# Filebeat :- Failed to publish events caused by: client is not connected

**URL:** https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603
**Category:** Beats
**Tags:** filebeat
**Created:** [February 3, 2020, 10:16am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603 "2020-02-03T10:16:05Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![ragur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ragur/32/115893_2.png) [@ragur](https://discuss.elastic.co/u/ragur)
#### Post date: [February 3, 2020, 10:16am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/1 "2020-02-03T10:16:05Z")

</div>

Filebeat throws the following error message:  
Failed to publish events caused by: read tcp 127.0.0.1:53380-\>127.0.0.1:5044: i/o timeout  
2020-02-03T15:45:46.987+0530 ERROR logstash/async.go:256 Failed to publish events caused by: client is not connected  
2020-02-03T15:45:48.415+0530 ERROR pipeline/output.go:121 Failed to publish events: client is not connected  
2020-02-03T15:45:48.416+0530 INFO pipeline/output.go:95 Connecting to backoff(async(tcp://localhost:5044))  
2020-02-03T15:45:48.418+0530 INFO pipeline/output.go:105 Connection to backoff(async(tcp://localhost:5044)) established

This is happening for every 30s and filebeat publishes the same log repeatedly to the elastic search. I have set client\_inactivity\_timieout in logstash as well but no use.

This is causing the same records getting indexed in the elastic search.

Please let me know how to resolve this issue.

Logstash version : 7.5.2  
Filebeat version : 7.5.2

---

<div class="post-metadata">

### Author: ![Admax0](https://avatars.discourse-cdn.com/v4/letter/a/f1d935/32.png) [@Admax0](https://discuss.elastic.co/u/Admax0)
#### Post date: [February 4, 2020, 7:54pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/2 "2020-02-04T19:54:32Z")

</div>

Hi,  
I had the exact same problem.  
Filebeat was sending the events and displaying this error, even if the events were recorded into Logstash and were showing up on Kibana. The same event was showing up multiple times because Filebeat kept trying to send it.  
Anyways, the solution was rolling back the entire stack to 7.5.1.  
Solved everything.  
I suggest you try that.

---

<div class="post-metadata">

### Author: ![ragur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ragur/32/115893_2.png) [@ragur](https://discuss.elastic.co/u/ragur)
#### Post date: [February 6, 2020, 4:10am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/3 "2020-02-06T04:10:20Z")

</div>

Hi,  
This was happening when filebeat writing to logstash. I had to introduce kafka in between filebeat and logstash and this seems to works fine. Had to look into this when filebeat writes to logstash.

---

<div class="post-metadata">

### Author: ![TimTim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timtim/32/5295_2.png) [@TimTim](https://discuss.elastic.co/u/TimTim)
#### Post date: [February 7, 2020, 10:16am UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/4 "2020-02-07T10:16:35Z")

</div>

I have the same problem but while running:

- Logstash 7.5.1
- Filebeat 7.5.1

I run everything through Logstash here, and nothing gets to Logstash at the moment. Only when I restart Filebeat will it send the logs that were stuck since the last restart. New logs are not moving on......

I use centralized management of Filebeat. If I go back the original (non-centralized) way, it all works fine.

/Tim

---

<div class="post-metadata">

### Author: ![dillip1](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@dillip1](https://discuss.elastic.co/u/dillip1)
#### Post date: [February 10, 2020, 3:49pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/5 "2020-02-10T15:49:42Z")

</div>

i get the same error.  
Filebeat, Logstash, Elasticsearch : version 7.5.2

FIlebeat to Elastic search : Works fine  
but Filebeat to Logstash is giving trouble.

| 2020-02-10T10:32:20.109-0500 | ERROR | logstash/async.go:256 | Failed to publish events caused by: read tcp 127.0.0.1:58722-\>127.0.0.1:5044: i/o timeout |
| --- | --- | --- | --- |
| 2020-02-10T10:32:20.113-0500 | ERROR | logstash/async.go:256 | Failed to publish events caused by: client is not connected |
| 2020-02-10T10:32:21.623-0500 | ERROR | pipeline/output.go:121 | Failed to publish events: client is not connected |
| 2020-02-10T10:32:21.623-0500 | INFO | pipeline/output.go:95 | Connecting to backoff(async(tcp://localhost:5044)) |
| 2020-02-10T10:32:21.626-0500 | INFO | pipeline/output.go:105 | Connection to backoff(async(tcp://localhost:5044)) established |

Sending same info again and again to logstash.

Please suggest me, where I am missing.

---

<div class="post-metadata">

### Author: ![Admax0](https://avatars.discourse-cdn.com/v4/letter/a/f1d935/32.png) [@Admax0](https://discuss.elastic.co/u/Admax0)
#### Post date: [February 10, 2020, 4:06pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/6 "2020-02-10T16:06:08Z")

</div>

If you had something that worked in version 7.5.1, I suggest you roll back to that version.  
I go straight from filebeat to logstash and everything is done on Docker and they are on the same bridge network.

I don't know if you are using Docker. If not then that's might not be your problem but you could always give it a try.

Be sure to clean any residual file of configuration or data. You want to start again in 7.5.1 on a clean board.

Something that worked for someone else was using a tempo like Kafka between FIlebeat and Logstash:  
Filebeat --\> Tempo --\> Logstash

Hope this helps

---

<div class="post-metadata">

### Author: ![dillip1](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@dillip1](https://discuss.elastic.co/u/dillip1)
#### Post date: [February 10, 2020, 4:11pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/7 "2020-02-10T16:11:48Z")

</div>

thanks for your quick reply. I am not using Docker. I just installed the latest Stack in Windows 10 machine. For few days, I am trying to get a solution. But not succeeded yet.

---

<div class="post-metadata">

### Author: ![dillip1](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@dillip1](https://discuss.elastic.co/u/dillip1)
#### Post date: [February 10, 2020, 4:35pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/8 "2020-02-10T16:35:02Z")

</div>

Okay. Issue is solved. I just added the **client\_ inactivity\_timeout** parameter in logstash conf file.

> [@\[SOLVED\] TCP "RST"/reset causing Filebeat/Logstash connection reset](https://discuss.elastic.co/t/solved-tcp-rst-reset-causing-filebeat-logstash-connection-reset/82343/3):
>
> I'm embarrassed it took me so long to solve this. Turns out all I needed to do was specify a client\_inactivity\_timeout of more than the default of 60 seconds. In my particular situation the client (on a test server) was relatively inactive, causing Logstash to kill the connection after 60 seconds. Increasing this beyond the inactivity time resolved the issue. input { beats { client\_inactivity\_timeout =\> 1200 port =\> 5044 } } Thanks, Greg

---

<div class="post-metadata">

### Author: ![dusko.bajic](https://avatars.discourse-cdn.com/v4/letter/d/bbce88/32.png) [@dusko.bajic](https://discuss.elastic.co/u/dusko.bajic)
#### Post date: [February 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/9 "2020-02-20T15:20:59Z")

</div>

Setting `client_inactivity_timeout` in logstash config did not help in my case. I'm using filebeat 7.6.0.  
Combination of 7.5.1 filebeat and 7.6.0 logstash did not help either.  
7.5.1 both versions are working correctly.  
I'd say it's logstash to blame.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 19, 2020, 3:21pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-publish-events-caused-by-client-is-not-connected/217603/10 "2020-03-19T15:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
