# Filebeat is not sending logs to Logstash, logstash is localhost

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586>\
**Category:** Logstash\
**Created:** [October 1, 2020, 3:28am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586 "2020-10-01T03:28:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sravan\_Kumar\_Guduru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sravan_kumar_guduru/32/48265_2.png) [@Sravan\_Kumar\_Guduru](https://discuss.elastic.co/u/Sravan_Kumar_Guduru)\
**Post date:** [October 1, 2020, 3:28am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/1 "2020-10-01T03:28:45Z")

</div>

Hi All,

I am having trouble with my filebeat/logstash. connectivity seems to be inconsistenst. When i try it in debug mode it works fine but when i use it with systemctl start it fails . Below are my filebeat and logstash config details and error output details

Filebeat:

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: log

# ============================== Filebeat modules ==============================

filebeat.config.modules:  
enabled: true  
path: ${path.config}/modules.d/\*.yml

# Set to true to enable config reloading

reload.enabled: false

# Period on which files under path should be checked for changes

#reload.period: 10s

# ======================= Elasticsearch template setting =======================

setup.template.settings:  
index.number\_of\_shards: 1  
#index.codec: best\_compression  
#\_source.enabled: false

# ================================== General ===================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

tags: ["10.112.22.74"]

# Optional fields that you can specify to add additional information to the

# output.

fields:  
env: Test\_Server

# ------------------------------ Logstash Output -------------------------------

output.logstash:

# The Logstash hosts

hosts: ["127.0.0.1:5044"]  
bulk\_max\_size: 1024

# Optional SSL. By default is off.

# ================================= Processors =================================

processors:

- add\_host\_metadata:  
when.not.contains.tags: forwarded
- add\_cloud\_metadata: ~
- add\_docker\_metadata: ~
- add\_kubernetes\_metadata: ~

# ================================== Logging ===================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

#logging.level: debug

# 

logging.level: debug  
logging.to\_files: true  
logging.files:  
path: /var/log/filebeat  
name: filebeat  
keepfiles: 7  
rotateeverybytes: 10485760  
permissions: 0644

and my Logstash beats.conf file

input {  
beats {

# client\_inactivity\_timeout =\> 1200

```
port => 5044
ssl => false

```

# ssl\_certificate =\> "/etc/pki/tls/certs/logstash.crt"

# ssl\_key =\> "/etc/pki/tls/private/logstash.key"

}  
}  
output {  
file {

# path =\> "/mnt/xxxxxxxxxxxxx/Logs/Dev\_Internal/VMSailPointTaskDEV0"

```
 path => "/mnt/xxxxxxxxxxx/Logs/Dev_Internal/Ganeshtest1TaskDev1/%{[host][name]}-catalina_logs-%{+YYYY-MM-dd}.log"
 codec => line { format => "%{message}" }

