# Filebeat 6.3.2 / Logstash 6.3.2

**URL:** <https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594>\
**Category:** Beats\
**Created:** [August 1, 2018, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594 "2018-08-01T14:32:58Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tusune](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@Tusune](https://discuss.elastic.co/u/Tusune)\
**Post date:** [August 1, 2018, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/1 "2018-08-01T14:32:59Z")

</div>

Hello !

Today i've tried to make filebeat (that is on one of my servers) send logs to another server, that have logstash, elasticsearch and kibana.

I've got some problems and one in particular that i can't find a solution, here the logs of it :

```
ERROR	logstash/async.go:235	Failed to publish events caused by: write tcp 192.168.250.88:50022->192.168.250.224:5044: write: connection reset by peer

```

I've seen some posts with the same problem, and some say that updating a plugin will solve this, but i never installed any plugin, or is there included plugins when installing logstash ?  
So yet i can't resolve this, look forward for your help 🙂

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 1, 2018, 4:36pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/2 "2018-08-01T16:36:49Z")

</div>

> [@Tusune](#):
>
> but i never installed any plugin, or is there included plugins when installing logstash ?

Each input/filter/output is a plugin to Logstash. Many are bundled with Logstash (e.g. logstash-input-beats). They updatable independent of the main Logstash install. See [Updating the Beats Input Plugin for Logstash](https://www.elastic.co/guide/en/beats/libbeat/5.6/logstash-installation.html#logstash-input-update).

Have you testing the connection via `filebeat test output`?

Or tested it via telnet?

If neither of those tests are able to connected then log onto the Logstash server and verify that it is listening with a command like `sudo netstat -anp | grep 5033`.

---

<div class="post-metadata">

**Author:** ![Tusune](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@Tusune](https://discuss.elastic.co/u/Tusune)\
**Post date:** [August 2, 2018, 12:03pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/3 "2018-08-02T12:03:46Z")

</div>

The `Filebeat test output` is ok, but telnet do not look ok, can't connect, tried why `telnet myip` and `telnet myip 5044` , the first don't work and with 5044, when i type something it close the connection (i use iptables on my ELK server, and i authorize ports 22, 9200, 5601 and 5044, is there an other one to authorize for filebeat ?

When doing `sudo netstat -anp | grep 5033` no output.

Also, in my filebeat log, sometime there is :  
`ERROR	logstash/async.go:235	Failed to publish events caused by: write tcp IPclient:41148->IPserver:5044: write: connection reset by peer`  
`ERROR	pipeline/output.go:92	Failed to publish events: write tcp IPclient:41148->IPserver:5044: write: connection reset by peer`

(Sorry for the late answer, was working on something else)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 2, 2018, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/4 "2018-08-02T21:24:35Z")

</div>

> [@Tusune](#):
>
> When doing `sudo netstat -anp | grep 5033` no output.

How about with 5044? 🙂 my bad

But if `filebeat test output` is passing and `telnet <ip> 5044` connects (it's normal to have it disconnect you after you type something because it rejects that input and resets the connection) then it seems like connection is being established OK.

So the next step is to inspect the Logstash logs (start LS with `-debug`) and see if there are any errors while Filebeat is sending data. It would be useful if you shared the LS configuration that you are using too.

Another test you can do is to disable all outputs in your Logstash config and add only a single stdout output. This way the outputs cannot block the pipeline.

```auto
output { 
  stdout { 
    codec => rubydebug {
      metadata => true
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Tusune](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@Tusune](https://discuss.elastic.co/u/Tusune)\
**Post date:** [August 2, 2018, 9:36pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/5 "2018-08-02T21:36:07Z")

</div>

Okay 🙂 i'll do that tomorrow and tell you the results 🙂

---

<div class="post-metadata">

**Author:** ![Tusune](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@Tusune](https://discuss.elastic.co/u/Tusune)\
**Post date:** [August 3, 2018, 8:01am UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/6 "2018-08-03T08:01:54Z")

</div>

So `sudo netstat -anp | grep 5033` is ok.

Now i can't find anything like bin/logstash, there is a dir /opt/logstash/bin, but nothing in there, the only one that seem like that is in /usr/share, does it matter ? Or i need to install something ?

For the configuration : (in /etc/logstash/conf.d/logstash.conf)

```
input {
    beats {
           	port => 5044
            client_inactivity_timeout => 3000
    }
}

output {
    elasticsearch {
            hosts => "myipserver:9200"
            manage_template => false
            index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
            document_type => "%{[@metadata][type]}"
    }
}

```

There's also a /etc/logstash/logstash.yml, isnt that the conf file or its something else ?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 3, 2018, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/7 "2018-08-03T14:18:08Z")

</div>

The location depends on how it was installed. The paths are documented [here](https://www.elastic.co/guide/en/logstash/6.3/dir-layout.html).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 3, 2018, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/8 "2018-08-03T14:21:53Z")

</div>

Your config deviates from what [we recommend](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/get-started-elastic-stack.html#logstash-setup). Specifically the index name differs. We include the version there an the default index template only apply to indexes containing a version.

```auto
output {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
  }
}

```

And since you are using Logstash, make sure that you [installed the index template to Elasticsearch](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually-alternate).

---

<div class="post-metadata">

**Author:** ![Tusune](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@Tusune](https://discuss.elastic.co/u/Tusune)\
**Post date:** [August 3, 2018, 2:27pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/9 "2018-08-03T14:27:41Z")

</div>

Actually i don't see any error when sending directly to elasticsearch, just when sending to logstash, just many `Non-zero metrics in the last 30s`.  
Anyway, i can't figure out why my ELK server, on Kibana, don't receive logs (he receive, but in discover i can see like 1 count per day), maybe my tested servers are just not active enought ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 4:27pm UTC](https://discuss.elastic.co/t/filebeat-6-3-2-logstash-6-3-2/142594/10 "2018-08-31T16:27:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
