# Logstash not receiving messages

**URL:** <https://discuss.elastic.co/t/logstash-not-receiving-messages/93370>\
**Category:** Logstash\
**Created:** [July 17, 2017, 9:54am UTC](https://discuss.elastic.co/t/logstash-not-receiving-messages/93370 "2017-07-17T09:54:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aleksandar\_Aleksandr](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@Aleksandar\_Aleksandr](https://discuss.elastic.co/u/Aleksandar_Aleksandr)\
**Post date:** [July 17, 2017, 9:54am UTC](https://discuss.elastic.co/t/logstash-not-receiving-messages/93370/1 "2017-07-17T09:54:39Z")

</div>

Hello,

I am trying to get the ELK up and running on docker. I have succesfully integrated the three services and they do in fact communicate with each other. My problem arises when I am trying to send messages to logstash over udp/tcp connection. I tried different input plugins including the udp, tcp and syslog plugins. In none of the cases or the tried configuration messages were actually being received. I checked and logstash is in fact listening to the requested ports. The application is also sending the packets to the right ip:port. However, no input is to be seen.

Does anybody have an idea what in the communication might possibly be going wrong?

Example.conf that I used:  
input {  
syslog {  
port =\> "14544"  
}  
}

output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}  
stdout {  
codec =\> rubydebug  
}  
}

docker-compose  
logstash:  
image: logstash:2.4.0  
ports:  
- "5044:5044"  
- "14544:14544"  
- "14544:14544/udp"  
links:  
- elasticsearch  
depends\_on:  
- elasticsearch

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 18, 2017, 2:19pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-messages/93370/2 "2017-07-18T14:19:45Z")

</div>

It's not clear to me if your "ports" map actually publishes the ports on the host; the documentation ([https://docs.docker.com/compose/compose-file/#ports](https://docs.docker.com/compose/compose-file/#ports)) isn't quite clear. Try using the long syntax described in the docs to really make sure the ports are published.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2017, 2:20pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-messages/93370/3 "2017-08-15T14:20:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
