# Logstash output traffic significantly higher than input (minimal transformations) + TCP RST

**URL:** <https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868>\
**Category:** Logstash\
**Created:** [June 4, 2025, 1:26pm UTC](https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868 "2025-06-04T13:26:37Z")\
**Posts on this page:** 1\
**Showing post:** 22

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 9, 2025, 12:04pm UTC](https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868/22 "2025-06-09T12:04:57Z")

</div>

**I’ve opened a question specifically about the RST behavior here:**

> [@Why does Logstash close idle TCP connections with RST instead of FIN?](https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000):
>
> Hi Elastic team, I’m trying to better understand how client\_inactivity\_timeout works in Logstash. I’ve noticed that when this timeout is reached, Logstash closes the TCP connection by sending a RST, even though the connection is still technically alive — TCP keep-alives are being sent by Winlogbeat every ~15 seconds and acknowledged by Logstash (confirmed via Wireshark). As I understand it: client\_inactivity\_timeout is based only on application-level data (e.g., log events), TCP-level activ…

**Hopefully someone from the Elastic team can provide more insight or consider addressing it if it makes sense.**

---

_[View the full topic](https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868)._
