-send-publish-logs-to-logstash-5-0/64614/6 "2016-11-22T18:59:17Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
