# Logstash plugin install : Error socket closed

**URL:** <https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243>\
**Category:** Logstash\
**Created:** [March 22, 2023, 12:14pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243 "2023-03-22T12:14:45Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 22, 2023, 12:14pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/1 "2023-03-22T12:14:45Z")

</div>

Hi ,

I want to install a Stormshield plugin for Logstash

I tried  
bin/logstash-plugin install --no-verify logstash-filter-SNS

I have "ERROR : Something went wrong when installalling bin/logstash-filter-SNS , message socket closed

I tried to install plugin with offline method with gem build  
gem build XXX.gemspec =\> work  
But when I launch : bin/logstash-plugin install --no-verify XXX.gem  
Same error : Socket closed

I tried to install by following the official doc and I have an URI error

Can you help me 🙂

Thanks

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 24, 2023, 8:34am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/2 "2023-03-24T08:34:41Z")

</div>

No idea ?

I search a long and there are anothers with the same problem...

Nobody solved this ?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 25, 2023, 8:13pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/3 "2023-03-25T20:13:50Z")

</div>

If your environment is using a proxy, must be set.  
Set log.level to `debug` or `trace` should be some traces.

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 26, 2023, 3:14pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/4 "2023-03-26T15:14:33Z")

</div>

I don't have any proxy . How I can set log level ?  
Thx

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 26, 2023, 4:56pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/5 "2023-03-26T16:56:16Z")

</div>

`log.level: debug` in logstash.yml, and restart LS.

Paste here, formated with \</\> button.

And ...Welcome to the community. 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 26, 2023, 11:29pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/6 "2023-03-26T23:29:38Z")

</div>

> [@Rios](#):
>
> `log.level: debug` in logstash.yml, and restart LS

I don't think that will work. logstash-plugin is interpreted Ruby code, and does not use log4j. But since it is interpreted Ruby you can just add puts calls wherever you want.

If you run `DEBUG=1 bin/logstash-plugin install --no-verify logstash-filter-SNS` you may get a few extra messages but I doubt it will help.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 27, 2023, 6:49am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/7 "2023-03-27T06:49:11Z")

</div>

Good point Badger. 👍

I have googled about SNS plugin. This should be a syslog message, and there is [LS configuration](https://www.lsconf.io/config/stormshield_network_security_(sns):114) and [github](https://github.com/stormshield/stormshield-ELK).

Might be not supported.

> Supported version
> 
> - Elasticsearch: _6.8.2_
> - Kibana: _6.8.2_
> - Logstash: _6.8.2_

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 27, 2023, 8:13am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/8 "2023-03-27T08:13:07Z")

</div>

How I can add "puts calls" ?

I follow this Github for my plugins and when I read lsconfiguration ( Thx for the website) it's write that the logstash-plugins are required ....

Do I have to do the filter manually ? 🤔 🤔 🤔

Have you got an another idea ?

Thx to Badger and Rios

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 27, 2023, 12:24pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/9 "2023-03-27T12:24:44Z")

</div>

Not sure is the plugin supported on 8.x platform. The release is for Logstash: 6.8.2.

I would:

1. Try to install as Badger suggested, and figure out from LS logs or journalctl is there any possible trace, do not spend more then 1h hour on this since Badge is not optimistic.
2. There is email contact for Labo SVC at the bottom of github link, you might ask for advice
3. Make a test conf just with syslog input, without filtering to see will you receive messages.  
If is not working, which is possible, but maaaaaaybe LS 8.x has something improved in syslog plugin.

I personally didn't have experience with this quite specific plugin, not yet. However I can provide an advice. 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 27, 2023, 5:37pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/10 "2023-03-27T17:37:25Z")

</div>

> [@Julien069](#):
>
> How I can add "puts calls" ?

The code for the pluginmanager is in ${LOGSTASH\_HOME}/lib/pluginmanager. It is .rb files that you can edit. It already has [some puts calls](https://github.com/elastic/logstash/blob/58abffce330533c8c6852e6a7f7fe3ae5d9d34fa/lib/pluginmanager/install.rb#L100). You can add more to try to follow the flow and see where the error is occuring. If you are not used to programming in ruby it will not be easy.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2023, 5:52pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/11 "2023-03-27T17:52:44Z")

</div>

Have you tried to install any other plugin?

The error you are getting seems to be network related, do you have any firewall in your network that could be blocking/limiting the connection?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 27, 2023, 7:26pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/12 "2023-03-27T19:26:02Z")

</div>

Leandro, I have already asked is there a proxy. No, there is no proxy. It's good idea to try with some other plugin just to test since this plugin is supported for 6.8.  
If there is no internet connection, then will need to install in offline mode if is supported for this plugin.

