# Logstash Not Receiving TCP Data

**URL:** <https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402>\
**Category:** Logstash\
**Created:** [April 17, 2018, 4:52pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402 "2018-04-17T16:52:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![clannadqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clannadqs/32/30088_2.png) [@clannadqs](https://discuss.elastic.co/u/clannadqs)\
**Post date:** [April 17, 2018, 4:52pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/1 "2018-04-17T16:52:24Z")

</div>

I am shipping monitored data as JSON from Python. I have tested whether the data is actually being sent outside of Logstash and it is successfully sending and being received. With Logstash the input is showing no signs of being received with the TCP input plugin.

Here is my configuration:

```
input{
   tcp{
     port => 55556
     codec => json
   }
}

output{
   elasticsearch {
   hosts => ['localhost:9200']
   sniffing => true
   index => "test2"
  document_type => "health"
  }
}

```

Verbose debugging doesn't show anything other than the basic output for logstash spinning up and connecting to the elasticsearch output specified. I'm under the impression that it might have something to do with the message being sent being ignored due to formatting.

Example message:

```
{"@fields": {"test": "test"}, "@message": {"doc_type": "sys_status", "PSUs": 2, "index": "shipper", "hostname": "client1", "CPUs": 2, "System": 4, "point_of_contact": "Tom Perry", "DIR": 4}, "@tags": ["test"]}
```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 17, 2018, 5:17pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/2 "2018-04-17T17:17:30Z")

</div>

The input is definitely not valid JSON (which uses _double_ quotes around strings, and does not support an encoding prefix, as strings are _always_ UTF-8-encoded), but when the JSON codec fails to parse an event, the event is created anyway with the literal text of the message as its `message` attribute and `_jsonparsefailure` added to the event's `tags`.

Do you have evidence that TCP traffic is arriving?

```auto
tcpdump tcp port 55556

```

---

<div class="post-metadata">

**Author:** ![clannadqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clannadqs/32/30088_2.png) [@clannadqs](https://discuss.elastic.co/u/clannadqs)\
**Post date:** [April 17, 2018, 5:22pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/3 "2018-04-17T17:22:51Z")

</div>

Sorry about that. Just realized that the example message was the message before a json.dumps() calls on it. I corrected it to what is actually sent.

Also, tcpdump does not show anything. I might be using it incorrectly, though.

---

<div class="post-metadata">

**Author:** ![clannadqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clannadqs/32/30088_2.png) [@clannadqs](https://discuss.elastic.co/u/clannadqs)\
**Post date:** [April 17, 2018, 7:17pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/4 "2018-04-17T19:17:57Z")

</div>

Got tcpdump to show the proper packets with:

```
tcpdump -i any -n tcp dst port 55556

15:12:56.008867 IP 127.0.0.1.32886 > 127.0.0.1.55556: Flags [P.], seq 1020442282:1020442491, ack 201299404, win 342, options [nop,nop,TS val 21211295 ecr 21206290], length 209
15:13:01.014242 IP 127.0.0.1.32886 > 127.0.0.1.55556: Flags [P.], seq 209:672, ack 1, win 342, options [nop,nop,TS val 21216301 ecr 21211295], length 463
15:13:06.019543 IP 127.0.0.1.32886 > 127.0.0.1.55556: Flags [P.], seq 672:881, ack 1, win 342, options [nop,nop,TS val 21221306 ecr 21216301], length 209

```

Printing hex/ASCII shows they are the messages I am expecting to send.

---

<div class="post-metadata">

**Author:** ![clannadqs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clannadqs/32/30088_2.png) [@clannadqs](https://discuss.elastic.co/u/clannadqs)\
**Post date:** [April 17, 2018, 9:12pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/5 "2018-04-17T21:12:23Z")

</div>

Solved the issue. Json codec was automatically being converted to json\_lines. After adding a new line after each message sent the index was created as well as messages being indexed in it.

---

<div class="post-metadata">

**Author:** ![RRSR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rrsr/32/27766_2.png) [@RRSR](https://discuss.elastic.co/u/RRSR)\
**Post date:** [May 3, 2018, 4:39am UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/6 "2018-05-03T04:39:44Z")

</div>

Hi @clannadqs ,

Can you help me with this : [tcp-data-sending-from-pyton-to-logstash-fails](https://discuss.elastic.co/t/tcp-data-sending-from-pyton-to-logstash-fails/130358)

Thanks

---

<div class="post-metadata">

**Author:** ![RRSR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rrsr/32/27766_2.png) [@RRSR](https://discuss.elastic.co/u/RRSR)\
**Post date:** [May 3, 2018, 12:36pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/7 "2018-05-03T12:36:09Z")

</div>

@clannadqs The same thing worked for me too 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 12:36pm UTC](https://discuss.elastic.co/t/logstash-not-receiving-tcp-data/128402/8 "2018-05-31T12:36:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
