# Logstash to elastic search TCP connection error

**URL:** <https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624>\
**Category:** Logstash\
**Created:** [April 29, 2022, 5:18pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624 "2022-04-29T17:18:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![newelastic](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Post date:** [April 29, 2022, 5:18pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/1 "2022-04-29T17:18:18Z")

</div>

Hi,

I'm trying to connect to Elasticsearch using logstash and running into an TCP connection error.

Below is my input plugin for logstash

```auto
input {
  elasticsearch {
	hosts => ["https://esipAddress:9200"]
	index => "test_2201"
	user => "esadminuser"
	password => "pwd"
	ssl => true
	ca_file => "/etc/logstash/ssl/escert.pem"	
}
}

```

Below is TCP connection error.

```auto
E:\ELK\logstash-6.4.2\bin>logstash -f e:\ELK\logstash.conf
Sending Logstash logs to E:/ELK/logstash-6.4.2/logs which is now configured via log4j2.properties
[2022-04-29T10:13:08,903][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2022-04-29T10:13:09,280][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"6.4.2"}
[2022-04-29T10:13:10,610][INFO][logstash.pipeline] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>12, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50}
[2022-04-29T10:13:10,836][INFO][com.microsoft.azure.kusto.ingest.QueuedIngestClient] Creating a new IngestClient
[2022-04-29T10:13:10,852][INFO][com.microsoft.azure.kusto.ingest.ResourceManager] Refreshing Ingestion Auth Token
[2022-04-29T10:13:10,883][INFO][logstash.outputs.kusto] Going to recover old files in path
[2022-04-29T10:13:10,908][INFO][logstash.outputs.kusto] Found 0 old file(s), sending them now...
[2022-04-29T10:13:11,309][INFO][logstash.pipeline] Pipeline started successfully {:pipeline_id=>"main", :thread=>"#<Thread:0x72c22c15 run>"}
[2022-04-29T10:13:11,353][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2022-04-29T10:13:11,620][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2022-04-29T10:13:11,887][INFO][com.microsoft.azure.kusto.ingest.ResourceManager] Refreshing Ingestion Resources
[2022-04-29T10:13:14,106][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.
  Pipeline_id:main
  Plugin: <LogStash::Inputs::Elasticsearch password=><password>, ca_file=>"e:\\certs\\escert.pem", hosts=>["https://esIpAddress:9200"], index=>"test_2201", id=>"689c8935bd4a8544125f8cfee5e34acbd908ddcea32cab3d3b055403f1d48cd1", user=>"esadminuser", ssl=>true, enable_metric=>true, codec=><LogStash::Codecs::JSON id=>"json_8282870b-dc73-4b75-a2e6-cb646910eaac", enable_metric=>true, charset=>"UTF-8">, query=>"{ \"sort\": [\"_doc\"] }", size=>1000, scroll=>"1m", docinfo=>false, docinfo_target=>"@metadata", docinfo_fields=>["_index", "_type", "_id"]>
  Error: Failed to open TCP connection to https:0 (initialize: name or service not known)
  Exception: Faraday::ConnectionFailed
  Stack: org/jruby/ext/socket/RubyTCPSocket.java:137:in `initialize'
org/jruby/RubyIO.java:1154:in `open'
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/http.rb:885:in `block in connect'
org/jruby/ext/timeout/Timeout.java:149:in `timeout'
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/http.rb:883:in `connect'
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/http.rb:868:in `do_start'
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/http.rb:857:in `start'
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/http.rb:1409:in `request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/adapter/net_http.rb:82:in `perform_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/adapter/net_http.rb:40:in `block in call'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/adapter/net_http.rb:87:in `with_net_http_connection'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/adapter/net_http.rb:32:in `call'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/rack_builder.rb:139:in `build_response'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/faraday-0.9.2/lib/faraday/connection.rb:377:in `run_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/http/faraday.rb:23:in `block in perform_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/base.rb:262:in `perform_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/http/faraday.rb:20:in `perform_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/client.rb:131:in `perform_request'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/elasticsearch-api-5.0.5/lib/elasticsearch/api/actions/search.rb:183:in `search'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/logstash-input-elasticsearch-4.2.1/lib/logstash/inputs/elasticsearch.rb:200:in `do_run'
E:/ELK/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/logstash-input-elasticsearch-4.2.1/lib/logstash/inputs/elasticsearch.rb:188:in `run'
E:/ELK/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:409:in `inputworker'
E:/ELK/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:403:in `block in start_input'
[2022-04-29T10:13:15,173][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.

```

Can someone throw if anything wrong with my plugin or missing anything here? TIA

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 29, 2022, 5:25pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/2 "2022-04-29T17:25:59Z")

</div>

I would start with the [host parameter](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html#plugins-inputs-elasticsearch-hosts). Think this is the one where you don't put `https` in the host and use `ssl => true` instead. Try this.

```auto
input {
  elasticsearch {
    hosts => ["esipAddress:9200"]
    ssl => "true"
	index => "test_2201"
	user => "esadminuser"
	password => "pwd"
	ssl => true
	ca_file => "e:\certs\escert.pem"	
  }
}

```

---

<div class="post-metadata">

**Author:** ![newelastic](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Post date:** [April 29, 2022, 6:14pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/3 "2022-04-29T18:14:34Z")

</div>

Thank you for quick response. After removing https from hosts, I don't see any log or error. I'm running this logstash on my private VNET. I did look up into /usr/share/logstash/logs and don't see anymore logs.

The service is active and showing as running. However, I don't see any output ☹ Is there any other location to view the logstash progress? I set log.level: info FYI

My output plugin is as below

```auto
output {   
file {
      path => "/tmp/logstash/output.log"
   }
}

```

---

<div class="post-metadata">

**Author:** ![newelastic](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Post date:** [April 29, 2022, 6:26pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/4 "2022-04-29T18:26:28Z")

</div>

After restarting the service, I could see the logs in /mnt/logstash/logs

But, I'm seeing below error. I'm passing a valid SSL cert though.

```auto
Error: problem creating x509 Aux certificate java.io.IOException: unknown tag 13 encountered
Exception: Faraday::SSLError
stack: org/jruby/ext/openssl/SSLContext.java:402 in setup

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 29, 2022, 6:29pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/5 "2022-04-29T18:29:49Z")

</div>

Looks like a cert issue but I am not able to assist with that. If you don't get a response I would make a separate post asking for help with the cert now.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2022, 7:33pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/6 "2022-04-29T19:33:52Z")

</div>

Is there more to the stack trace? The "unknown tag 13 encountered" suggests it is expecting an ASN.1 byte stream but getting something else (possibly a base64 encoded stream).

The exception appears to be happening [here](https://github.com/jruby/jruby-openssl/blob/af64ffd794c57737e29b7935101bab38534215ac/src/main/java/org/jruby/ext/openssl/SSLContext.java#L401). Going down that rabbit hole it appears to be building a certificate revocation list, which could be a call to (if I remember correctly) another web service, or even an LDAP server. The rest of the stack trace might help narrow that down.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2022, 7:34pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-tcp-connection-error/303624/7 "2022-05-27T19:34:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
