# Filebeat error when trying to send logs from filebeat to logstash

**URL:** <https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 23, 2018, 12:37pm UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992 "2018-05-23T12:37:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![remo](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@remo](https://discuss.elastic.co/u/remo)\
**Post date:** [May 23, 2018, 12:37pm UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992/1 "2018-05-23T12:37:31Z")

</div>

I am getting this error when I am trying to send logs from filebeat to logstash.

**Failed to connect: dial tcp 127.0.0.1:5044: connectex: No connection could be made because the target machine actively refused it.**

Please help me out with this.

Thank you

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [May 23, 2018, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992/2 "2018-05-23T13:12:05Z")

</div>

Could you please share you debug logs and configuration? Please format these using `</>`.

---

<div class="post-metadata">

**Author:** ![remo](https://avatars.discourse-cdn.com/v4/letter/r/bb73d2/32.png) [@remo](https://discuss.elastic.co/u/remo)\
**Post date:** [May 24, 2018, 4:29am UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992/3 "2018-05-24T04:29:03Z")

</div>

**This is my filebeat.yml configuration:**

\<filebeat.prospectors:

- type: log  
enabled: true  
paths:
  - C:\Users\abccsh\Documents\My Received Files\sample.log  
filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: true  
output.logstash:  
hosts: ["localhost:5044"]/\>

**my logstash conf file:**  
input {  
beats {  
port =\> 5044  
}  
}  
output{  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "reshma"  
user=\> elastic  
password=\>elastic  
}  
stdout{codec =\> rubydebug}  
}

**Debug logs:**

cfgfile/reload.go:77 BETA: Dynamic config reload is enabled.  
2018-05-24T09:57:55.518+0530 INFO crawler/crawler.go:82 Loading and starting Prospectors completed. Enabled prospectors: 1  
2018-05-24T09:57:55.518+0530 INFO cfgfile/reload.go:127 Config reloader started  
2018-05-24T09:57:55.520+0530 INFO log/harvester.go:216 Harvester started for file: C:\Users\rmorampu\Documents\My Received Files\sample.log  
2018-05-24T09:57:58.591+0530 ERROR pipeline/output.go:74 Failed to connect: dial tcp 127.0.0.1:5044: connectex: No connection could be made because the target machine actively refused it.  
2018-05-24T09:58:02.622+0530 ERROR pipeline/output.go:74 Failed to connect: dial tcp 127.0.0.1:5044: connectex: No connection could be made because the target machine actively refused it.  
2018-05-24T09:58:08.660+0530 ERROR pipeline/output.go:74 Failed to connect: dial tcp [::1]:5044: connectex: No connection could be made because the target machine actively refused it.

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [May 24, 2018, 5:27am UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992/4 "2018-05-24T05:27:06Z")

</div>

@remo You can verify the log shipment from Filebeat to Logstash without using Elasticsearch. Sometime if Elasticsearch is not working properly with Logstash then this kind of problem may arise.

You can verify it by following below steps:

1. Configure stdout in output section of logstash  
**output {**  
**stdout{}**  
**}**

2. Restart Logstash

3. Run Filebeat

[Note : If it is working fine then it is the problem regarding Elasticsearch and Logstash]

You can Follow the start sequence accordingly  
Elasticsearch --\> Logstash --\> Filebeat

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2018, 5:27am UTC](https://discuss.elastic.co/t/filebeat-error-when-trying-to-send-logs-from-filebeat-to-logstash/132992/5 "2018-06-21T05:27:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
