# Filebeat can not publishing events

**URL:** <https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 16, 2015, 11:52am UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349 "2015-12-16T11:52:01Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adria\_Garcia\_Alzorri](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Adria\_Garcia\_Alzorri](https://discuss.elastic.co/u/Adria_Garcia_Alzorri)\
**Post date:** [December 16, 2015, 11:52am UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/1 "2015-12-16T11:52:01Z")

</div>

Howdy,

I'm trying the ELK stack under CentOS 6 machines, following [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-centos-7](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-centos-7).

Every service is running in a separated machine, so `ela01` has Elasticsearch, `log` has Logstash and `filebeat`… you know, Filebeat service 😄

The problem I'm facing is that Filbeat gives below error to me:  
`2015-12-16T12:21:58+01:00 INFO backoff retry: 4s 2015-12-16T12:22:02+01:00 INFO Error publishing events (retrying): EOF 2015-12-16T12:22:02+01:00 INFO Error publishing events (retrying): read tcp 192.168.28.162:51149->192.168.28.163:5044: read: connection reset by peer 2015-12-16T12:22:02+01:00 INFO send fail`

My config looks like below:

`Logstash .conf file:`

```
input {
  beats {
    host => "log"
    port => 5044
    type => "logs"
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }    
}

…

```

`filebeat.yml:`

```
filebeat:
  prospectors:
    -
      paths:
        - /input/*.log
      input_type: log
  registry_file: /var/lib/filebeat/registry

output:
  elasticsearch:
    hosts: ["ela01:9200"]
    tls:
      certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

  logstash:
    hosts: ["log:5044"]

shipper:
  geoip:
    paths:
      - "/usr/share/GeoIP/GeoLiteCity.dat"

logging:
  to_files: true
  files:
    path: /var/log/mybeat
    name: mybeat
  level: info

```

From Logstash server I can connect to Filebeat:

```
# nc -vz log 5044
Connection to 192.168.28.163 5044 port [tcp/lxi-evntsvc] succeeded!

```

Any clue about what more I could check?

Commenting out lines regarding to certificates stuff gives the same error message.

Thanks so much!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 16, 2015, 12:22pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/2 "2015-12-16T12:22:02Z")

</div>

You've configured the listener on the Logstash side to use TLS but you're not configuring Filebeat to use TLS when connecting to Logstash.

---

<div class="post-metadata">

**Author:** ![Adria\_Garcia\_Alzorri](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Adria\_Garcia\_Alzorri](https://discuss.elastic.co/u/Adria_Garcia_Alzorri)\
**Post date:** [December 16, 2015, 1:29pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/3 "2015-12-16T13:29:13Z")

</div>

Hi Magnus,

your're right.

Thanks, now Elasticsearch is indexing yet 😄

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 16, 2015, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/4 "2015-12-16T14:46:29Z")

</div>

In case this is not intentional, I noticed that the configuration has both an elasticsearch output and a logstash output configured.

If you are intending for events to go from Filebeat -\> Logstash -\> Elasticsearch, then you can remove the elasticsearch section of the configuration and only send events to Logstash. An elasticsearch output will need to be added to you logstash config. There is an example in the [Getting Started](https://www.elastic.co/guide/en/beats/libbeat/current/logstash-installation.html#logstash-setup).

---

<div class="post-metadata">

**Author:** ![Adria\_Garcia\_Alzorri](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Adria\_Garcia\_Alzorri](https://discuss.elastic.co/u/Adria_Garcia_Alzorri)\
**Post date:** [December 16, 2015, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/5 "2015-12-16T15:33:00Z")

</div>

It does make sense to me. In fact my idea was tweaking the config and you helped me.  
Thanks for pointing it to me.

---

<div class="post-metadata">

**Author:** ![iqbal\_nazir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iqbal_nazir/32/10216_2.png) [@iqbal\_nazir](https://discuss.elastic.co/u/iqbal_nazir)\
**Post date:** [June 14, 2016, 3:08pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/6 "2016-06-14T15:08:13Z")

</div>

Hi,

I am having kind of similar issue and I was going through this thread and I noticed your ''Getting Started" link (which might help me too) doesn't work.

