# Logstash tcp input plugin connection reset error

**URL:** <https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441>\
**Category:** Logstash\
**Created:** [January 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441 "2024-01-05T09:10:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fmelk65](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fmelk65/32/123902_2.png) [@fmelk65](https://discuss.elastic.co/u/fmelk65)\
**Post date:** [January 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441/1 "2024-01-05T09:10:16Z")

</div>

Hello,  
I have 25 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash).  
I'm getting a lot of connection reset errors.  
It's been discussed here before, can @true64gurus specifically help?

```auto
[ERROR][logstash.inputs.tcp] xxxxxxxxxxxxxxx/x.x.x.x:16591: closing due:
java.net.SocketException: Connection reset
        at sun.nio.ch.SocketChannelImpl.throwConnectionReset(SocketChannelImpl.java:394) ~[?:?]
        at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:426) ~[?:?]
        at io.netty.buffer.PooledByteBuf.setBytes(PooledByteBuf.java:253) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.buffer.AbstractByteBuf.writeBytes(AbstractByteBuf.java:1132) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.socket.nio.NioSocketChannel.doReadBytes(NioSocketChannel.java:350) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:151) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:719) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:655) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:581) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:493) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.util.concurrent.SingleThreadEventExecutor$4.run(SingleThreadEventExecutor.java:989) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.util.internal.ThreadExecutorMap$2.run(ThreadExecutorMap.java:74) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30) [netty-all-4.1.65.Final.jar:4.1.65.Final]
        at java.lang.Thread.run(Thread.java:833) [?:?]

```

> [@Optimize logstash tcp input plugin](https://discuss.elastic.co/t/optimize-logstash-tcp-input-plugin/337847):
>
> Hello, I have 10 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash port 7000) . Logstash gets to a point where logs are being missed and source pods doing retries to get logs through . ( errors I see on this case are listed below). Looking for recommendation to optimize logstash tcp input . Errors on logstash [ERROR][logstash.inputs.tcp] xxxxxxxxxxxxxxx/x.x.x.x:16591: closing due: java.net.SocketException: Connection reset at sun.nio.ch.SocketCh…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441/2 "2024-02-02T09:10:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
