# Logstash not listening on port

**URL:** <https://discuss.elastic.co/t/logstash-not-listening-on-port/255356>\
**Category:** Logstash\
**Created:** [November 13, 2020, 2:38pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356 "2020-11-13T14:38:22Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 13, 2020, 2:38pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/1 "2020-11-13T14:38:22Z")

</div>

I noticed that nothing is listening on port 5044 on my ELK server. Logstash is running. Is there some configuration I missed somewhere to have it running/listening on that port? Here are the last few lines from my log file:

```auto
[2020-11-13T14:36:17,578][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.10.0", "jruby.version"=>"jruby 9.2.13.0 (2.5.7) 2020-08-03 9a89c94bcc OpenJDK 64-Bit Server VM 11.0.8+10 on 11.0.8+10 +indy +jit [linux-x86_64]"}
[2020-11-13T14:36:19,947][INFO][logstash.config.source.local.configpathloader] No config files found in path {:path=>"/etc/logstash/conf.d/*.conf"}
[2020-11-13T14:36:19,996][ERROR][logstash.config.sourceloader] No configuration found in the configured sources.
[2020-11-13T14:36:20,316][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 13, 2020, 2:56pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/2 "2020-11-13T14:56:35Z")

</div>

Right now it's looking for configuration files in `/etc/logstash/conf.d/*.conf` and it looks like you don't have any in that folder. So create a file called `name.conf` in `/etc/logstash/conf.d/` with the below suggestions. Then restart logstash to run.

You need to create a pipeline configuration using [this structure](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html).

Most likely you will want a [UDP](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-udp.html) or [TCP](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html) input if you are listening to a port.

No filter unless you want to manipulate the data.

Then an [elasticsearch output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html).

---

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 13, 2020, 3:44pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/3 "2020-11-13T15:44:20Z")

</div>

Thank you for your response and help.  
Here is what I am seeing from the client-side for Logstash:

```auto
Failed to publish events caused by: read tcp 192.168.0.100:46456->192.168.0.103:5044: i/o timeout
isher] pipeline/retry.go:223 done
stash] logstash/async.go:280 Failed to publish events caused by: write tcp 192.168.0.100:46456->192.168.0.103:5044: use of closed network connection

```

On the server, 5044 is now listening:

```auto
tcp6 0 0 :::5044 :::* LISTEN 7744/java           

```

In the logstash folder on the server, I created log4j2.xml:

```auto
<Configuration>
  <Appenders>
     <Socket name="Socket" host="192.168.0.103" port="5044">
       <JsonLayout compact="true" eventEol="true" />
    </Socket>
  </Appenders>
  <Loggers>
    <Root level="info">
      <AppenderRef ref="Socket"/>
    </Root>
  </Loggers>
</Configuration>

```

In my name.conf file:

```auto
input {
    tcp {
    port => 5044
    codec => json
    }
}

filter {
  date {
    match => ["timeMillis", "UNIX_MS"]
  }
}

output {
  elasticsearch {
    index => "%{[@metadata][beat]}"
  }
}

```

Also, is TCP or UDP recommended?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 13, 2020, 4:06pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/4 "2020-11-13T16:06:37Z")

</div>

TCP is recommended over UDP due to TCP less likely than TCP to lose messages.

---

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 13, 2020, 5:18pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/5 "2020-11-13T17:18:29Z")

</div>

Ok, and what about the error message that I am getting? How would I resolve that?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 13, 2020, 5:32pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/6 "2020-11-13T17:32:13Z")

</div>

Sorry didn't see the other question. Can you change your output to the below and let me know what it says?

```auto
output {
  stdout { }
}

```

---

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 17, 2020, 3:47pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/7 "2020-11-17T15:47:20Z")

</div>

I am not sure why, but I am having a hard time stopping/starting/restarting the logstash service. Here is the error that I am seeing:

```auto
2020-11-17T15:40:19,620][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://127.0.0.1:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [http://127.0.0.1:9200/][Manticore::SocketException] Connection refused (Connection refused)"}

```

I see elasticsearch is listening on 127.0.0.1 instead of the 192 IP. But when I view the elasticsearch conf file, I see the network.host is set to this 192 address. Is there another place this needs to be defined, that it's being pointed to?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 17, 2020, 4:02pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/8 "2020-11-17T16:02:01Z")

</div>

What do you have in your logstash output [elasticsearch for hosts](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-hosts)? The default is `127` so if you don't set it to the right IP then it won't try to go there.

---

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 18, 2020, 1:13pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/9 "2020-11-18T13:13:48Z")

</div>

Here is what it looks like now:

```auto
output {
  elasticsearch {
    index => "%{[@metadata][beat]}"
    hosts => "192.168.0.103"
  }
}

```

Here is what I am seeing now though, on logstash:

```auto
 [2020-11-18T13:08:12,824][WARN][logstash.codecs.jsonlines][main][26da92079e525d4bfdac5a892ff28079c6695bd768a516e8a992f0d588033c05] Received an event that has a different character encoding than you configured. {:text=>"\\u000E\\x97P]...
 [2020-11-18T13:08:12,826][WARN][logstash.codecs.jsonlines][main][26da92079e525d4bfdac5a892ff28079c6695bd768a516e8a992f0d588033c05] JSON parse error, original data now in message field {:error=>#<LogStash::Json::ParserError: Unrecognized token 'z': was expecting ('true', 'false' or 'null')
 at [Source: (String)"z -9\x92\u0001~\u0000/\f\x960l...

```

EDIT:  
I added

```auto
codec => plain {
      charset => "ISO-8859-1"
    }

```

But am getting similar error messages:

```auto
JSON parse error, original data now in message field {:error=>#<LogStash::Json::ParserError: Unexpected character...
Received an event that has a different character encoding than you configured. {:text=>"\\xB6\\xA6}e#\\x

```

---

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [November 22, 2020, 8:34pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/10 "2020-11-22T20:34:21Z")

</div>

_bump_

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 23, 2020, 2:31pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/11 "2020-11-23T14:31:01Z")

</div>

Since this is a new issue might want to create a new thread about message parsing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2020, 2:31pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356/12 "2020-12-21T14:31:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
