# Filebeat is not sending logs to logstash getting A plugin had an unrecoverable error

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 29, 2017, 1:01pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455 "2017-05-29T13:01:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![abinstephen1989](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@abinstephen1989](https://discuss.elastic.co/u/abinstephen1989)\
**Post date:** [May 29, 2017, 1:01pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/1 "2017-05-29T13:01:12Z")

</div>

i am getting below error in logstash logs , Could you please help me to understand why i am getting this error

```auto
[2017-05-29T12:45:12,250][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.
  Plugin: <LogStash::Inputs::Beats port=>5044, ssl=>true, ssl_certificate=>"/opt/bitnami/logstash/ssl/logstash-remote.crt1",[2017-05-29T12:45:18,266][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.
  Plugin: <LogStash::Inputs::Beats port=>5044, ssl=>true, ssl_certificate=>"/opt/bitnami/logstash/ssl/logstash-remote.crt1", ssl_key=>"/opt/bitnami/logstash/ssl/logstash-remote.key", id=>"a7a87cc40298b03d988d0ddd91f714277a95bb19-6", enable_metric=>true, codec=><LogStash::Codecs::Plain id=>"plain_fe9a89ad-fdec-4af4-b50e-42182159c696", enable_metric=>true, charset=>"UTF-8">, host=>"0.0.0.0", ssl_verify_mode=>"none", include_codec_tag=>true, ssl_handshake_timeout=>10000, congestion_threshold=>5, target_field_for_codec=>"message", tls_min_version=>1, tls_max_version=>1.2, cipher_suites=>["TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384", "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384", "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256"], client_inactivity_timeout=>60>
  Error: event executor terminated

```

**filebeat.yml**

```auto
filebeat:
    prospectors:
      -
        paths:
          - /opt/wildfly/standalone/log/*.log
          - /var/log/syslog
          # - /var/log/*.log
        document_type: syslog
  output:
    logstash:
      hosts: ["xxxxxxxxxxxx:5044"]
      bulk_max_size: 1024
logging.level: warning
logging.to_files: true
logging.to_syslog: false
logging.files:
  path: /var/log/mybeat
  name: mybeat.log
  keepfiles: 7
      tls:
        certificate_authorities: ["/home/ec2-user/logstash-remote.crt1"]

```

**access-log.conf**

```auto
input {
     file {
         path => "/opt/bitnami/apache2/logs/access_log"
         start_position => beginning
     }
  beats {
      port => 5044
      ssl => true
      ssl_certificate => "/opt/bitnami/logstash/ssl/logstash-remote.crt1"
      ssl_key => "/opt/bitnami/logstash/ssl/logstash-remote.key"
    }

 }

 filter {
     grok {
         match => { "message" => "%{COMBINEDAPACHELOG}" }
     }
     date {
         match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
 }

 output {
     elasticsearch {
         hosts => ["127.0.0.1:9200"]
     }
 }

```

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 30, 2017, 9:42am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/2 "2017-05-30T09:42:38Z")

</div>

Note that I edited your post to use three ``` for formatting.

Not explaining the error you get on the LS side, but the Filebeat config might have the `output` section indented too much. It should be toplevel (no indentation). Also the TLS configuration needs to be under logstash, not at the end.

```auto
    prospectors:
      -
        paths:
          - /opt/wildfly/standalone/log/*.log
          - /var/log/syslog
          # - /var/log/*.log
        document_type: syslog
output:
  logstash:
    hosts: ["xxxxxxxxxxxx:5044"]
    bulk_max_size: 1024
    tls:
      certificate_authorities: ["/home/ec2-user/logstash-remote.crt1"]

logging.level: warning
logging.to_files: true
logging.to_syslog: false
logging.files:
  path: /var/log/mybeat
  name: mybeat.log
  keepfiles: 7

```

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 30, 2017, 9:42am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/3 "2017-05-30T09:42:55Z")

</div>

For the LS error, it might be worth asking in the Logstash forums.

---

<div class="post-metadata">

**Author:** ![abinstephen1989](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@abinstephen1989](https://discuss.elastic.co/u/abinstephen1989)\
**Post date:** [May 30, 2017, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/4 "2017-05-30T12:57:53Z")

</div>

For me logs also not generating in below location  
logging.files:  
path: /var/log/mybeat  
name: mybeat.log

Any problem in the configuration??

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 31, 2017, 7:32am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/5 "2017-05-31T07:32:19Z")

</div>

That looks good at first sight, but you have warning level, so maybe there are no messages. Try making that `debug` for a short while to check.

---

<div class="post-metadata">

**Author:** ![abinstephen1989](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@abinstephen1989](https://discuss.elastic.co/u/abinstephen1989)\
**Post date:** [May 31, 2017, 9:21am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/6 "2017-05-31T09:21:59Z")

</div>

That worked 🙂

But now i am getting belwo error in my log ☹

2017-05-31T09:11:40Z DBG Check file for harvesting: /home/ec2-user/access\_log  
2017-05-31T09:11:40Z DBG Update existing file for harvesting: /home/ec2-user/access\_log, offset: 42734  
2017-05-31T09:11:40Z DBG File didn't change: /home/ec2-user/access\_log  
2017-05-31T09:11:40Z DBG Prospector states cleaned up. Before: 1, After: 1  
2017-05-31T09:11:40Z DBG Flushing spooler because of timeout. Events flushed: 0  
2017-05-31T09:11:45Z DBG Flushing spooler because of timeout. Events flushed: 0  
2017-05-31T09:11:49Z DBG connect  
2017-05-31T09:11:49Z DBG Try to publish 377 events to logstash with window size 1  
2017-05-31T09:11:49Z DBG handle error: read tcp 172.31.7.247:60988-\>52.60.189.106:5044: read: connection reset by peer  
2017-05-31T09:11:49Z DBG 0 events out of 377 events sent to logstash. Continue sending  
2017-05-31T09:11:49Z DBG close connection  
2017-05-31T09:11:49Z DBG closing  
_ **2017-05-31T09:11:49Z ERR Failed to publish events caused by: read tcp 172.31.7.247:60988-\>52.60.189.106:5044: read: connection reset by peer** _  
2017-05-31T09:11:49Z INFO Error publishing events (retrying): read tcp 172.31.7.247:60988-\>52.60.189.106:5044: read: connection reset by peer

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [June 1, 2017, 12:29pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/7 "2017-06-01T12:29:54Z")

</div>

That looks like an SSL error. Did you move the tls section under `logstash`? Try also to debug with openssl: `openssl s_client -connect logstash:5043 -showcerts`

---

<div class="post-metadata">

**Author:** ![abinstephen1989](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@abinstephen1989](https://discuss.elastic.co/u/abinstephen1989)\
**Post date:** [June 5, 2017, 11:57am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/8 "2017-06-05T11:57:36Z")

</div>

Thanks you  
changed tls to ssl that resolved the issue 🙂  
tls:  
certificate\_authorities: ["/home/ec2-user/logstash-remote.crt1"]

ssl:  
certificate\_authorities: ["/home/ec2-user/logstash-remote.crt1"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2017, 11:57am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-getting-a-plugin-had-an-unrecoverable-error/87455/9 "2017-07-03T11:57:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
