# I have installed a 7.17.3 metric beat and file beat, both the beats are unable to send data to the logstash

**URL:** <https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018>\
**Category:** Logstash\
**Created:** [October 30, 2023, 10:08am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018 "2023-10-30T10:08:34Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [October 30, 2023, 10:08am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/1 "2023-10-30T10:08:34Z")

</div>

Hi Team,

I have a 3 node elk cluster 7.17.3 , i have installed metricbeats and file beat on a new server , the logstash ports are opened(5044). i have checked telnet. the connection looks fine.

The beats are unable to send the data to logstash. this is the info i got from the logs

INFO [publisher\_pipeline\_output] pipeline/output.go:143 Connecting to backoff(async(tcp://1xxx...:5044))  
2023-10-30T09:44:37.607Z INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2023-10-30T09:44:37.607Z INFO [publisher] pipeline/retry.go:223 done  
2023-10-30T09:44:37.610Z INFO [publisher\_pipeline\_output] pipeline/output.go:151 Connection to backoff(async(tcp://xxxxx5044)) established  
2023-10-30T09:44:37.614Z INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2023-10-30T09:44:37.614Z INFO [publisher] pipeline/retry.go:223 done  
2023-10-30T09:44:37.614Z ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp 1xxxx3:60612-\>1xxxx:5044: wsarecv: An existing connection was forcibly closed by the remote host.

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [October 30, 2023, 12:59pm UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/2 "2023-10-30T12:59:02Z")

</div>

Is there any issue with my logstash .. do i need to check anything in my logstash server

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 2, 2023, 6:33am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/3 "2023-11-02T06:33:37Z")

</div>

> [@AKAM14](#):
>
> ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp 1xxxx3:60612-\>1xxxx:5044: wsarecv: An existing connection was forcibly closed by the remote host.

can some one look in to this issue

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 2, 2023, 8:53am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/4 "2023-11-02T08:53:02Z")

</div>

Are you using HTTPS connection?

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 2, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/5 "2023-11-02T09:05:01Z")

</div>

> [@AKAM14](#):
>
> ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp

No, We are not using the https . currently we are trying to connect via http

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 2, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/6 "2023-11-02T09:05:26Z")

</div>

We are not using https.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 2, 2023, 9:06am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/7 "2023-11-02T09:06:44Z")

</div>

Can you show part from filebeat.yml and input from LS?  
If there is an active firewall on LS, open TCP port 5044

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 2, 2023, 12:30pm UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/8 "2023-11-02T12:30:30Z")

</div>

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

# filestream is an input for collecting log messages from files.
- type: filestream

  # Change to true to enable this input configuration.
  enabled: false

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    #- /var/log/*.log
    - D:\xxx\Scripts\xxx\rxxx_log.txt

  # Exclude lines. A list of regular expressions to match. It drops the lines that are
  # matching any regular expression from the list.
  #exclude_lines: ['^DBG']

  # Include lines. A list of regular expressions to match. It exports the lines that are
  # matching any regular expression from the list.
  include_lines: ['.*xxxxxx stopped(.*)']

  # Exclude files. A list of regular expressions to match. Filebeat drops the files that
  # are matching any regular expression from the list. By default, no files are dropped.
  #prospector.scanner.exclude_files: ['.gz$']

  # Optional additional fields. These fields can be freely picked
  # to add additional information to the crawled log files for filtering
  #fields:
  # level: debug
  # review: 1

# ============================== Filebeat modules ==============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

# ======================= Elasticsearch template setting =======================

setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false

# ================================== General ===================================

# The name of the shipper that publishes the network data. It can be used to group
# all the transactions sent by a single shipper in the web interface.
#name:

# The tags of the shipper are included in their own field with each
# transaction published.
#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the
# output.
fields:
   env: pre-production
   Application: pass2
   Data: filebeat

# ================================= Dashboards =================================
# These settings control loading the sample dashboards to the Kibana index. Loading
# the dashboards is disabled by default and can be enabled either by setting the
# options here or by using the `setup` command.
#setup.dashboards.enabled: false

# The URL from where to download the dashboards archive. By default this URL
# has a value which is computed based on the Beat name and version. For released
# versions, this URL points to the dashboard archive on the artifacts.elastic.co
# website.
#setup.dashboards.url:

# =================================== Kibana ===================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.
# This requires a Kibana endpoint configuration.
setup.kibana:

  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
  #host: "localhost:5601"

  # Kibana Space ID
  # ID of the Kibana Space into which the dashboards should be loaded. By default,
  # the Default Space will be used.
  #space.id:

# =============================== Elastic Cloud ================================

# These settings simplify using Filebeat with the Elastic Cloud (https://cloud.elastic.co/).

# The cloud.id setting overwrites the `output.elasticsearch.hosts` and
# `setup.kibana.host` options.
# You can find the `cloud.id` in the Elastic Cloud web UI.
#cloud.id:

# The cloud.auth setting overwrites the `output.elasticsearch.username` and
# `output.elasticsearch.password` settings. The format is `<user>:<pass>`.
#cloud.auth:

# ================================== Outputs ===================================

# Configure what output to use when sending the data collected by the beat.

# ---------------------------- Elasticsearch Output ----------------------------
#output.elasticsearch:
  # Array of hosts to connect to.
  #hosts: ["localhost:9200"]

  # Protocol - either `http` (default) or `https`.
  #protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  #username: "elastic"
  #password: "changeme"

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["xxxxxx:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  
  # Certificate for SSL client authentication
  
  # Client Certificate Key

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 2, 2023, 1:25pm UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/9 "2023-11-02T13:25:25Z")

</div>

Have you check firewall?  
Also, most likely file registry already contain record that files have been read. You can delete or change `filebeat.registry.path:`

Please use \< /\> icon for formatting text.

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 14, 2023, 1:46pm UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/10 "2023-11-14T13:46:50Z")

</div>

For some reasons, both the metric beat and file beat data are not getting sent to the logstash server .

This is the error i get in the metric beat log files

ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp 1xxxx:5044: wsarecv: An existing connection was forcibly closed by the remote host.  
2023-11-14T13:22:58.655Z ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: read tcp 1xxx-\>1xx:5044: wsarecv: An existing connection was forcibly closed by the remote host.  
2023-11-14T13:22:58.655Z INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2023-11-14T13:22:58.655Z INFO [publisher] pipeline/retry.go:223 done  
2023-11-14T13:22:58.655Z INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer  
2023-11-14T13:22:58.655Z INFO [publisher] pipeline/retry.go:223 done  
2023-11-14T13:22:58.655Z ERROR [logstash] logstash/async.go:280 Failed to publish events caused by: client is not connected  
2023-11-14T13:22:58.655Z INFO [publisher] pipeline/retry.go:159 Drop batch  
2023-11-14T13:23:00.578Z ERROR [publisher\_pipeline\_output] pipeline/output.go:180 failed to publish events: client is not connected

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [November 14, 2023, 1:47pm UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/11 "2023-11-14T13:47:24Z")

</div>

telnet to logstash port 5044 is working fine .

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [December 1, 2023, 5:02am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/12 "2023-12-01T05:02:43Z")

</div>

any one has any thoughts about this file beat issue

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 1, 2023, 5:22am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/13 "2023-12-01T05:22:28Z")

</div>

Share your logstash.conf the logstash pipeline file

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 1, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/14 "2023-12-01T05:24:15Z")

</div>

> [@AKAM14](#):
>
> ` enabled: false`

That input is not enabled

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018/15 "2023-12-29T05:24:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