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 27, 2023, 8:08pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/13 "2023-03-27T20:08:44Z")

</div>

I have a working Internet connection and I have the same error with offline install.

Can you give me an online plugin working with 8.6 ?

When I tested with list or update option , the result seems good..

I will test with a Vmware station and standard Internet connection too..

Lot off people have the same error and no solution

Thx a lot

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2023, 9:57pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/14 "2023-03-27T21:57:08Z")

</div>

It is not related to the version, the plugin installs fine in `8.6.2` for me.

```auto
$ bin/logstash --version; bin/logstash-plugin install --no-verify logstash-filter-SNS
Using bundled JDK: /opt/logstash/jdk
logstash 8.6.2
Using bundled JDK: /opt/logstash/jdk
Installing logstash-filter-SNS
Installation successful

```

> [@Julien069](#):
>
> Lot off people have the same error and no solution

Can you share any post that you found in the forum about this issue?

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 28, 2023, 8:31am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/15 "2023-03-28T08:31:34Z")

</div>

Thanks for your feedback  
I will test with Vmware station ...

Some posts :

> <https://stackoverflow.com/questions/70914334/logstash-cannot-install-filters>

> [@Install filter-plugin failed](https://discuss.elastic.co/t/install-filter-plugin-failed/295237):
>
> Hello, Today I upgraded logstash to the latest version and needs to install logstash-filter-elapsed plugin. I'm receiving below error: ./logstash-plugin install logstash-filter-elapsed Using bundled JDK: /usr/share/logstash/jdk warning: no jvm.options file found ERROR: Something went wrong when installing logstash-filter-elapsed, message: Socket closed probably some ports I need to have open. Can someone tell me which ports I need to have opened to have ability to install plugins ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 28, 2023, 12:47pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/16 "2023-03-28T12:47:57Z")

</div>

> [@Julien069](#):
>
> Thanks for your feedback  
> I will test with Vmware station

The issue of the error in your linked post is a network issue, the OP clearly specifies that he is on a _corporate environment_ and probably has something interfering in its connnection.

I've made a recommendation in the same post to create a offline package on another machine.

Where are you trying to install it, are you in your home pc or are you in your work PC or a server in your company?

That's why I asked if you may have a firewall in your network that could be impacting your connection.

Keep in mind that you do not need to be using a proxy and can have a working internet connection and at the same time have a firewall in your network that could cause issues like this.

There is not much to troubleshoot, the _socket closed_ error heavily suggests a network issue.

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 29, 2023, 8:02am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/17 "2023-03-29T08:02:17Z")

</div>

My environment is a server behind a firewall with no proxy.

I don't have any logs on my firewall showing a blocked packet. However, I tested the installation with the offline method and I have the same problem.

That's why, I started to install Logstash Server on a Vmware station environment to test it, install the plugin with another connection and import it on my Vcenter.

I couldn't find any other solution...

The real question is: Why the same error with offline installation ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 29, 2023, 1:50pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/18 "2023-03-29T13:50:49Z")

</div>

> [@Julien069](#):
>
> However, I tested the installation with the offline method and I have the same problem.

How do you test it? For the offline method to work you need to have the desired plugin already installed, if you tried to create a offline package in the same machine where you can't install the package it won't work because you do not have the package in the machine.

You need to do this in a complete different machine where you are able to install the plugin, probably an machine outside your environment.

> [@Julien069](#):
>
> My environment is a server behind a firewall with no proxy.
> 
> I don't have any logs on my firewall showing a blocked packet.

So you have a firewall in the end and even withtout a log showing a block this could be your issue.

For example, if your firewall is inspecting the ssl packages it may be opening the ssl connections and replacing the certificate, this could create an issue similar to yours.

You need to check with your network team.

---

<div class="post-metadata">

**Author:** ![Julien069](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Post date:** [March 29, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/19 "2023-03-29T14:36:40Z")

</div>

For the offline method, I download the plugin, create a .gem with "gem build" and install it with logstash-plugin (offline method)

I checked the firewall and I unblocked the SSL inspection for the server...

However, it works with Vmstation, so I think Firewall PNAT is not compatible with the installation

I really appreciate your help

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 29, 2023, 2:56pm UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243/20 "2023-03-29T14:56:11Z")

</div>

> [@Julien069](#):
>
> For the offline method, I download the plugin, create a .gem with "gem build" and install it with logstash-plugin (offline method)

This is not how you create an offline package, you need to follow the [documentation](https://www.elastic.co/guide/en/logstash/current/offline-plugins.html#building-offline-packs).

Basically you need to have the plugin installed on another logstash and use this logstash to generate the offline package.

> [@Julien069](#):
>
> I checked the firewall and I unblocked the SSL inspection for the server...

Did you tried to install again after disabling SSL inspection?

[Next page](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243.md?page=2)
