# Filebeat to Logstash --\> DBG \[transport\] handle error: EOF

**URL:** <https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [August 26, 2019, 9:17am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735 "2019-08-26T09:17:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andreatera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreatera/32/115921_2.png) [@andreatera](https://discuss.elastic.co/u/andreatera)\
**Post date:** [August 26, 2019, 9:17am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735/1 "2019-08-26T09:17:16Z")

</div>

We have the following Filebeat 6.1.3 conf:

> ```
> filebeat.prospectors:
> - type: log
> paths:
> - /usr/share/filebeat/taifunlogs/server.log
> 
> output.logstash:
> hosts: ["xxxxxx.com:443"]
> bulk_max_size: 999999999
> 
> logging.level: debug
> logging.to_files: false
> logging.to_syslog: false
> loggins.metrice.enabled: false
> logging.files:
> path: /var/log/filebeat
> name: filebeat
> keepfiles: 7
> permissions: 0644
> ssl.verification_mode: none
> 
> ```

and Logstash 6.1.3 pipeline:

> input {  
> http {  
> port =\> "5044"  
> }  
> }
> 
> ## Add your filters / logstash plugins configuration here
> 
> output {  
> elasticsearch {  
> hosts =\> ["[https://376d1d6ba0b54ecf9ace06b3b8ddd4db.elasticsearch.xxxx.com](https://376d1d6ba0b54ecf9ace06b3b8ddd4db.elasticsearch.xxxx.com)"]  
> user =\> "es3iv3ARd9U6egMrg5"  
> password =\> "GeaUxFT5zmMJqUZT"  
> ssl =\> true  
> ssl\_certificate\_verification =\> true  
> codec =\> "plain"  
> workers =\> 1  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> manage\_template =\> true  
> template\_name =\> "logstash"  
> template\_overwrite =\> true  
> }  
> }

We also configured a TCP routing from 443 to 5044, in fact we can run a test wget from the filebeat machine to the Logstash url (443) and the message is received correctly.  
Unfortunately with this configuration this is what we get from filbeat (trying to inject a 173M message):

