# Filebeat refuse connect to Logstash port- "Connection timed out error"

**URL:** <https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803>\
**Category:** Beats\
**Created:** [April 20, 2020, 8:07am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803 "2020-04-20T08:07:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pash123](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@pash123](https://discuss.elastic.co/u/pash123)\
**Post date:** [April 20, 2020, 8:07am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/1 "2020-04-20T08:07:39Z")

</div>

```auto
Hi all, 
I have installed FB on Linux server and LG on my local server. (ES and Kibana installed on local server as well)

**LG configuration:**   
input{
	beats{
		port => 5044
	}
}	
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
}

**FB configuration:**
filebeat.inputs:
- type: log
  enabled: true
  paths:
  - /opt/tomcat/logs/catalina.out
output.logstash:
  hosts: ["192.168.220.33:5044"] 

**More details:** 
I'm connecting to the FB server from my pc which working with VPN the VPN's ip- 192.168.220.33 (as written in FB config). 
The LG working fine, i check configuration for LG and it's OK, and seems that it's listening to port 5044. However than trying to check connection on FB: "telnet 192.168.220.33 5044"
I get:
"try to connect" and after few seconds "Connection timed out error".

 I check some tutorials on this site so i try as well, this what i got:
* I turn off Firewall for public and social connection, not working. 
* try to run FB- "sudo chown root filebeat.yml => sudo ./filebeat -e"- ERROR   
          pipeline/output.go:100 Failed to connect to backoff(async(tcp://192.168.220.33:5044)): dial 
          tcp 192.168.220.33:5044: i/o timeout
* ping 192.168.220.33 -"PING 192.168.220.33 (192.168.220.33) 56(84) bytes of data".

```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 20, 2020, 6:59pm UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/2 "2020-04-20T18:59:31Z")

</div>

Hi @pash123, welcome to the Elastic community forums!

Yes, I suspect this has to do with firewall rules between your Filebeat and Logstash hosts. I see that ping worked but that just means that ICMP echo requests are being allowed. We need to check if TCP requests to port 5044 are allowed from your Filebeat host to your Logstash host.

What happens if you run the following on your Filebeat host?

```auto
telnet 192.168.220.33 5044

```

---

<div class="post-metadata">

**Author:** ![pash123](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@pash123](https://discuss.elastic.co/u/pash123)\
**Post date:** [April 20, 2020, 11:00pm UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/3 "2020-04-20T23:00:15Z")

</div>

Hi @[shaunak](https://discuss.elastic.co/u/shaunak),

thanks for responding, as i describe in the issue then running: telnet 192.168.220.33 5044 i get this:

Trying 192.168.220.33...

telnet: connect to address [192.168.220.33](http://192.168.220.33): Connection timed out

[![](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa7c81a314df14f3a4acac74f5ba0fa269d58467.gif)](https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail)  
בלי וירוסים. [www.avast.com](https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail)

‫בתאריך יום ב׳, 20 באפר׳ 2020 ב-22:09 מאת ‪Shaunak Kashyap via Discuss the Elastic Stack‬‏ \<‪elastic@discoursemail.com‬‏\>:‬

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 21, 2020, 12:04am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/4 "2020-04-21T00:04:49Z")

</div>

The connection timed out can indicate one of two things:

- either there is a networking issue somewhere between your Filebeat host and your Logstash host, or
- there is nothing listening on port 5044 on your Logstash host.

What happens if you run `telnet localhost 5044` on your Logstash host? Does that work? If so then we know it's some networking issue between your Filebeat host and your Logstash host.

---

<div class="post-metadata">

**Author:** ![pash123](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@pash123](https://discuss.elastic.co/u/pash123)\
**Post date:** [April 21, 2020, 11:00am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/5 "2020-04-21T11:00:25Z")

</div>

```auto
I run the LG config file:
bin\logstash.bat -f C:\Users\pavel\OneDrive\Desktop\ELK\logstash-7.6.2\config\logstash.conf

this is the LS config file:
input{
	beats{
		port => 5044
	}
}
	
output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
  }
}

After i run this: 
C:\Windows\system32>netstat -na | find "5044"
  TCP 0.0.0.0:5044 0.0.0.0:0 LISTENING
  TCP [::]:5044 [::]:0 LISTENING

```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 21, 2020, 11:31am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/6 "2020-04-21T11:31:02Z")

</div>

Thanks. The `0.0.0.0` proves that Logstash is listening on port 5044 on all IP addresses assigned to the Logstash host. Is 192.168.220.33 one of those IP addresses? I'm not sure how to check that on Windows. If it is, then I'd check the Windows firewall configuration — is TCP port 5044 open to receiving connections from the outside?

---

<div class="post-metadata">

**Author:** ![pash123](https://avatars.discourse-cdn.com/v4/letter/p/ce73a5/32.png) [@pash123](https://discuss.elastic.co/u/pash123)\
**Post date:** [April 22, 2020, 9:38am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/7 "2020-04-22T09:38:55Z")

</div>

Hey, can I assigned this ip:192.168.220.33 on the logStash config file?  
P.S  
This ip:192.168.220.33 is my vpn ip.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 11:38am UTC](https://discuss.elastic.co/t/filebeat-refuse-connect-to-logstash-port-connection-timed-out-error/228803/8 "2020-05-20T11:38:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
