# Logstash not listening to 5044

**URL:** <https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432>\
**Category:** Logstash\
**Created:** [June 30, 2021, 8:56am UTC](https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432 "2021-06-30T08:56:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![azid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azid/32/90992_2.png) [@azid](https://discuss.elastic.co/u/azid)\
**Post date:** [June 30, 2021, 8:56am UTC](https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432/1 "2021-06-30T08:56:52Z")

</div>

Hi Im new to ELK, when I try to transfert data filebeat -\>logstash I got my logstash not listening to port 5044 any help would be appreciated

**Pipeline :**

```auto
input {
    beats {
        port => 5044
    }
}
filter {
    grok {
        match => { "message" => "%{COMBINEDAPACHELOG}"}
    }
}
output {
    stdout { codec => rubydebug }
    elasticsearch {
        hosts => ["127.0.0.1:9200"]
        index => "testapa-%{+YYYY.MM.dd}"
}

```

**filebeat.yml**

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/*.log
    - /Users/abelkadhi/Downloads/logstash-tutorial.log

# filestream is an experimental input. It is going to replace log input in the future.
- type: filestream

  # Change to true to enable this input configuration.
  enabled: false

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /var/log/*.log

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1
  #index.codec: best_compression
  #_source.enabled: false

setup.kibana:

  # Kibana Host
  # Scheme and port can be left out and will be set to the default (http and 5601)
  # In case you specify and additional path, the scheme is required: http://localhost:5601/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:5601
  host: "localhost:5601"

output.logstash:
  # The Logstash hosts
  hosts: ["localhost:5044"]

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

**logstash.yml**

```auto
# ------------ Data path ------------------
#
# Which directory should be used by logstash and its plugins
# for any persistent needs. Defaults to LOGSTASH_HOME/data
#
path.data: /var/lib/logstash

pipeline.ordered: auto

# ------------ HTTP API Settings -------------
# Define settings related to the HTTP API here.
#
# The HTTP API is enabled by default. It can be disabled, but features that rely
# on it will not work as intended.
# http.enabled: true
#
# By default, the HTTP API is bound to only the host's local loopback interface,
# ensuring that it is not accessible to the rest of the network. Because the API
# includes neither authentication nor authorization and has not been hardened or
# tested for use as a publicly-reachable API, binding to publicly accessible IPs
# should be avoided where possible.
#
http.host: 0.0.0.0
#
# The HTTP API web server will listen on an available port from the given range.
# Values can be specified as a single port (e.g., `9600`), or an inclusive range
# of ports (e.g., `9600-9700`).
#
http.port: 5044

path.logs: /var/log/logstash

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2021, 4:21pm UTC](https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432/2 "2021-06-30T16:21:47Z")

</div>

> [@azid](#):
>
> ```auto
> beats {
> port => 5044
> }
> 
> ```

The default value of the host option on a beats input is "0.0.0.0", which of the available IP addresses that includes depends on the TCP stack. If you have configured filebeat to send to "localhost:5044" then I suggest you add

```
host => "localhost"

```

to your beats input.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 1, 2021, 4:21am UTC](https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432/3 "2021-07-01T04:21:54Z")

</div>

Try to remove the following config from your `logstash.yml` and start logstash again.

> [@azid](#):
>
> `http.port: 5044`

This will set the API endpoint to listen on port `5044`, the same port of your beats input.

The `http.port` config in `logstash.yml` has nothing to do with your pipeline, it sets the port for the logstash api which is used mostly in monitoring the pipelines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2021, 4:22am UTC](https://discuss.elastic.co/t/logstash-not-listening-to-5044/277432/4 "2021-07-29T04:22:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