```

}

and logs from filebeat

2020-09-30T23:15:50.798-0400 DEBUG [transport] transport/client.go:205 handle error: write tcp 127.0.0.1:54730-\>127.0.0.1:5044: write: connection reset by peer  
2020-09-30T23:15:50.798-0400 DEBUG [transport] transport/client.go:118 closing  
2020-09-30T23:15:50.798-0400 DEBUG [logstash] logstash/async.go:172 73 events out of 73 events sent to logstash host 127.0.0.1:5044. Continue sending  
2020-09-30T23:15:50.798-0400 DEBUG [logstash] logstash/async.go:128 close connection  
2020-09-30T23:15:50.798-0400 ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: write tcp 127.0.0.1:54730-\>127.0.0.1:5044: write: connection reset by peer  
2020-09-30T23:15:50.798-0400 DEBUG [logstash] logstash/async.go:128 close connection  
2020-09-30T23:15:50.798-0400 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2020-09-30T23:15:50.798-0400 INFO [publisher] pipeline/retry.go:223 done  
2020-09-30T23:15:50.798-0400 DEBUG [harvester] log/log.go:107 End of file reached: /home/clouduser/apache-tomcat-9.0.36/logs/catalina.2020-09-30.log; Backoff now.  
2020-09-30T23:15:52.532-0400 ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: write tcp 127.0.0.1:54730-\>127.0.0.1:5044: write: connection reset by peer  
2020-09-30T23:15:52.532-0400 INFO [publisher\_pipeline\_output] pipeline/output.go:143 Connecting to backoff(async(tcp://127.0.0.1:5044))  
2020-09-30T23:15:52.532-0400 DEBUG [logstash] logstash/async.go:120 connect  
2020-09-30T23:15:52.533-0400 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2020-09-30T23:15:52.533-0400 INFO [publisher] pipeline/retry.go:223 done  
2020-09-30T23:15:52.798-0400 DEBUG [harvester] log/log.go:107 End of file reached: /home/clouduser/apache-tomcat-9.0.36/logs/catalina.2020-09-30.log; Backoff now.  
2020-09-30T23:15:54.767-0400 DEBUG [input] input/input.go:139 Run input  
2020-09-30T23:15:54.767-0400 DEBUG [input] log/input.go:205 Start next scan  
2020-09-30T23:15:54.767-0400 DEBUG [input] log/input.go:439 Check file for harvesting: /home/clouduser/apache-tomcat-9.0.36/logs/catalina.2020-09-30.log  
2020-09-30T23:15:54.767-0400 DEBUG [input] log/input.go:530 Update existing file for harvesting: /home/clouduser/apache-tomcat-9.0.36/logs/catalina.2020-09-30.log, offset: 169191  
2020-09-30T23:15:54.767-0400 DEBUG [input] log/input.go:582 Harvester for file is still running: /home/clouduser/apache-tomcat-9.0.36/logs/catalina.2020-09-30.log  
2020-09-30T23:15:54.767-0400 DEBUG [input] log/input.go:226 input states cleaned up. Before: 1, After: 1, Pending: 0

Can some one help me , why I am facing network/connectivity issues from logstash to filebeat

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2020, 3:54am UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/2 "2020-10-01T03:54:34Z")

</div>

Welcome to our community! 😃

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 2:57pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/3 "2020-10-01T14:57:59Z")

</div>

If filebeat is seeing 'connection reset by peer' then the peer (logstash) probably logs an error. What does logstash log (formatted, please, as Mark said).

---

<div class="post-metadata">

**Author:** ![Sravan\_Kumar\_Guduru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sravan_kumar_guduru/32/48265_2.png) [@Sravan\_Kumar\_Guduru](https://discuss.elastic.co/u/Sravan_Kumar_Guduru)\
**Post date:** [October 1, 2020, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/4 "2020-10-01T15:45:24Z")

</div>

Hi ,

I have tried a different way

input {  
file {  
path =\> "/home/clouduser/apache-tomcat-9.0.36/logs/catalina.\*.log"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"

# ssl\_certificate =\> "/etc/pki/tls/certs/logstash.crt"

# ssl\_key =\> "/etc/pki/tls/private/logstash.key"

}  
}  
output {  
file {

# path =\> "/mnt/xxxxxx/Logs/Dev\_Internal/VMSailPointTaskDEV0"

```
 path => "/mnt/xxxxxx/Logs/Dev_Internal/GaneshTestTaskDev1/%{[host][name]}-catalina_logs-%{+YYYY-MM-dd}.log"
 codec => line { format => "%{message}" }

```

}

}

all the logs are getting captured when i run this manually

/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/beats.conf

but when i start the logstash with systemctl start logstash . logs are not getting captured not sure why ?

any thoughts on this ?

---

<div class="post-metadata">

**Author:** ![Sravan\_Kumar\_Guduru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sravan_kumar_guduru/32/48265_2.png) [@Sravan\_Kumar\_Guduru](https://discuss.elastic.co/u/Sravan_Kumar_Guduru)\
**Post date:** [October 1, 2020, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/5 "2020-10-01T19:06:46Z")

</div>

Interestingly my logstash is running when I tried ps -ef | grep logstash and when my filebeat tries to send the logs it is getting connection refused error.

When I even do telent , i get below error message  
[root@GaneshTestTaskDev2TaskDev1 logstash]# telnet localhost 5044  
Trying 127.0.0.1...  
telnet: connect to address 127.0.0.1: Connection refused

I am not able to see any logstash logs its empty, any help here ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2020, 7:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-logs-to-logstash-logstash-is-localhost/250586/6 "2020-10-29T19:06:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
