# Filebeat 5.x can't send logs to Logstash (SSL and EOF)

**URL:** <https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 17, 2016, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216 "2016-10-17T18:53:08Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_Mahzoun](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mohammad\_Mahzoun](https://discuss.elastic.co/u/Mohammad_Mahzoun)\
**Post date:** [October 17, 2016, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/1 "2016-10-17T18:53:08Z")

</div>

I Have filebeat on one server and logstash on another server. I checked the certificates and they are correct. also logstash is running on 5044. but filebeat can't send anything and this is the log:

```
2016-10-17T14:50:09-04:00 INFO No non-zero metrics in the last 30s
2016-10-17T14:50:12-04:00 ERR Failed to publish events caused by: EOF
2016-10-17T14:50:12-04:00 INFO Error publishing events (retrying): EOF
2016-10-17T14:50:39-04:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.publish.write_bytes=253 libbeat.logstash.call_count.PublishEvents=1 libbeat.logstash.publish.read_errors=1 libbeat.logstash.published_but_not_acked_events=2045

```

what should i do?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 17, 2016, 6:56pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/2 "2016-10-17T18:56:22Z")

</div>

Have you done [this test with curl](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-tls-logstash.html#testing-tls-logstash) from the Filebeat host? What was the output?

Please share the configuration for Logstash and Filebeat. What OSes? What versions?

---

<div class="post-metadata">

**Author:** ![Mohammad\_Mahzoun](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mohammad\_Mahzoun](https://discuss.elastic.co/u/Mohammad_Mahzoun)\
**Post date:** [October 17, 2016, 7:17pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/3 "2016-10-17T19:17:13Z")

</div>

this is filebeat.yml

```
  output:
  logstash:
   enabled: true
hosts: ["<ip>:5044"]
worker: 1
tls:
  certificate_authorities: ["/etc/pki/tls/certs/logstash-beats.crt"]
  certificate: ["/etc/pki/tls/certs/logstash-beats.crt"]
  certificate_key: ["/etc/pki/tls/private/logstash-beats.keys"]

timeout: 15

 filebeat:
 prospectors:
-
  paths:
    - /var/log/secure
  document_type: syslog
-
  paths:
    - "/var/log/nginx/*.log"
  document_type: nginx-access

```

yes i'v done the test and output is :

```
 * About to connect() to <ip> port 5044 (#0)
* Trying <ip>...
* Connected to <ip> (<ip>) port 5044 (#0)
> GET / HTTP/1.1
> User-Agent: curl/7.29.0
> Host: <ip>:5044
> Accept: */*
> 
* Empty reply from server
* Connection #0 to host <ip> left intact
curl: (52) Empty reply from server

```

and this is my logstash config for beats input:

```
input{
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-beats.crt"
    ssl_key => "/etc/pki/tls/private/logstash-beats.key"
  }
}
```

---

<div class="post-metadata">

**Author:** ![Mohammad\_Mahzoun](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mohammad\_Mahzoun](https://discuss.elastic.co/u/Mohammad_Mahzoun)\
**Post date:** [October 17, 2016, 7:20pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/4 "2016-10-17T19:20:41Z")

</div>

filebeat is filebeat-5.0.0-rc1-x86\_64  
logstash is 2.4  
filebeat is running on centos 7  
and logstash on docker container

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 17, 2016, 7:28pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/5 "2016-10-17T19:28:14Z")

</div>

Can you please format your config with three backticks (`). (Example: [http://oi66.tinypic.com/eu1zph.jpg](http://oi66.tinypic.com/eu1zph.jpg))

What is your Logstash config?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 18, 2016, 1:26am UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/6 "2016-10-18T01:26:53Z")

</div>

It looks like the indentation of your config is wrong. It should look like:

```auto
output:
  logstash:
    enabled: true
    hosts: ["<ip>:5044"]
    worker: 1
    tls:
      certificate_authorities: ["/etc/pki/tls/certs/logstash-beats.crt"]
      # You haven't enable client authentication in Logstash so these aren't needed.
      #certificate: ["/etc/pki/tls/certs/logstash-beats.crt"]
      #certificate_key: ["/etc/pki/tls/private/logstash-beats.keys"]

```

---

<div class="post-metadata">

**Author:** ![Mohammad\_Mahzoun](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mohammad\_Mahzoun](https://discuss.elastic.co/u/Mohammad_Mahzoun)\
**Post date:** [October 18, 2016, 8:45am UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/7 "2016-10-18T08:45:38Z")

</div>

I change the config and remove those 2 lines, i still have the problem. everything looks fine but it doesn't work.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 18, 2016, 10:50am UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/8 "2016-10-18T10:50:25Z")

</div>

Since filebeat 5.0-beta1 the SSL/TLS settings have been changed to be more in line with other projects in the elastic stack. The `tls` section has been renamed to `ssl` for example.

---

<div class="post-metadata">

**Author:** ![Mohammad\_Mahzoun](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@Mohammad\_Mahzoun](https://discuss.elastic.co/u/Mohammad_Mahzoun)\
**Post date:** [October 18, 2016, 1:27pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/10 "2016-10-18T13:27:46Z")

</div>

I changed tls to ssl and create a new certificate and now it's ok.  
thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2016, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-5-x-cant-send-logs-to-logstash-ssl-and-eof/63216/11 "2016-11-07T18:53:09Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
