# Logstash TCP connection leak

**URL:** <https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119>\
**Category:** Logstash\
**Created:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119 "2017-07-06T14:11:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119/1 "2017-07-06T14:11:41Z")

</div>

Logstash: 5.3.0

Logstash is keeping TCP connections open even for servers that are shutdown. It also seems to be preventing the OS from closing the connections via TCP keep alive- I just have the default settings:

```
  # cat /proc/sys/net/ipv4/tcp_keepalive_time
  7200
  # cat /proc/sys/net/ipv4/tcp_keepalive_intvl
  75
  # cat /proc/sys/net/ipv4/tcp_keepalive_probes
  9

```

```auto

I also have duplicate tcp connections for the same hosts.

So I added `data_timeout => 500` to my input filter and restarted logstash but it looks like connections are still growing and remaining in the established state.

I think logstash is keeping the tcp connection active even if the server on the other end is shutdown? If the OS sees the connection as ESTABLISHED does that not count as an idle connection? Because in that case data_timeout would have no impact right?

I was hoping there would be a logstash setting for this, but it seems like logstash is even preventing the OS from cleaning up connections. I don't want to have to run a cronjob to restart logstash.

Edit: so it seems logstash doesn't implement TCP keep alives so my keep alive settings won't matter anyway and it will always leak TCP connections.

Should I open a bug report on github for this?
```

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [July 14, 2017, 1:51pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119/2 "2017-07-14T13:51:31Z")

</div>

I assume this is in reference to the TCP input ?

If so,  
We just released a re-implementation of the TCP-input that uses a NIO under the covers, for non-ssl connection. If this is non-ssl connection, I would encourage you to try the new implementation, and if it still has issues, then please raise an issue.

To upgrade the TCP input:

1. Edit the Gemfile under your Logstash home directory
2. Update to lock to the v4 of plugin ( add , "~\> 4" to the existing line): `gem "logstash-input-tcp", "~> 4"`
3. run the command `bin/logstash-plugin update logstash-input-tcp`

This will be the version shipped with 5.6.0+

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [July 14, 2017, 5:10pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119/3 "2017-07-14T17:10:19Z")

</div>

Yup this is TCP input and its non-ssl.

I'm planning an ELK upgrade soon so I'll wait for 5.6.0- although it looks like your next release is going to be 6.0.0?

For now scheduling reboots to clear out connections works fine for me.

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [July 14, 2017, 5:55pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119/4 "2017-07-14T17:55:01Z")

</div>

There will be a 5.6.0 release about the same time as the 6.0.0-beta1 release [1]. The new tcp-input with nio will be in both.

[1] standard disclaimer - assuming plans don't change.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2017, 5:55pm UTC](https://discuss.elastic.co/t/logstash-tcp-connection-leak/92119/5 "2017-08-11T17:55:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
