# LogStash-forwarder not sending data to Logstash/ElasticSearch older than 24 hours

**URL:** <https://discuss.elastic.co/t/logstash-forwarder-not-sending-data-to-logstash-elasticsearch-older-than-24-hours/76508>\
**Category:** Logstash\
**Created:** [February 25, 2017, 11:44pm UTC](https://discuss.elastic.co/t/logstash-forwarder-not-sending-data-to-logstash-elasticsearch-older-than-24-hours/76508 "2017-02-25T23:44:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![priyashet123](https://avatars.discourse-cdn.com/v4/letter/p/c57346/32.png) [@priyashet123](https://discuss.elastic.co/u/priyashet123)\
**Post date:** [February 25, 2017, 11:44pm UTC](https://discuss.elastic.co/t/logstash-forwarder-not-sending-data-to-logstash-elasticsearch-older-than-24-hours/76508/1 "2017-02-25T23:44:29Z")

</div>

We have ELK s/w setup in one server(serverA) and logstash-forwarder (in a remote server-ServerB), forwarding logs to ELK server(ServerA).

Everything works fine if both server are up and running.

If logstash-forwarder service is stopped for some reason and reinvoked after 24 hours , the logs with timestamp older than 24 hours (timestamp)are not transferred to the ELK server (ServerA).

What am i missing here?

This is the logstash.conf

input {  
lumberjack {  
port =\> 5000  
#type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

output {  
elasticsearch  
{  
hosts =\> ["127.0.0.1:9200"]

# index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

}  
#stdout { codec =\> rubydebug }  
}

~

Logstash-forwarder conf

{

"network": {  
# A list of downstream servers listening for our messages.  
# logstash-forwarder will pick one at random and only switch if  
# the selected one appears to be dead or unresponsive  
"servers": ["\<ServerA\_IP\>:5000"],

```
# The path to your client ssl certificate (optional)
#"ssl certificate": "./logstash-forwarder.crt",
# The path to your client ssl key (optional)

```

# "ssl key": "/etc/pki/tls/private/lumberjack.key",

```
# The path to your trusted ssl CA file. This is used
# to authenticate your downstream server.

```

"ssl ca": "/etc/pki/tls/certs/logstash-forwarder.crt",

# "ssl ca": "/etc/pki/tls/certs/lumberjack.crt",

```
# Network timeout in seconds. This is most important for
# logstash-forwarder determining whether to stop waiting for an
# acknowledgement from the downstream server. If an timeout is reached,
# logstash-forwarder will assume the connection or server is bad and
# will connect to a server chosen at random from the servers list.
"timeout": 15

```

},

"files": [  
{  
"paths": [  
"/opt/JBOSS\_FUSE/JBOSS/data/log/ECMLApp.log\*"  
],  
"dead time": "2400h",  
"fields": { "type": "ecmlApp logs" }  
}  
]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2017, 11:52pm UTC](https://discuss.elastic.co/t/logstash-forwarder-not-sending-data-to-logstash-elasticsearch-older-than-24-hours/76508/2 "2017-02-25T23:52:15Z")

</div>

LSF is no longer supported and has been replaced by filebeat, you should really upgrade.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2017, 11:52pm UTC](https://discuss.elastic.co/t/logstash-forwarder-not-sending-data-to-logstash-elasticsearch-older-than-24-hours/76508/3 "2017-03-25T23:52:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
