# Http communication failure connection refused

**URL:** <https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208>\
**Category:** Logstash\
**Created:** [February 7, 2025, 6:52am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208 "2025-02-07T06:52:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jecks\_Speed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jecks_speed/32/113221_2.png) [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Post date:** [February 7, 2025, 6:52am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/1 "2025-02-07T06:52:45Z")

</div>

Is there a way to keep the http port open in logstash?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 7, 2025, 9:15am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/2 "2025-02-07T09:15:52Z")

</div>

Which an input plugin do you use? Have you put any restriction?

---

<div class="post-metadata">

**Author:** ![Jecks\_Speed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jecks_speed/32/113221_2.png) [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Post date:** [February 7, 2025, 4:15pm UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/3 "2025-02-07T16:15:15Z")

</div>

Hello Rios,

I am using http plugin in the input. I did not put any restriction.  
I tried to use tcp\_keep\_alive =\> True but it did not worked as it is only applicable for tcp plugin.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 8, 2025, 10:54am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/4 "2025-02-08T10:54:53Z")

</div>

You cannot use `tcp_keep_alive` as parameter. The HTTP connection should be always active when LS is up and running. Can you explain us:

- how you set input plugin, full the input section
- have you checked tcp/http connection by telner/curl to LS server
- have you open the tcp port 80 on firewall
- is there any trace in LS log
- have you investigate in the debug mode:  
Add to the output section:  
`stdout { codec => rubydebug{}}`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 8, 2025, 12:50pm UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/5 "2025-02-08T12:50:36Z")

</div>

What exactly you want to do?

If the Logstash service is running, the port on the http input will always be listening, if the port is not listening then the logstash service may be stopped.

What does your configuration looks like? You need to share it.

---

<div class="post-metadata">

**Author:** ![Jecks\_Speed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jecks_speed/32/113221_2.png) [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Post date:** [February 11, 2025, 2:29pm UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/6 "2025-02-11T14:29:22Z")

</div>

Hello Rios,

my input plugin is configured something like this.  
input {  
http {  
port =\> "${port}"  
host =\> "0.0.0.0"  
codec =\> "json"   
}  
}

for bullet 1 and 2 i doubt i can do that since i have limited access as i am not the admin for the bullet 3 and 4 i will check that.

---

<div class="post-metadata">

**Author:** ![Jecks\_Speed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jecks_speed/32/113221_2.png) [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Post date:** [February 11, 2025, 2:50pm UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/7 "2025-02-11T14:50:35Z")

</div>

Hello leandro,

Thank you for your response, first is i just want to understand how http behaves in logstash. as you said if the logstash service is up and running. the port on the http will always be listening.

In your experience and experties in logstash do you have a known or common cause that affects the connection to http port except when the service is not running?

my logstash config look something like this.  
input {  
http {  
port =\> "${port}"  
host =\> "0.0.0.0"  
codec =\> "json"   
}  
}

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 12, 2025, 7:15am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208/8 "2025-02-12T07:15:32Z")

</div>

Make a test conf, something like this:

```auto
input {
	http {
		port => "1234"
		# host => "0.0.0.0" # No need, default value is "0.0.0.0"
		codec => "json"
	}
}
filter{
}
output {
    stdout { codec => rubydebug{}} 
}

```

Run LS, you should have active process on your port. Make sure that you have in the log, something like this:

```auto
2025-02-12T07:57:15,319][INFO][logstash.javapipeline][ls] Pipeline started {"pipeline.id"=>"ls"}
[2025-02-12T07:57:15,320][INFO][logstash.inputs.http][ls][d9dac642dfa1f391e1e5ff949cbd8cb61e85eb8f1b744e34a05132eb048783c8] Starting http input listener {:address=>"0.0.0.0:1234", :ssl_enabled=>false}

```

Send test data to LS, something like this:

`curl -X POST http://localhost:1234/ -H "Content-Type: application/json" -d "{\"title\":\"The test\",\"author\":\"J.J. TEST\",\"sender\":\"devops\"}"`

You should get parsed JSON fields.

In case of any issues please provide more details logs, screens.
