# Filebeat -\> Logstash :connection reset by peer

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-connection-reset-by-peer/94117>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 21, 2017, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-logstash-connection-reset-by-peer/94117 "2017-07-21T13:00:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yeruvass](https://avatars.discourse-cdn.com/v4/letter/y/d6d6ee/32.png) [@yeruvass](https://discuss.elastic.co/u/yeruvass)\
**Post date:** [July 21, 2017, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-logstash-connection-reset-by-peer/94117/1 "2017-07-21T13:00:37Z")

</div>

I'm shipping logs from filebeat to logstash with tls and getting below error and tried lot of ways to resolve but helpless.

2017-07-21T18:24:27+05:30 ERR Failed to publish events caused by: read tcp 10.197.53.179:41349-\>10.197.53.179:5044: read: connection reset by peer  
2017-07-21T18:24:27+05:30 INFO Error publishing events (retrying): read tcp 10.197.53.179:41349-\>10.197.53.179:5044: read: connection reset by peer

Filebeat and logstash versions :- 5.2.1  
**filebeat configurations** :-  
logstash:  
hosts: ["10.197.53.179:5044"]  
tls:  
certificate\_authorities: ["/etc/filebeat/logstash-fwd.crt"]

**Logstash configuration :-**  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/logstash/conf.d/logstash-fwd.crt"  
ssl\_key =\> "/etc/logstash/conf.d/logstash-fwd.key"  
}  
}

**certificates created by using below command :**

openssl req -x509 -batch -nodes -newkey rsa:2048 -keyout logstash-fwd.key -out logstash-fwd.crt -subj /CN=10.197.53.179

Please help me on this issue.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 21, 2017, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-logstash-connection-reset-by-peer/94117/2 "2017-07-21T14:20:31Z")

</div>

Problem is most likely caused by logstash prematurely closing the connection. I think the logstash-input-beats plugin version 3.11 did mostly solve the issue. Try upgrading logstash to 5.4 and increase `client_connectivity_timeout` in logstash beats input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2017, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-logstash-connection-reset-by-peer/94117/3 "2017-08-18T14:20:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
