# Logstash stops send information to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-stops-send-information-to-elasticsearch/49677>\
**Category:** Logstash\
**Created:** [May 10, 2016, 3:18pm UTC](https://discuss.elastic.co/t/logstash-stops-send-information-to-elasticsearch/49677 "2016-05-10T15:18:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![daguero](https://avatars.discourse-cdn.com/v4/letter/d/b5e925/32.png) [@daguero](https://discuss.elastic.co/u/daguero)\
**Post date:** [May 10, 2016, 3:18pm UTC](https://discuss.elastic.co/t/logstash-stops-send-information-to-elasticsearch/49677/1 "2016-05-10T15:18:12Z")

</div>

I am using elasticsearch 2.2.0, logstash 2.2.2, Kibana 4.4.1, topbeat 1.1.1 and filebeat 1.1.1 containers deployed Docker in a cluster of Mesos. When I deploy services everything seems to work fine, but after a few hours logstash stops send information to elasticsearch and this is the log file:

```
"Beats input: the pipeline is blocked, temporary refusing new connection.
message=>"Beats Input: Remote connection closed", :peer=>"172.29.6.20:35612", :exception=>#<Lumberjack::Beats::Connection::ConnectionClosed: Lumberjack::Beats::Connection::ConnectionClosed wrapping: lumberjack::Beats::Parser::UnsupportedProtocol, unsupported protocol 0>, :level=>:warn}

```

I saw also that this log file grows much as logstash works well. Some idea of the problem

**This is my logstash.conf**

input {  
beats {  
codec =\> json {  
charset =\> "UTF-8"  
}  
port =\> {{logstash\_container\_port}}  
}  
}

filter {  
grok {  
match =\> { "source" =\> "/var/log/([^/]+)/logstasher\_[^_]+_(?\<build\_id\>[^_]+)_[^.]+.log" }  
}

grok {  
match =\> { "source" =\> "/var/log/(?\<project\_name\>[^/]+)/[^.]+.log" }  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}

elasticsearch {  
hosts =\> ["{{es\_host}}:{{es\_service\_port}}"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"

```
}

```

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2016, 11:30pm UTC](https://discuss.elastic.co/t/logstash-stops-send-information-to-elasticsearch/49677/2 "2016-05-11T23:30:41Z")

</div>

Looks like a networking issue.  
But I don't know mesos so I can't suggest anywhere to start.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/logstash-stops-send-information-to-elasticsearch/49677/3 "2017-07-06T04:58:02Z")

</div>


