# Logstash tcp input doesn't work

**URL:** <https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134>\
**Category:** Logstash\
**Created:** [July 30, 2018, 9:06am UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134 "2018-07-30T09:06:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hbceylan](https://avatars.discourse-cdn.com/v4/letter/h/50afbb/32.png) [@hbceylan](https://discuss.elastic.co/u/hbceylan)\
**Post date:** [July 30, 2018, 9:06am UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134/1 "2018-07-30T09:06:08Z")

</div>

Hi,

I'm using logstash docker like below, but always say "Pipeline has terminated". What's the problem?

docker run --name logstash -d   
-p 4560:4560   
-p 4561:4561   
--link elasticsearch:elasticsearch   
-v /opt/logstash:/usr/share/logstash/pipeline   
-v /opt/logstash/pipelines.yml:/usr/share/logstash/config/pipelines.yml   
[docker.elastic.co/logstash/logstash:6.3.2](http://docker.elastic.co/logstash/logstash:6.3.2)

/opt/logstash/app.conf

input {  
tcp {  
port =\> 4560  
codec =\> json  
type =\> "simple"  
}  
udp {  
port =\> 4560  
codec =\> json  
type =\> "simple"  
}  
log4j {  
port =\> 4561  
codec =\> json  
type =\> "simple"  
}  
}

output {  
if [type] == "simple" {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}  
}  
}

logstash-log

[2018-07-30T09:04:14,234][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://elasticsearch:9200/](http://elasticsearch:9200/)]}}  
[2018-07-30T09:04:14,246][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://elasticsearch:9200/](http://elasticsearch:9200/), :path=\>"/"}  
[2018-07-30T09:04:14,471][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://elasticsearch:9200/](http://elasticsearch:9200/)"}  
[2018-07-30T09:04:14,555][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-07-30T09:04:14,560][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-07-30T09:04:14,595][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://elasticsearch:9200](http://elasticsearch:9200)"]}  
[2018-07-30T09:04:14,761][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://elasticsearch:9200/](http://elasticsearch:9200/)]}}  
[2018-07-30T09:04:14,762][INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://elasticsearch:9200/](http://elasticsearch:9200/), :path=\>"/"}  
[2018-07-30T09:04:14,769][WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=\>"[http://elasticsearch:9200/](http://elasticsearch:9200/)"}  
[2018-07-30T09:04:14,776][INFO][logstash.licensechecker.licensereader] ES Output version determined {:es\_version=\>6}  
[2018-07-30T09:04:14,780][WARN][logstash.licensechecker.licensereader] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-07-30T09:04:14,941][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x7ae3f6b1 run\>"}  
[2018-07-30T09:04:15,077][INFO][logstash.inputs.metrics] Monitoring License OK  
[2018-07-30T09:04:15,404][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-07-30T09:04:21,609][INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x7ae3f6b1 run\>"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 1:13pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134/2 "2018-07-30T13:13:18Z")

</div>

If the monitoring pipeline is the only pipeline running then logstash will shut itself down. My guess is that it has found a pipelines.yml that does not define any pipelines. I would run it with log.level: debug and see what configuration it is using.

---

<div class="post-metadata">

**Author:** ![hbceylan](https://avatars.discourse-cdn.com/v4/letter/h/50afbb/32.png) [@hbceylan](https://discuss.elastic.co/u/hbceylan)\
**Post date:** [July 31, 2018, 11:18am UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134/3 "2018-07-31T11:18:51Z")

</div>

It's worked like below.

/opt/logstash/app.conf

input {  
tcp {  
port =\> 4560  
}  
}

output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 31, 2018, 11:53am UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134/4 "2018-07-31T11:53:00Z")

</div>

Set log.level: debug and check whether it is using that configuration. It probably is not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2018, 11:53am UTC](https://discuss.elastic.co/t/logstash-tcp-input-doesnt-work/142134/5 "2018-08-28T11:53:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
