# Logstash/logstash forwarder connection issue

**URL:** <https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532>\
**Category:** Logstash\
**Created:** [January 30, 2016, 12:09am UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532 "2016-01-30T00:09:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [January 30, 2016, 12:09am UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/1 "2016-01-30T00:09:01Z")

</div>

Hello, I am trying to send records using logstash forwarder to logstash instance(dedicated server), then from logstash to elasticsearch(another dedicated server) but got this error from logstash:

Lumberjack input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover. {:exception=\>LogStash::CircuitBreaker::HalfOpenBreaker, :level=\>:warn}  
Lumberjack input: the pipeline is blocked, temporary refusing new connection. {:level=\>:warn}  
CircuitBreaker::Open {:name=\>"Lumberjack input", :level=\>:warn}  
Lumberjack input: The circuit breaker has detected a slowdown or stall in the pipeline, the input is closing the current connection and rejecting new connection until the pipeline recover. {:exception=\>LogStash::CircuitBreaker::OpenBreaker, :level=\>:warn}  
Lumberjack input: the pipeline is blocked, temporary refusing new connection. {:level=\>:warn}  
Lumberjack input: the pipeline is blocked, temporary refusing new connection. {:level=\>:warn}  
...  
...

and this error from logstash-forwarder:  
Read error looking for akc:EOF

and it keeps trying to reconnect, and once connected, it's back to the error again

I tested them individually, I was able to send records from logstash-forwarder to logstash and print them to the terminal, I was also able to parse logs with logstash and send them to elasticsearch. But when I connect them together, aka, logstash-forwarder-\> logstash -\> elasticsearch. I have the situation above? Any suggestions will be appreciated. Thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 30, 2016, 12:56am UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/2 "2016-01-30T00:56:50Z")

</div>

Providing your configs would be useful.

Please make sure you format them with the pre-formatted option!

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [February 1, 2016, 5:35pm UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/3 "2016-02-01T17:35:06Z")

</div>

forwarder config:  
`{ "network": { "servers": ["server_name:8010"], "ssl ca": "lumberjack.crt", "timeout": 30 }, "files": [{ "paths": [ "C:/Users/DAVIDL/Desktop/logs/*"], "fields": { "type": "log" } } ] }`

logstash input:  
`lumberjack { port => 8010 # flush_size => 512 ssl_certificate => "/home/davidl/logstash-2.1.1/ssl/lumberjack.crt" ssl_key => "/home/davidl/logstash-2.1.1/ssl/lumberjack.key" }`  
logstash output:  
`lumberjack { hosts => "Another-server" port => 5043 ssl_certificate => "/home/logstash-2.1.1/ssl/logstash-forwarder.crt" codec => "json" }`

Thank you for the help!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2016, 5:42pm UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/4 "2016-02-01T17:42:04Z")

</div>

> [@DavidL](#):
>
> lumberjack { hosts =\> "Another-server" port =\> 5043 ssl\_certificate =\> "/home/logstash-2.1.1/ssl/logstash-forwarder.crt" codec =\> "json" }

If your Logstash instance is to send logs to Elasticsearch, why does the output contain the lumberjack output plugin?

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [February 1, 2016, 5:50pm UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/5 "2016-02-01T17:50:04Z")

</div>

Sorry, I should have made this more clear, the logstash instance is actually sending the logs to another logstash instance before eventually get to elasticsearch, this it the infrastructure set up by the logging team at our company, they want to make sure everything is formatted well in Json before their logstash gets the records. My job is to make sure our logs get parsed and well formatted before sending to them, and I encountered the above in the process.

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [February 8, 2016, 10:58pm UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/6 "2016-02-08T22:58:12Z")

</div>

Fixed by changing to Filebeat, I would recommend whoever's having logstash forwarder issues to switch to filebeat first and see if it's resolved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/logstash-logstash-forwarder-connection-issue/40532/7 "2017-07-06T05:12:38Z")

</div>


