# Logstash keep restarting and doesn't listen to beats

**URL:** <https://discuss.elastic.co/t/logstash-keep-restarting-and-doesnt-listen-to-beats/80001>\
**Category:** Logstash\
**Created:** [March 25, 2017, 6:13pm UTC](https://discuss.elastic.co/t/logstash-keep-restarting-and-doesnt-listen-to-beats/80001 "2017-03-25T18:13:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahar\_q](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@sahar\_q](https://discuss.elastic.co/u/sahar_q)\
**Post date:** [March 25, 2017, 6:13pm UTC](https://discuss.elastic.co/t/logstash-keep-restarting-and-doesnt-listen-to-beats/80001/1 "2017-03-25T18:13:29Z")

</div>

Hi guys, i'm using ubuntu server 16.10 headless, i installed ELK and filebeat via apt,  
configured everything i should've (that i know of) and for some reason, logstash isn't getting the syslogs from the 'filebeat' , and the logstash service keeps shutting down and activating again and again.  
i realy dont get what's happening and would like some help.  
•note: every think is installed on a single machine who's IP is 192.168.32.131  
here are my config file:  
logstash conf:  
`input {   
beats {  
port =\> "5043"  
}   
}

filter {

if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostnmae} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }   
}  
}  
}

output {  
elasticsearch{  
hosts =\> ["192.168.32.131:9200"]  
index =\> "%{[@metadata][beats]}-%{+YYYY.MM.dd}"  
docuent\_type =\> "%{[@metadata][type]}"  
}  
}  
`

filebeat conf:  
#-------------------------- Elasticsearch output ------------------------------  
#output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
output.logstash:

# The Logstash hosts

hosts: ["192.168.32.131:5043"]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 27, 2017, 7:21am UTC](https://discuss.elastic.co/t/logstash-keep-restarting-and-doesnt-listen-to-beats/80001/2 "2017-03-27T07:21:16Z")

</div>

If Logstash is restarting I'd expect to find clues in the Logstash log.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2017, 7:21am UTC](https://discuss.elastic.co/t/logstash-keep-restarting-and-doesnt-listen-to-beats/80001/3 "2017-04-24T07:21:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
