# Filebeat ERR Connecting error publishing events (retrying) read tcp i/o timeout

**URL:** <https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 14, 2017, 2:29am UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368 "2017-04-14T02:29:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Chen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_chen/32/17288_2.png) [@Daniel\_Chen](https://discuss.elastic.co/u/Daniel_Chen)\
**Post date:** [April 14, 2017, 2:29am UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/1 "2017-04-14T02:29:30Z")

</div>

I have Filebeat 5.3.0 installed on one of my server

**filebeat.yml** :

```auto
filebeat:
  prospectors:
    -
      paths:
        - /home/jarvis/data/nginx-logs/*.log

      input_type: log

      document_type: nginx-access

  registry_file: /var/lib/filebeat/registry

output:
  logstash:
    hosts: ["10.0.6.35:5044"]
    bulk_max_size: 2048

    ssl:
      certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

shipper:

logging:
  logging.level: warning
  logging.to_files: true
  logging.to_syslog: false
  logging.files:
    path: /var/log/mybeat
    name: mybeat.log
    keepfiles: 7

```

and logstash 5.3.0 installed on another machine

**02-beats-input.conf** :

```auto
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

```

filebeat harvest some very large log files send to logstash. logstash-input-beats plugin was installed. Error message:

```auto
2017-04-14T10:13:12+08:00 INFO Non-zero metrics in the last 30s: filebeat.harvester.open_files=2 filebeat.harvester.running=2 filebeat.harvester.started=2 libbeat.logstash.publish.write_bytes=132 libbeat.publisher.published_events=2044
2017-04-14T10:13:12+08:00 ERR Connecting error publishing events (retrying): read tcp 10.0.3.200:40424->10.0.6.35:5044: i/o timeout
2017-04-14T10:13:42+08:00 INFO Non-zero metrics in the last 30s: libbeat.logstash.publish.read_errors=1 libbeat.logstash.publish.write_bytes=132
2017-04-14T10:13:43+08:00 ERR Connecting error publishing events (retrying): read tcp 10.0.3.200:40550->10.0.6.35:5044: i/o timeout

```

I can ping to my logstash server, but `telnet server 5044` failed. I've looked into search results in the forum but no idea.

Can I have any advice on this problem?

---

<div class="post-metadata">

**Author:** ![giuseppe](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@giuseppe](https://discuss.elastic.co/u/giuseppe)\
**Post date:** [April 14, 2017, 4:47pm UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/2 "2017-04-14T16:47:58Z")

</div>

Do the Logstash logs show anything useful? It almost looks as if Logstash went down.

---

<div class="post-metadata">

**Author:** ![Daniel\_Chen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_chen/32/17288_2.png) [@Daniel\_Chen](https://discuss.elastic.co/u/Daniel_Chen)\
**Post date:** [April 15, 2017, 6:44am UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/3 "2017-04-15T06:44:11Z")

</div>

No, logstash server was up, and nothing was write into the log files.  
I was thinking if the filebeat tcp connection make it's own server timeout and not able to connect to the logstash server.

---

<div class="post-metadata">

**Author:** ![giuseppe](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@giuseppe](https://discuss.elastic.co/u/giuseppe)\
**Post date:** [April 17, 2017, 5:46pm UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/4 "2017-04-17T17:46:15Z")

</div>

Yes you can customize the timeout if you think that's the problem, the default is 30s:

[https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#\_timeout\_2](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#_timeout_2)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 20, 2017, 9:33am UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/5 "2017-04-20T09:33:03Z")

</div>

if telnet is not working, the remote is not reachable. Maybe some firewall or network not reachable?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 9:37am UTC](https://discuss.elastic.co/t/filebeat-err-connecting-error-publishing-events-retrying-read-tcp-i-o-timeout/82368/6 "2017-05-18T09:37:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
