Logstash-filebeat error

Can some one help me resolve this error

root@logstash:/opt/logstash/bin# ./logstash -f logstash.conf
Apr 04, 2016 7:53:07 PM org.elasticsearch.node.internal.InternalNode
INFO: [logstash-logstash-3557-12128] version[1.7.0], pid[3557], build[929b973/2015-07-16T14:31:07Z]
Apr 04, 2016 7:53:07 PM org.elasticsearch.node.internal.InternalNode
INFO: [logstash-logstash-3557-12128] initializing ...
Apr 04, 2016 7:53:07 PM org.elasticsearch.plugins.PluginsService
INFO: [logstash-logstash-3557-12128] loaded [], sites []
Apr 04, 2016 7:53:10 PM org.elasticsearch.bootstrap.Natives
WARNING: JNA not found. native methods will be disabled.
Apr 04, 2016 7:53:11 PM org.elasticsearch.node.internal.InternalNode
INFO: [logstash-logstash-3557-12128] initialized
Apr 04, 2016 7:53:11 PM org.elasticsearch.node.internal.InternalNode start
INFO: [logstash-logstash-3557-12128] starting ...
Apr 04, 2016 7:53:11 PM org.elasticsearch.transport.TransportService doStart
INFO: [logstash-logstash-3557-12128] bound_address {inet[/0:0:0:0:0:0:0:0:9301]}, publish_address {inet[/192.168.1.14:9301]}
Apr 04, 2016 7:53:11 PM org.elasticsearch.discovery.DiscoveryService doStart
INFO: [logstash-logstash-3557-12128] elasticsearch/1GIoi9U_SUyDJgn8egGUew
Apr 04, 2016 7:53:15 PM org.elasticsearch.discovery.zen.ping.unicast.UnicastZenPing$4 handleException
WARNING: [logstash-logstash-3557-12128] failed to send ping to [[#zen_unicast_1#][logstash][inet[localhost/127.0.0.1:9200]]]
org.elasticsearch.transport.ReceiveTimeoutTransportException: [][inet[localhost/127.0.0.1:9200]][internal:discovery/zen/unicast_gte_1_4] request_id [0] timed out after [3752ms]
at org.elasticsearch.transport.TransportService$TimeoutHandler.run(TransportService.java:529)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
at java.lang.Thread.run(Thread.java:745)

Apr 04, 2016 7:53:19 PM org.elasticsearch.discovery.zen.ping.unicast.UnicastZenPing$4 handleException
WARNING: [logstash-logstash-3557-12128] failed to send ping to [[#zen_unicast_1#][logstash][inet[localhost/127.0.0.1:9200]]]
org.elasticsearch.transport.ReceiveTimeoutTransportException: [][inet[localhost/127.0.0.1:9200]][internal:discovery/zen/unicast_gte_1_4] request_id [3] timed out after [3751ms]
at org.elasticsearch.transport.TransportService$TimeoutHandler.run(TransportService.java:529)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
at java.lang.Thread.run(Thread.java:745)

Try using the HTTP protocol in the ES output.

I got this below error after adding protocol => http

Trouble parsing json {:source=>"rest", :raw=>"CONNECTION_LOST", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'CONNECTION_LOST': was expecting ('true', 'false' or 'null')
at [Source: [B@1e93758; line: 1, column: 31]>, :level=>:warn}
Trouble parsing json {:source=>"rest", :raw=>"CONNECTION_LOST", :exception=>#<LogStash::Json::ParserError: Unrecognized token 'CONNECTION_LOST': was expecting ('true', 'false' or 'null')
at [Source: [B@a54131; line: 1, column: 31]>, :level=>:warn}
^CSIGINT received. Shutting down the pipeline. {:level=>:warn}
Logstash shutdown completed

Can you post your config? OS? LS version? Java version?

input {
beats {
port => 5044
ssl => true
ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
}
}

filter {
grok {
match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} [%{WORD:text},%{NUMBER:num},%{IPV4:attack_src}]\s*[%{GREEDYDATA:username}][%{WORD:password}] -\s*%{GREEDYDATA:rest}" }
}

mutate {
gsub => ["rest", "'", '"']
gsub => ["rest", "False", "false"]
}

json {
source => "rest"
}

mutate {
remove_field => ["rest", "message"]
}
}

output {
elasticsearch {
host => ["localhost:9200"]
protocol => http
sniffing => true
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}

Try commenting out the sniffing line.