# Filebeat Error

**URL:** <https://discuss.elastic.co/t/filebeat-error/64072>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 26, 2016, 10:42pm UTC](https://discuss.elastic.co/t/filebeat-error/64072 "2016-10-26T22:42:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![admin1](https://avatars.discourse-cdn.com/v4/letter/a/bbce88/32.png) [@admin1](https://discuss.elastic.co/u/admin1)\
**Post date:** [October 26, 2016, 10:42pm UTC](https://discuss.elastic.co/t/filebeat-error/64072/1 "2016-10-26T22:42:11Z")

</div>

I am getting a similar kind of error. I am trying to monitor logs from different hosts using filebeats

I get this error on some hosts

```auto
2016/10/26 17:28:48.159067 single.go:140: ERR Connecting error publishing events (retrying): read tcp 10.0.1.151:41256->54.214.224.161:5044: i/o timeout
2016/10/26 17:29:17.922310 logp.go:230: INFO Non-zero metrics in the last 30s: libbeat.logstash.publish.write_bytes=132 libbeat.logstash.publish.read_errors=1

```

This is happening on some hosts, while I have other hosts which have filebeats running and they are pushing logs to logstash  
I have already checked connectivity and that is fine.

my filebeat.yml is as follows

```auto
filebeat.prospectors:

input_type: log
paths:
- /var/log/vdebug
- /var/log/auth.log
- /var/log/kern.log
- /var/log/vsyslog
- /var/log/nms/vmanage-server.log
document_type: log

output.logstash:
# The Logstash hosts
hosts: ["54.214.224.161:5044"]
bulk_max_size: 1024
ssl:

verification_mode: none

```

conf file is as follows

```auto
ester@elk:/etc/logstash$ more syslog-elasticsearch.conf
input {
beats {
port => 5044
ssl => true
ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
}
}
filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:[%{POSINT:syslog_pid}])?: %{GREEDYDATA:syslog_message}" }
add_field => ["received_at", "%{@timestamp}"]
add_field => ["received_from", "%{host}"]
}
syslog_pri { }
date {
match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
sniffing => true
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}

```

Any help would be appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [October 28, 2016, 1:23pm UTC](https://discuss.elastic.co/t/filebeat-error/64072/2 "2016-10-28T13:23:30Z")

</div>

It seems you don't have any certificate defined on the client side. Also indentation of your config file looks off. I tried to format it by putting ticks around it, but that didn't help. Make sure to share the ocnfig file with the exact indentation and putting ticks around.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2016, 10:42pm UTC](https://discuss.elastic.co/t/filebeat-error/64072/3 "2016-11-16T22:42:13Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
