# Logstash not receiving remote tcp data

**URL:** <https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783>\
**Category:** Logstash\
**Created:** [May 26, 2019, 4:50am UTC](https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783 "2019-05-26T04:50:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Barry\_C](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/barry_c/32/46856_2.png) [@Barry\_C](https://discuss.elastic.co/u/Barry_C)\
**Post date:** [May 26, 2019, 4:50am UTC](https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783/1 "2019-05-26T04:50:19Z")

</div>

I am new to ELK and I spent days to troubleshoot and still not able to find out what's wrong with my configuration.

The following is my problem and what I have done to troubleshoot

- I setup a basic ELK 7.1 on a single host

- logstash can accept various kinds of log from localhost, but it fails to accept logs from remote machines

- I troubleshoot by changing a very basic logstash.conf.

- the following was my first logstash.conf that accepted stdin and it worked  
input { stdin { } }  
output { elasticsearch { hosts =\> ["localhost:9200"] } }

- I modified the logstash.conf to the following  
input { tcp { port =\> 5017 } }  
output { elasticsearch { hosts =\> ["localhost:9200"] } }

- I changed my router to write syslog to my logstash IP and port 5017, nothing is captured in logstash

- I tried using netcat from another linux using the following command and the command neither timeout nor finish  
echo "message" | nc -q0 192.168.1.200 5017

- I tested the same netcat command from localhost and it worked.

- I could find logstash listen the right port from log  
[2019-05-26T03:54:12,430][INFO][logstash.inputs.tcp] Starting tcp input listener {:address=\>"0.0.0.0:5017", :ssl\_enable=\>"false"}  
[2019-05-26T03:54:12,618][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}

- I ran "netstat -a | grep 5017" and I confirmed the host was listening  
tcp6 0 0 [::]:5017 [::]:\* LISTEN

- I ran "tcpdump tcp port 5017" and it received some data from the remote netcat command  
listening on ens32, link-type EN10MB (Ethernet), capture size 262144 bytes  
04:40:07.647365 IP 192.168.1.73.41174 \> 192.168.1.200.5017: Flags [S], seq 3625096655, win 29200, options [mss 1460,sackOK,TS val 1674425657 ecr 0,nop,wscale 6], length 0

What have I missed ? Any help is appreciated.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [May 26, 2019, 7:59am UTC](https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783/2 "2019-05-26T07:59:34Z")

</div>

Check the syslog input plugin. This is 7.1 version info, but it exists on all versions: [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html)

---

<div class="post-metadata">

**Author:** ![Barry\_C](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/barry_c/32/46856_2.png) [@Barry\_C](https://discuss.elastic.co/u/Barry_C)\
**Post date:** [May 26, 2019, 9:32am UTC](https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783/3 "2019-05-26T09:32:52Z")

</div>

Thanks staodd. I tested syslog plugin but still didn't work. I just tried disabling firewall and it work......

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2019, 9:33am UTC](https://discuss.elastic.co/t/logstash-not-receiving-remote-tcp-data/182783/4 "2019-06-23T09:33:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
