# Lumberjack input: Kafka output the pipeline is blocked, temporary refusing new connection

**URL:** <https://discuss.elastic.co/t/lumberjack-input-kafka-output-the-pipeline-is-blocked-temporary-refusing-new-connection/173264>\
**Category:** Logstash\
**Created:** [March 21, 2019, 8:24am UTC](https://discuss.elastic.co/t/lumberjack-input-kafka-output-the-pipeline-is-blocked-temporary-refusing-new-connection/173264 "2019-03-21T08:24:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bijucyborg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bijucyborg/32/42481_2.png) [@bijucyborg](https://discuss.elastic.co/u/bijucyborg)\
**Post date:** [March 21, 2019, 8:24am UTC](https://discuss.elastic.co/t/lumberjack-input-kafka-output-the-pipeline-is-blocked-temporary-refusing-new-connection/173264/1 "2019-03-21T08:24:48Z")

</div>

After we upgraded OS packages on the logstash server, logstash has stopped transmitting messages to Kafka. This is quite an old environment and uses the lumberjack plugin.

The architecture is somewhat like this

Logstash (entity1) ==\> Logstash (entity2) ==\> Kafka (entity2)

The Logstash (entity2) service keeps transmitting the following warning messages.

[2019-03-21T06:55:09,842][WARN][logstash.inputs.lumberjack] Lumberjack input: the pipeline is blocked, temporary refusing new connection.  
[2019-03-21T06:55:10,342][WARN][logstash.inputs.lumberjack] Lumberjack input: the pipeline is blocked, temporary refusing new connection.  
[2019-03-21T06:55:10,842][WARN][logstash.inputs.lumberjack] Lumberjack input: the pipeline is blocked, temporary refusing new connection.

* * *

The logstash config looks somewhat like this

input {  
lumberjack{  
port =\> 5000  
type =\> "logs"  
codec =\> "json"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder-fqdn.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder-fqdn.key"  
congestion\_threshold =\> 30  
}  
}  
filter {  
ruby{  
init =\> 'require "base64"'  
code =\> 'event.set("[message]", Base64.decode64(event.get("[message]")))'  
}  
}  
output {  
stdout{  
codec =\> line { format =\> "%{@timestamp} - %{[kafka][topic]}" }  
}

if "XXX" in [kafka][topic] or "YYY" in [kafka][topic] {  
kafka{  
topic\_id =\> "%{[kafka][topic]}"  
codec =\> plain { format =\> "%{message}" }  
bootstrap\_servers =\> "XXXXXXX:9092"  
metadata\_max\_age\_ms =\> "1000"  
retries =\> 60  
retry\_backoff\_ms =\> 5000  
acks =\> "all"  
}  
}

## }

RPM packages

logstash-5.2.2-1.noarch  
libselinux-ruby-2.0.94-7.el6.x86\_64  
ruby-libs-1.8.7.374-4.el6\_6.x86\_64  
rubygems-1.3.7-5.el6.noarch  
ruby-augeas-0.4.1-3.el6.x86\_64  
ruby-1.8.7.374-4.el6\_6.x86\_64  
rubygem-json-1.5.5-3.el6.x86\_64  
ruby-libs-1.8.7.374-5.el6.x86\_64  
ruby-rdoc-1.8.7.374-5.el6.x86\_64  
ruby-irb-1.8.7.374-4.el6\_6.x86\_64  
ruby-shadow-2.2.0-2.el6.x86\_64

\*\*\* LOCAL GEMS \*\*\*

json (1.5.5)

* * *

1. I have checked connectivity and everything looks fine.
2. I tested changing the codec from json to plain in the input part and then the warning messages stop but then this does not help parse the messages for kafka, because of the logic we need.
3. If I add congestion\_threshold to 2200000 or such ridiculous value then the lumberjack warnings go away but no messages reach Kafka. I believe logstash is just spending time trying to process them.

Any help or advice to solve this problem is appreciated.

---

<div class="post-metadata">

**Author:** ![bijucyborg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bijucyborg/32/42481_2.png) [@bijucyborg](https://discuss.elastic.co/u/bijucyborg)\
**Post date:** [April 6, 2019, 9:01am UTC](https://discuss.elastic.co/t/lumberjack-input-kafka-output-the-pipeline-is-blocked-temporary-refusing-new-connection/173264/2 "2019-04-06T09:01:58Z")

</div>

So the problem was that the logstash-kafka-output plugin had to be downgraded in order to be compatible with Kafka 0.9.0.0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2019, 9:02am UTC](https://discuss.elastic.co/t/lumberjack-input-kafka-output-the-pipeline-is-blocked-temporary-refusing-new-connection/173264/3 "2019-05-04T09:02:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
