# Filebeat 7.10.2: connection reset by peer Error flooding in filebeat log

**URL:** <https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 23, 2023, 7:53am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826 "2023-11-23T07:53:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![epadmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/epadmav/32/127306_2.png) [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Post date:** [November 23, 2023, 7:53am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826/1 "2023-11-23T07:53:28Z")

</div>

Hi,

We have a cluster in which we're inconsistently observing the below errors filbeat.log within time periods of 5mins/10mins/15mins so on, when using filebeat to send logs to logstash.

2023-11-23T04:40:07.524+0100 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: write tcp 214.5.244.8:44990-\>214.5.244.7:5046: write: connection reset by peer  
2023-11-23T04:40:08.989+0100 ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: write tcp 214.5.244.8:44990-\>214.5.244.7:5046: write: connection reset by peer  
2023-11-23T05:20:06.273+0100 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: write tcp 214.5.244.8:51342-\>214.5.244.6:5046: write: connection reset by peer  
2023-11-23T05:20:07.667+0100 ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: write tcp 214.5.244.8:51342-\>214.5.244.6:5046: write: connection reset by peer  
2023-11-23T05:50:06.940+0100 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: write tcp 214.5.244.8:49108-\>214.5.244.6:5046: write: connection reset by peer  
2023-11-23T05:50:08.620+0100 ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: write tcp 214.5.244.8:49108-\>214.5.244.6:5046: write: connection reset by peer  
2023-11-23T06:20:07.473+0100 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: write tcp 214.5.244.8:55956-\>214.5.244.6:5046: write: connection reset by peer  
2023-11-23T06:20:09.024+0100 ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: write tcp 214.5.244.8:55956-\>214.5.244.6:5046: write: connection reset by peer  
~  
We already have "client\_inactivity\_timeout =\> 900" set in logstash configuration and have below ttl option set in filebeat.yml

Filebeat.yml

```auto
output:
  logstash:
    hosts: ["<host1>,<host2>,<host3>"]
    loadbalance: true
    ttl: 60

```

These are the filebeat and logstash version we're using:  
**filebeat version - filebeat-7.10.2-1.x86\_64**  
**logstash version - logstash-oss-8.4.0-1.x86\_64**

Could you please help here.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Ljapunov](https://avatars.discourse-cdn.com/v4/letter/l/f4b2a3/32.png) [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Post date:** [November 24, 2023, 11:10am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826/2 "2023-11-24T11:10:43Z")

</div>

Can you show your Logstash Input definition as well please?

Is logstash receiving logs despite the errorlogs? (I am used to have these Errorlines in filebeat-logs from time to time)

---

<div class="post-metadata">

**Author:** ![epadmav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/epadmav/32/127306_2.png) [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Post date:** [November 26, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826/3 "2023-11-26T16:31:18Z")

</div>

Hi,  
Thanks for looking into the issue.  
Please find the logstash input configuration:

```auto
input {
  beats {
    port => 5046
    client_inactivity_timeout => 900
    ssl => true
    ssl_certificate_authorities => "xxxx"
    ssl_certificate => "xxxx"
    ssl_key => "xxxx"
    ssl_verify_mode => force_peer
    tls_min_version => 1.2
  }
  tcp {
    id => "rsyslog-port"
    port => 6514
    type => "rsyslog-ssl"
    add_field => ["xxxx", "xxxx"]
    ssl_enable => true
    ssl_certificate_authorities => "xxxx"
    ssl_cert => "xxxx"
    ssl_key => ""
    ssl_verify => true
  }
}

```

Yes, Logstash is receiving logs despite the errorlogs in filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2023, 6:32pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826/4 "2023-12-24T18:32:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