Regards,  
Iqbal

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 15, 2016, 6:12am UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/7 "2016-06-15T06:12:32Z")

</div>

Here is the most recent one: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [October 25, 2016, 3:32pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/8 "2016-10-25T15:32:42Z")

</div>

Can you please share your filebeat.yml i have similar issue connecting i.o time out configurations to use TLS

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [October 25, 2016, 3:36pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/9 "2016-10-25T15:36:26Z")

</div>

input {  
beats {  
port =\> 5044  
type =\> "syslog"  
#ssl =\> true  
#ssl\_certificate =\> "/etc/pki/tls/certs/filebeat.crt"  
#ssl\_key =\> "/etc/pki/tls/private/filebeat.key"  
}  
}

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [October 25, 2016, 3:56pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/10 "2016-10-25T15:56:20Z")

</div>

2016-10-25T15:50:12Z INFO Total non-zero values: libbeat.logstash.published\_and\_acked\_events=3816 filebeat.harvester.closed=7 filebeat.harvester.started=7 libbeat.publisher.published\_events=4089 registrar.states.update=2048 registrar.writes=2 libbeat.logstash.call\_count.PublishEvents=29 libbeat.logstash.published\_but\_not\_acked\_events=14443 libbeat.logstash.publish.read\_bytes=108 publish.events=2048 registar.states.current=7 libbeat.logstash.publish.read\_errors=27 libbeat.logstash.publish.write\_bytes=194818  
2016-10-25T15:50:12Z INFO Uptime: 32m20.917862941s  
2016-10-25T15:50:12Z INFO filebeat stopped.

---

<div class="post-metadata">

**Author:** ![Adria\_Garcia\_Alzorri](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Adria\_Garcia\_Alzorri](https://discuss.elastic.co/u/Adria_Garcia_Alzorri)\
**Post date:** [October 25, 2016, 5:58pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/11 "2016-10-25T17:58:22Z")

</div>

```
filebeat:
  prospectors:
    -
      paths:
        - /path/to/whatever.log
      input_type: log
      document_type: whatever

[…]
   
  registry_file: /var/lib/filebeat/registry

output:
  logstash:
    hosts: ["logstash:5044"]

shipper:
  tags: []

logging:
  to_files: true
  files:
    path: /var/log/filebeat
    name: filebeat
    level: error
```

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [October 25, 2016, 6:18pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/12 "2016-10-25T18:18:25Z")

</div>

Thanks for getting back to me I'm running again in this error not sure [..]

service filebeat start  
Starting filebeat: Exiting: error loading config file: yaml: line 21: could not find expected ':'

filebeat:  
prospectors:  
-  
paths:  
- /var/.log  
- /var/log/.log  
- /var/log/messages  
- /var/log  
- /var/.log  
- /opt/.log  
- /opt.log  
- /opt.log  
- /opt/.log

```
  input_type: log

  document_type: syslog

```

[…]

registry\_file: /var/lib/filebeat/registry

output:  
logstash:  
hosts: ["10.251.33.130:5044"]

shipper:  
tags: []

logging:  
to\_files: true  
files:  
path: /var/log/filebeat  
name: filebeat  
level: error

---

<div class="post-metadata">

**Author:** ![Adria\_Garcia\_Alzorri](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@Adria\_Garcia\_Alzorri](https://discuss.elastic.co/u/Adria_Garcia_Alzorri)\
**Post date:** [October 25, 2016, 6:38pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/13 "2016-10-25T18:38:17Z")

</div>

It looks like a syntax error. Please check it.

PS: I'd suggest to create a new thread instead of using an almost-one-year-ago one.

---

<div class="post-metadata">

**Author:** ![admin1](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@admin1](https://discuss.elastic.co/u/admin1)\
**Post date:** [October 26, 2016, 6:45pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/14 "2016-10-26T18:45:44Z")

</div>

I am getting a similar kind of error. I am trying to monitor logs from different hosts using filebeats

I get this error on some hosts  
2016/10/26 17:28:48.159067 single.go:140: ERR Connecting error publishing events (retrying): read tcp 10.0.1.151:41256-\>54.214.224.161:5044: i/o timeout  
2016/10/26 17:29:17.922310 logp.go:230: INFO Non-zero metrics in the last 30s: libbeat.logstash.publish.write\_bytes=132 libbeat.logstash.publish.read\_errors=1

This is happening on some hosts, while I have other hosts which have filebeats running and they are pushing logs to logstash  
I have already checked connectivity and that is fine.

my filebeat.yml is as follows  
filebeat.prospectors:

- input\_type: log

output.logstash:

# The Logstash hosts

hosts: ["54.214.224.161:5044"]  
bulk\_max\_size: 1024  
ssl:

```
verification_mode: none

```

conf file is as follows

ester@elk:/etc/logstash$ more syslog-elasticsearch.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Any help would be appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 26, 2016, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/15 "2016-10-26T20:48:12Z")

</div>

@admin1, please start a new thread for your unrelated problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:50pm UTC](https://discuss.elastic.co/t/filebeat-can-not-publishing-events/37349/16 "2017-07-05T21:50:24Z")

</div>


