# Logstash active exited using filebeat input

**URL:** <https://discuss.elastic.co/t/logstash-active-exited-using-filebeat-input/53552>\
**Category:** Logstash\
**Created:** [June 21, 2016, 6:12pm UTC](https://discuss.elastic.co/t/logstash-active-exited-using-filebeat-input/53552 "2016-06-21T18:12:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![William\_Leclerc](https://avatars.discourse-cdn.com/v4/letter/w/9fc29f/32.png) [@William\_Leclerc](https://discuss.elastic.co/u/William_Leclerc)\
**Post date:** [June 21, 2016, 6:12pm UTC](https://discuss.elastic.co/t/logstash-active-exited-using-filebeat-input/53552/1 "2016-06-21T18:12:27Z")

</div>

I have a Logstash, Elasticsearch and Kibana service running on a server and Filebeat running on another server to test configurations. Everything is running fine with the following config, logs are forwarded to my elasticsearch/kibana.

> input {  
> beats {  
> port =\> 5045  
> ssl =\> true  
> ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
> ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
> }  
> }

> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> syslog\_pri { }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

The thing is that server admins are used to browse logs in command line interface and want access to them so I found out about the File plugin and decided to try it out.

I modified the output section for and added file plugin:

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }

> if [type] == "syslog" {  
> file {  
> #flush\_interval =\> 10  
> path =\> "/var/data/syslog/%{+YYYY}/%{+MM}/%{+dd}/%{source\_host}/%{syslog\_file\_name}.log"  
> #codec =\> { line { format =\> "" }}  
> }  
> }  
> }

I used the "service logstash configtest" command and my files are "ok".  
I restarted my services ES,Kibana and logstash.  
I restarted my filebeat client but it now gives me error:

> 2016/06/21 18:09:54.477774 transport.go:125: ERR SSL client failed to connect with: dial tcp ip\_address:5045: getsockopt: connection refused"

Meanwhile my logstash service goes Active: Active (exited) instead of Active (running).  
Firewalld is disableded and yes I have the correct certificate in the correct folder as the whole config is working fine before the ouput file is modified.

tailf /var/log/logstash/logstash.log

```
{:timestamp=>"2016-06-23T09:56:58.919000-0400", 
:message=>"UDP listener died", 
:exception=>#<SocketError: bind: name or service not known>, 
:backtrace=>["org/jruby/ext/socket/RubyUDPSocket.java:160:in `bind'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-2.0.5/lib/logstash/inputs/udp.rb:67:in `udp_listener'", 
"/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-2.0.5/lib/logstash/inputs/udp.rb:50:in `run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:334:in `inputworker'", 
 "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:328:in `start_input'"], 
 :level=>:warn}

```

I am probably missing something so if you have any hints let me know.  
WL

---

<div class="post-metadata">

**Author:** ![William\_Leclerc](https://avatars.discourse-cdn.com/v4/letter/w/9fc29f/32.png) [@William\_Leclerc](https://discuss.elastic.co/u/William_Leclerc)\
**Post date:** [June 21, 2016, 7:05pm UTC](https://discuss.elastic.co/t/logstash-active-exited-using-filebeat-input/53552/2 "2016-06-21T19:05:45Z")

</div>

OK so I did some more research on the problem. It seems that Filebeat is the reason why logstash stop working. When I stop Filebeat and start Logstash with the File plugin config it keeps running but as soon as I try to start Filebeat, logstash stop working.

filebeat -e -c /etc/filebeat/filebeat.yml

> 2016/06/21 19:04:15.824162 transport.go:125: ERR SSL client failed to connect with: dial tcp ip\_adress:5045: getsockopt: connection refused

tailf /var/log/logstash/logstash.log  
`{:timestamp=>"2016-06-22T09:48:00.529000-0400", :message=>"SIGTERM received. Shutting down the pipeline.", :level=>:warn} `  
The config I want:  
Filebeat-\>LS\>ES/File  
Keep in mind that the filebeat/ssl/logstash work fine with the first config....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/logstash-active-exited-using-filebeat-input/53552/3 "2017-07-06T04:50:57Z")

</div>


