# Filebeat not communicating with Logstash, is TLS required?

**URL:** <https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066>\
**Category:** Beats\
**Created:** [February 22, 2017, 3:02pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066 "2017-02-22T15:02:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lexa](https://avatars.discourse-cdn.com/v4/letter/l/cc9497/32.png) [@Lexa](https://discuss.elastic.co/u/Lexa)\
**Post date:** [February 22, 2017, 3:02pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/1 "2017-02-22T15:02:04Z")

</div>

I have installed LS 5.2.1 and filebeat 5.2.1. (CentOs7) When attempting to ship via filbeat, I am getting the following error in the filebeat log.

2017-02-21T23:25:15-05:00 ERR Connecting error publishing events (retrying): Get [http://192.168.56.102:5044](http://192.168.56.102:5044): read tcp 192.168.56.101:33570-\>192.168.56.102:5044: read: connection reset by peer  
2017-02-21T23:25:36-05:00 INFO Non-zero metrics in the last 30s: libbeat.es.publish.read\_errors=1 libbeat.es.publish.write\_bytes=126

I have verified that I can telnet from the filebeat host to the logstash host on port 5044..

The following are the changes that I made to the default /etc/filebeat/filebeat.yml file

- input\_type: log  
document\_type: syslog

#output.logstash:

# The Logstash hosts

hosts: ["192.168.56.102:5044"]

and here is the logstash plugin file that I have in /etc/logstash/conf.d on the logstash host

input {  
beats {  
port =\> 5044  
client\_inactivity\_timeout =\> "900"  
}  
}  
output {  
stdout { }  
elasticsearch { }  
}

I have searched the previous topics and have been unable to find any resolution. Any advice would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 22, 2017, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/2 "2017-02-22T15:44:07Z")

</div>

did you try to:

```
Input {
beats {
port => "5044"
client_inactivity_timeout => "900"
}
```

---

<div class="post-metadata">

**Author:** ![Lexa](https://avatars.discourse-cdn.com/v4/letter/l/cc9497/32.png) [@Lexa](https://discuss.elastic.co/u/Lexa)\
**Post date:** [February 22, 2017, 4:00pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/3 "2017-02-22T16:00:43Z")

</div>

> [@lueneburger](#):
>
> Input {  
> beats {  
> port =\> "5044"  
> client\_inactivity\_timeout =\> "900"  
> }

The only difference I see is that you have the port number in quotes.... I am trying this now.

Thank you!

---

<div class="post-metadata">

**Author:** ![Lexa](https://avatars.discourse-cdn.com/v4/letter/l/cc9497/32.png) [@Lexa](https://discuss.elastic.co/u/Lexa)\
**Post date:** [February 22, 2017, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/4 "2017-02-22T16:16:32Z")

</div>

I tried with quotes. This did not correct the issue.

input {  
beats {  
port =\> "5044"  
client\_inactivity\_timeout =\> "900"  
}  
}  
output {  
stdout { }  
elasticsearch { }  
}

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 23, 2017, 11:44am UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/5 "2017-02-23T11:44:58Z")

</div>

i only know the error from trying to get filebeat and logstash working on an SSL connection, with the wrong certificate.

and logstash is starting without any problem?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 23, 2017, 4:03pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/6 "2017-02-23T16:03:09Z")

</div>

the read timeout indicates filebeat has pushed the events, but the remote host closing the connection while filebeat is waiting for the ACK.

Which logstash-input-beats version is installed? Consider upgrading the plugin to the most recent version. Some users did report version 3.1.10 of the plugin fixing this issue for them.

Note:  
Well, TSL/SSL also use read/write operations and the java-code seems to just close connection on certificate failure, which would give you a similar error message. But as you are not using TLS, the error happens waiting for ACK from logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2017, 3:02pm UTC](https://discuss.elastic.co/t/filebeat-not-communicating-with-logstash-is-tls-required/76066/7 "2017-03-15T15:02:12Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