> filebeat\_1 | "message": "[#|2019-08-25T18:04:08.335+0200|FINE|Payara 4.1|ch.ergon.taifun.sql.DistributedWorksetSql|\_ThreadID=263;\_ThreadName=allegro/incrementalUpdateConsumer-managedThreadFactory-Thread-5;\_TimeMillis=1566749048335;\_LevelValue=500;ClassName=ch.ergon.taifun.base.jooq.impl.LoggingExecuteListener;MethodName=logFine;|Query with params : select CE\_LOCK.LOCK\_NAME, CE\_LOCK.SUB\_LOCK\_NAME, CE\_LOCK.LOCKING\_FUNCTION, CE\_LOCK.HOSTNAME, CE\_LOCK.USERW, CE\_LOCK.DATEW, CE\_LOCK.USERI, CE\_LOCK.DATEI from CE\_LOCK where CE\_LOCK.LOCK\_NAME = 'REPORTING\_SYNC\_LOCK' for update|#]",  
> filebeat\_1 | "prospector": {  
> filebeat\_1 | "type": "log"  
> filebeat\_1 | },  
> filebeat\_1 | "beat": {  
> filebeat\_1 | "name": "filebeat",  
> filebeat\_1 | "hostname": "filebeat",  
> filebeat\_1 | "version": "6.1.3"  
> filebeat\_1 | }  
> filebeat\_1 | }  
> filebeat\_1 | 2019/08/26 09:11:33.420534 processor.go:275: DBG [publish] Publish event: {  
> filebeat\_1 | "@timestamp": "2019-08-26T09:11:33.420Z",  
> filebeat\_1 | "@metadata": {  
> filebeat\_1 | "beat": "filebeat",  
> filebeat\_1 | "type": "doc",  
> filebeat\_1 | "version": "6.1.3"  
> filebeat\_1 | },  
> filebeat\_1 | "source": "/usr/share/filebeat/taifunlogs/server.log",  
> filebeat\_1 | "offset": 2375631,  
> filebeat\_1 | "message": "[#|2019-08-25T18:04:08.356+0200|INFO|Payara 4.1|ch.ergon.taifun.commonentities.lock.LockService|\_ThreadID=263;\_ThreadName=allegro/incrementalUpdateConsumer-managedThreadFactory-Thread-5;\_TimeMillis=1566749048356;\_LevelValue=800;|Acquired partial locks unsafely: REPORTING\_INC\_RUNNING(d-alg-be-11)|#]",  
> filebeat\_1 | "prospector": {  
> filebeat\_1 | "type": "log"  
> filebeat\_1 | },  
> filebeat\_1 | "beat": {  
> filebeat\_1 | "version": "6.1.3",  
> filebeat\_1 | "name": "filebeat",  
> filebeat\_1 | "hostname": "filebeat"  
> filebeat\_1 | }  
> filebeat\_1 | }  
> filebeat\_1 | 2019/08/26 09:11:33.420615 processor.go:275: DBG [publish] Publish event: {  
> filebeat\_1 | "@timestamp": "2019-08-26T09:11:33.420Z",  
> filebeat\_1 | "@metadata": {  
> filebeat\_1 | "beat": "filebeat",  
> filebeat\_1 | "type": "doc",  
> filebeat\_1 | "version": "6.1.3"  
> filebeat\_1 | },  
> filebeat\_1 | 2019/08/26 09:12:05.648135 output.go:92: ERR Failed to publish events: client is not connected  
> filebeat\_1 | 2019/08/26 09:12:05.648197 async.go:94: DBG [logstash] connect  
> filebeat\_1 | 2019/08/26 09:12:05.648619 logger.go:22: INFO retryer: send unwait-signal to consumer  
> filebeat\_1 | 2019/08/26 09:12:05.648644 logger.go:22: INFO done  
> filebeat\_1 | 2019/08/26 09:12:05.648655 logger.go:22: INFO retryer: send wait signal to consumer  
> filebeat\_1 | 2019/08/26 09:12:05.648665 logger.go:22: INFO done  
> filebeat\_1 | 2019/08/26 09:12:05.654675 logger.go:22: INFO retryer: send unwait-signal to consumer  
> filebeat\_1 | 2019/08/26 09:12:05.654698 logger.go:22: INFO done  
> filebeat\_1 | 2019/08/26 09:12:05.658828 async.go:142: DBG [logstash] 295 events out of 295 events sent to logstash host [xxxxxxxxx.com:443](http://xxxxxxxxx.com:443). Continue sending  
> filebeat\_1 | 2019/08/26 09:12:05.660761 client.go:201: DBG [transport] handle error: EOF  
> filebeat\_1 | 2019/08/26 09:12:05.660799 client.go:114: DBG [transport] closing  
> filebeat\_1 | 2019/08/26 09:12:05.660869 async.go:235: ERR Failed to publish events caused by: EOF  
> filebeat\_1 | 2019/08/26 09:12:05.689668 async.go:142: DBG [logstash] 1973 events out of 1973 events sent to logstash host [xxxxxxxx.com:443](http://xxxxxxxx.com:443). Continue sending  
> filebeat\_1 | 2019/08/26 09:12:05.689696 async.go:99: DBG [logstash] close connection  
> filebeat\_1 | 2019/08/26 09:12:05.689705 async.go:99: DBG [logstash] close connection  
> filebeat\_1 | 2019/08/26 09:12:05.689724 async.go:235: ERR Failed to publish events caused by: client is not connected  
> filebeat\_1 | 2019/08/26 09:12:05.689739 logger.go:22: INFO retryer: send wait signal to consumer

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2019, 9:17am UTC](https://discuss.elastic.co/t/filebeat-to-logstash-dbg-transport-handle-error-eof/196735/2 "2019-09-23T09:17:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
