# Filebeat 5.5.2 Connection reset by peer

**URL:** <https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 6, 2017, 11:28pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090 "2017-10-06T23:28:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bkt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkt/32/48260_2.png) [@Bkt](https://discuss.elastic.co/u/Bkt)\
**Post date:** [October 6, 2017, 11:28pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/1 "2017-10-06T23:28:07Z")

</div>

Hello, I am getting connection reset when using filebeat to send the logs to logstash. When I restart filebeat, it does send the prior events but soon repeats the connection reset by peer event. I am using the filebeat version 5.5.2 and logstash version is 5.4.1 (I have two filebeat instances from different machines which send the data to the same logstash on a third machine, one works fine, the other one keeps running into this issue)

```
2017-10-06T15:41:13-07:00 INFO Starting prospector of type: log; id: 14053815997108757649
2017-10-06T15:41:13-07:00 INFO Prospector with previous states loaded: 1
2017-10-06T15:41:13-07:00 INFO Starting prospector of type: log; id: 3816360967876514380
2017-10-06T15:41:13-07:00 INFO Prospector with previous states loaded: 12
2017-10-06T15:41:13-07:00 INFO Starting prospector of type: log; id: 13958902202340005319
2017-10-06T15:41:13-07:00 INFO Prospector with previous states loaded: 1
2017-10-06T15:41:13-07:00 INFO Starting prospector of type: log; id: 6158945275295326147
2017-10-06T15:41:13-07:00 INFO Loading and starting Prospectors completed. Enabled prospectors: 4
2017-10-06T15:41:43-07:00 INFO Non-zero metrics in the last 30s: publish.events=15 registrar.states.current=15 registrar.states.update=15 registrar.writes=1
2017-10-06T15:42:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:42:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:43:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:43:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:44:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:44:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:44:43-07:00 INFO Harvester started for file: /scratch/alpha_logs/alpha_output.log
2017-10-06T15:45:13-07:00 INFO Non-zero metrics in the last 30s: filebeat.harvester.open_files=1 filebeat.harvester.running=1 filebeat.harvester.started=1 libbeat.logstash.call_count.PublishEvents=1 libbeat.logstash.publish.read_bytes=6 libbeat.logstash.publish.write_bytes=372 libbeat.logstash.published_and_acked_events=1 libbeat.publisher.published_events=1 publish.events=2 registrar.states.update=2 registrar.writes=2
2017-10-06T15:45:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:46:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:46:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:47:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:47:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:48:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:48:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:49:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:49:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:49:54-07:00 ERR Failed to publish events caused by: write tcp 10.196.27.243:28765->10.242.132.9:5044: write: connection reset by peer
2017-10-06T15:49:54-07:00 INFO Error publishing events (retrying): write tcp 10.196.27.243:28765->10.242.132.9:5044: write: connection reset by peer
2017-10-06T15:50:13-07:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call_count.PublishEvents=2 libbeat.logstash.publish.read_bytes=6 libbeat.logstash.publish.write_bytes=358 libbeat.logstash.publish.write_errors=1 libbeat.logstash.published_and_acked_events=1 libbeat.logstash.published_but_not_acked_events=1 libbeat.publisher.published_events=1 publish.events=1 registrar.states.update=1 registrar.writes=1
2017-10-06T15:50:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:51:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:51:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:52:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:52:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:53:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:53:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:54:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:54:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:54:59-07:00 ERR Failed to publish events caused by: write tcp 10.196.27.243:29354->10.242.132.9:5044: write: connection reset by peer
2017-10-06T15:54:59-07:00 INFO Error publishing events (retrying): write tcp 10.196.27.243:29354->10.242.132.9:5044: write: connection reset by peer
2017-10-06T15:55:13-07:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call_count.PublishEvents=2 libbeat.logstash.publish.read_bytes=6 libbeat.logstash.publish.write_bytes=358 libbeat.logstash.publish.write_errors=1 libbeat.logstash.published_and_acked_events=1 libbeat.logstash.published_but_not_acked_events=1 libbeat.publisher.published_events=1 publish.events=1 registrar.states.update=1 registrar.writes=1
2017-10-06T15:55:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:56:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:56:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:57:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:57:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:58:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:58:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:59:13-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:59:43-07:00 INFO No non-zero metrics in the last 30s
2017-10-06T15:59:54-07:00 ERR Failed to publish events caused by: write tcp 10.196.27.243:29933->10.242.132.9:5044: write: connection reset by peer
2017-10-06T15:59:54-07:00 INFO Error publishing events (retrying): write tcp 10.196.27.243:29933->10.242.132.9:5044: write: connection reset by peer
2017-10-06T16:00:13-07:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.call_count.PublishEvents=2 libbeat.logstash.publish.read_bytes=6 libbeat.logstash.publish.write_bytes=363 libbeat.logstash.publish.write_errors=1 libbeat.logstash.published_and_acked_events=1 libbeat.logstash.published_but_not_acked_events=1 libbeat.publisher.published_events=1 publish.events=1 registrar.states.update=1 registrar.writes=1
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2017, 11:36pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/2 "2017-10-06T23:36:45Z")

</div>

Is there a firewall or load balancer in use somewhere?

---

<div class="post-metadata">

**Author:** ![Bkt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkt/32/48260_2.png) [@Bkt](https://discuss.elastic.co/u/Bkt)\
**Post date:** [October 6, 2017, 11:43pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/3 "2017-10-06T23:43:26Z")

</div>

nope just two boxes on the same network

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 8, 2017, 11:10am UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/4 "2017-10-08T11:10:33Z")

</div>

Can you check the logstash-input-beats version as well?

It might be logstash closing the connection, due to filebeat being idle for quite some time. It's almost 5 minutes from last ACK until next batch events are published.

You might consider to increase the [client\_inactivity\_timeout](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-client_inactivity_timeout) to 600 seconds (default is 60 seconds).

---

<div class="post-metadata">

**Author:** ![Bkt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkt/32/48260_2.png) [@Bkt](https://discuss.elastic.co/u/Bkt)\
**Post date:** [October 10, 2017, 8:02pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/5 "2017-10-10T20:02:03Z")

</div>

The beats version is 3.1.15, I have made the change to add the client\_inactivity\_timeout =\> 600, will update after watching the logs for some time, thank you Steffen for taking the time out to read this and respond

---

<div class="post-metadata">

**Author:** ![Bkt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bkt/32/48260_2.png) [@Bkt](https://discuss.elastic.co/u/Bkt)\
**Post date:** [October 10, 2017, 8:21pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/6 "2017-10-10T20:21:45Z")

</div>

seems the client\_inactivity\_timeout resolved the issue Thank you @steffens for your valuable inputs

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2017, 8:21pm UTC](https://discuss.elastic.co/t/filebeat-5-5-2-connection-reset-by-peer/103090/7 "2017-11-07T20:21:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
