# Logstash hangs (CLOSE\_WAIT)

**URL:** <https://discuss.elastic.co/t/logstash-hangs-close-wait/201545>\
**Category:** Logstash\
**Created:** [September 29, 2019, 7:48pm UTC](https://discuss.elastic.co/t/logstash-hangs-close-wait/201545 "2019-09-29T19:48:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![manunc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manunc/32/48340_2.png) [@manunc](https://discuss.elastic.co/u/manunc)\
**Post date:** [September 29, 2019, 7:48pm UTC](https://discuss.elastic.co/t/logstash-hangs-close-wait/201545/1 "2019-09-29T19:48:04Z")

</div>

Hello,

Logstash version 7.3.2-1 on CentOS 7.6.1810

Since several days I noticed that Logstash is frozen every 24h.  
When I check the server I found a lot of CLOSE\_WAIT (131).

Nothing in the logstash-plain.log relevant and even no error logs displayed

...  
tcp6 322 0 127.0.0.1:52001 127.0.0.1:33758 CLOSE\_WAIT 0 0 -  
tcp6 322 0 127.0.0.1:52001 127.0.0.1:42042 CLOSE\_WAIT 0 0 -  
tcp6 322 0 127.0.0.1:52001 127.0.0.1:41674 CLOSE\_WAIT 0 0 -  
tcp6 622 0 127.0.0.1:52001 127.0.0.1:35762 CLOSE\_WAIT 0 0 -  
...

My configuration is the following:  
NGINX listening on port 443 (SSL) forwarding request to logstash on port 52001 (SSL) using http-input-plugin:

input {  
http {  
host =\> "0.0.0.0"  
port =\> 52001  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/var/element/elk/certs/cert4.pem"]  
ssl\_certificate =\> "/var/element/elk/certs/fullchain4.pem"  
ssl\_key =\> "/var/element/elk/certs/privkey4.pem"  
ssl\_verify\_mode =\> "peer"  
tags =\> ["opt","lorawan"]  
}  
}

Any idea or clues to debug this?

The only things to do for the moment is to restart logstash

---

<div class="post-metadata">

**Author:** ![manunc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manunc/32/48340_2.png) [@manunc](https://discuss.elastic.co/u/manunc)\
**Post date:** [October 1, 2019, 8:22pm UTC](https://discuss.elastic.co/t/logstash-hangs-close-wait/201545/2 "2019-10-01T20:22:04Z")

</div>

Hello,

Any help?  
The situation appears again today.  
Is it possible to turn something in debug mode?

Br

---

<div class="post-metadata">

**Author:** ![manunc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manunc/32/48340_2.png) [@manunc](https://discuss.elastic.co/u/manunc)\
**Post date:** [October 10, 2019, 9:58am UTC](https://discuss.elastic.co/t/logstash-hangs-close-wait/201545/3 "2019-10-10T09:58:06Z")

</div>

I found the root cause of my issue without for the moment found the solution but every 24 hours I got too many CLOSE\_WAIT due to an input syslog plugin not used so I removed it for the moment.  
If it can help someone 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 9:58am UTC](https://discuss.elastic.co/t/logstash-hangs-close-wait/201545/4 "2019-11-07T09:58:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
