# Logsatash同士の通信エラー

**URL:** <https://discuss.elastic.co/t/logsatash/151543>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [October 9, 2018, 2:32am UTC](https://discuss.elastic.co/t/logsatash/151543 "2018-10-09T02:32:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aurantiacus](https://avatars.discourse-cdn.com/v4/letter/a/ebca7d/32.png) [@aurantiacus](https://discuss.elastic.co/u/aurantiacus)\
**Post date:** [October 9, 2018, 2:32am UTC](https://discuss.elastic.co/t/logsatash/151543/1 "2018-10-09T02:32:40Z")

</div>

3つ質問があります。  
上記lumberjack同士の通信において、LSサーバ(srv1)のlogstashのログで発生が頻発しています。

1.下記ログが発生している場合、何台かhostからのログの受信ができていないのでしょうか？  
2.このログの発生を無くす（限りなく減らす）ための有効な設定や試せることはあるでしょうか？  
3.そもそもbeatを動かしすぎでlumberjackでのログ送受信運用が厳しいとかありますでしょうか？

**構築環境**

> host[beat(out:lumberjack)--\>logstash(out:lumberjack)]--\>インターネット--\>srv1[logstash(in:lumberjack)]\*1台--\>srv2[elasticsearch]\*3台  
> ※beatはauditbeat,filebeat,packetbeat,winlogbeat  
> ※全てVer6.4.0で統一  
> ※hostは10台。今後増える可能性有。

**マシン情報**

> host:Windows7,10  
> srv1:centos7(仮想srv)  
> srv2:centos7(仮想srv)

**logstash.confの設定**

> 【srv1】  
> input.lumberjackで受信できるよう必要な設定のみ  
> output.elasticsearchのhostsにはelasticsearch3台のIPを設定  
> ※filterなどは設定していません。

**srv1で出力されるログ**

> [pool-5-thread-41] lumberjack - Lumberjack input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover. {:exception=\>LogStash::CircuitBreaker::OpenBreaker}  
> [[main]\<lumberjack] lumberjack - Lumberjack input: the pipeline is blocked, temporary refusing new connection.  
> [Ruby-0-Thread-18@[main]\>worker0: :1] elasticsearch - Marking url as dead. Last error: [LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError] Elasticsearch Unreachable: [[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/)][Manticore::SocketTimeout] Read timed out {:url=\>[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/), :error\_message=\>"Elasticsearch Unreachable: [[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/)][Manticore::SocketTimeout] Read timed out", :error\_class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError"}  
> [Ruby-0-Thread-18@[main]\>worker0: :1] elasticsearch - Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_message=\>"Elasticsearch Unreachable: [[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/)][Manticore::SocketTimeout] Read timed out", :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError", :will\_retry\_in\_seconds=\>2}  
> [Ruby-0-Thread-10: :1] elasticsearch - Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/), :path=\>"/"}  
> [Ruby-0-Thread-10: :1] elasticsearch - Restored connection to ES instance {:url=\>"[http://xxx.xxx.xxx.xxx:9200/](http://xxx.xxx.xxx.xxx:9200/)"}

私が試したことは  
【srv1】  
・cpuコアを8つ（ワーカーが8つで動作する）  
・メモリ8gb(javaヒープmin,maxを4gb)  
【srv2】※3台とも同じ設定  
・メモリ8gb(javaヒープmin,maxを4gb)

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [October 22, 2018, 7:20am UTC](https://discuss.elastic.co/t/logsatash/151543/2 "2018-10-22T07:20:28Z")

</div>

ログを見たところ、Es側に接続がタイムアウトしたりしているようですが、  
Es側のログには何も出ていないでしょうか？  
例えば、CPUが高かったり、GCが走っていたりと、Esのクラスター側の性能などは測定していないでしょうか？

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2018, 7:20am UTC](https://discuss.elastic.co/t/logsatash/151543/3 "2018-11-19T07:20:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
