# Logstash elastic\_agent input: connection resets

**URL:** <https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898>\
**Category:** Logstash\
**Created:** [July 30, 2026, 11:04am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898 "2026-07-30T11:04:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![CD9820](https://avatars.discourse-cdn.com/v4/letter/c/e9c0ed/32.png) [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Post date:** [July 30, 2026, 11:04am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898/1 "2026-07-30T11:04:46Z")

</div>

I notice a lot of java.net.SocketException: Connection reset warnings in my Logstash logs. It seems this is related to the elastic\_agent input and is noticeably higher in combination with Defend. It also occurs on devices where there is no firewall or load balancer between the device and the logstash server. Is this a known issue or does anyone have any ideas how to fix this?

Best regards

Christophe

---

<div class="post-metadata">

**Author:** ![covj12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/covj12/32/147474_2.png) [@covj12](https://discuss.elastic.co/u/covj12)\
**Post date:** [August 13, 2026, 4:57am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898/2 "2026-08-13T04:57:55Z")

</div>

Hello, you can check network connectivity between the Elastic Agent and Logstash using Telnet. If the connection is established, the network path between the two components is may working fine.

And Regarding `client_inactivity_timeout` (default: 60s) option, If the agent sends no data within that time period, Logstash will close the connection. So if you observe the connection being dropped after ~60 seconds of inactivity, it likely indicates that the agent is not producing or sending data.

> **[client\_inactivity\_timeout - Elastic Agent input plugin | Logstash Plugins](https://www.elastic.co/docs/reference/logstash/plugins/plugins-inputs-elastic_agent#plugins-inputs-elastic_agent-client_inactivity_timeout)**
>
> Close Idle clients after X seconds of inactivity. | Plugin version: v7.0.0, Released on: 2024-12-02, Changelog. For other versions, see the Versioned plugin docs. For questions about the plugin, open a...

In that case, you can check whether the agent is actually working by:

- Confirming the agent process is running: `ps aux | grep elastic-agent`
- Reviewing Elastic Agent logs for errors or restart loops
- Ensuring the agent policy and output configuration correctly point to Logstash (host/port)
