# INFO Error publishing events (retrying): read tcp read: connection reset by peer

**URL:** <https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358>\
**Category:** Logstash\
**Created:** [March 3, 2017, 7:51pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358 "2017-03-03T19:51:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmstein](https://avatars.discourse-cdn.com/v4/letter/w/a8b319/32.png) [@wmstein](https://discuss.elastic.co/u/wmstein)\
**Post date:** [March 3, 2017, 7:51pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358/1 "2017-03-03T19:51:16Z")

</div>

I put filebeat on a prod box and can not get filebeat to push to Logstash on my elkserver box. I am getting the below error from the filebeat.log file

INFO Error publishing events (retrying): read tcp IP:45790-\>ELK\_IP:5044: read: connection reset by peer

telnet works for that ip:5044. I tried making the ip addresses match on filebeat.yml and Logstash config but does not work. Logstash only seems to work if host is localhost. I see nothing in the logs telling me what the issue is. Telnet to port 5044 works so I am at a loss to understand why filebeat can not push a log.

filebeat.yml from Prod box:  
...  
#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

#hosts: ["localhost:5044"]  
hosts: ["[xx.0.0.xxx:5044](http://xx.0.0.xxx:5044)"]  
tls:  
# List of root certificates for HTTPS server verifications  
certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

#ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================  
...

Logstash config from my elserver box

## cat /etc/logstash/conf.d/02-beats-input.conf input { beats { port =\> 5044 ssl =\> true ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt" ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key" } }

cat /etc/logstash/conf.d/30-elasticsearch-output.conf  
output {  
elasticsearch {  
hosts =\> ["[xx.0.0.xxx:9200](http://xx.0.0.xxx:9200)"]  
#hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

I think it is something between the yml and output config but can not figure out how to get it working

---

<div class="post-metadata">

**Author:** ![wmstein](https://avatars.discourse-cdn.com/v4/letter/w/a8b319/32.png) [@wmstein](https://discuss.elastic.co/u/wmstein)\
**Post date:** [March 3, 2017, 10:52pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358/2 "2017-03-03T22:52:14Z")

</div>

I checked my ssl cert using: curl -v --cacert /etc/pki/tls/certs/logstash-forwarder.crt [https://xx.0.0.xxx:5044](https://xx.0.0.xxx:5044)  
and i think the below means it is ok -

ALPN, offering http/1.1

- SSL connection using TLS1.2 / ECDHE\_RSA\_AES\_256\_GCM\_SHA384
- server certificate verification OK
- server certificate status verification SKIPPED
- error fetching CN from cert:The requested data were not available.
- common name: (matched)
- server certificate expiration date OK
- server certificate activation date OK
- certificate public key: RSA
- certificate version: #3
- subject: C=AU,ST=Some-State,O=Internet Widgits Pty Ltd
- start date: Fri, 03 Mar 2017 21:11:40 GMT
- expire date: Mon, 01 Mar 2027 21:11:40 GMT
- issuer: C=AU,ST=Some-State,O=Internet Widgits Pty Ltd
- compression: NULL
- ALPN, server did not agree to a protocol

> GET / HTTP/1.1  
> Host: 10.0.0.212:5044  
> User-Agent: curl/7.47.0  
> Accept: _/_

- Empty reply from server
- Connection #0 to host 10.0.0.212 left intact  
curl: (52) Empty reply from server

---

<div class="post-metadata">

**Author:** ![wmstein](https://avatars.discourse-cdn.com/v4/letter/w/a8b319/32.png) [@wmstein](https://discuss.elastic.co/u/wmstein)\
**Post date:** [March 4, 2017, 5:21pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358/3 "2017-03-04T17:21:19Z")

</div>

I added a 10 minute timeout to Logstash config and still get the below filebeat error log

2017-03-04T17:18:52Z ERR Failed to publish events caused by: read tcp 10.0.0.xxx:34916-\>[10.0.0.xxx:5044](http://10.0.0.xxx:5044): read: connection reset by peer  
2017-03-04T17:18:52Z INFO Error publishing events (retrying): read tcp 10.0.0.xxx:34916-\>[10.0.0.xxx:5044](http://10.0.0.xxx:5044): read: connection reset by peer  
2017-03-04T17:19:09Z INFO Non-zero metrics in the last 30s: libbeat.logstash.call\_count.PublishEvents=1 libbeat.logstash.publish.read\_errors=1 libbeat.logstash.publish.write\_bytes=381 libbeat.logstash.published\_but\_not\_acked\_events=2044

---

<div class="post-metadata">

**Author:** ![wmstein](https://avatars.discourse-cdn.com/v4/letter/w/a8b319/32.png) [@wmstein](https://discuss.elastic.co/u/wmstein)\
**Post date:** [March 4, 2017, 5:44pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358/4 "2017-03-04T17:44:18Z")

</div>

Here are my versions loaded on the elkserver

curl -XGET 'localhost:9200'  
{  
"name" : "elkserver-node-1",  
"cluster\_name" : "elkserver-cluster-1",  
"cluster\_uuid" : "mxhWhcThS3uioz53lkj4FA",  
"version" : {  
"number" : "5.2.2",  
"build\_hash" : "f9d9b74",  
"build\_date" : "2017-02-24T17:26:45.835Z",  
"build\_snapshot" : false,  
"lucene\_version" : "6.4.1"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2017, 5:44pm UTC](https://discuss.elastic.co/t/info-error-publishing-events-retrying-read-tcp-read-connection-reset-by-peer/77358/5 "2017-04-01T17:44:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
