# Nxlog can not connet to logstash

**URL:** <https://discuss.elastic.co/t/nxlog-can-not-connet-to-logstash/48377>\
**Category:** Logstash\
**Created:** [April 26, 2016, 4:16am UTC](https://discuss.elastic.co/t/nxlog-can-not-connet-to-logstash/48377 "2016-04-26T04:16:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Inbeo\_Beo](https://avatars.discourse-cdn.com/v4/letter/i/d78d45/32.png) [@Inbeo\_Beo](https://discuss.elastic.co/u/Inbeo_Beo)\
**Post date:** [April 26, 2016, 4:16am UTC](https://discuss.elastic.co/t/nxlog-can-not-connet-to-logstash/48377/1 "2016-04-26T04:16:42Z")

</div>

Hi,

I have problem below:

i have 02 Servers with

- IP Ser1: 10.151.130.119 --\> installed ELK
- IP Ser2: 10.151.130.110 --\> OS is Win Server 2008r2 and nxlog is installed in there

I have a file nxlog configure in Ser2 is:

#define ROOT C:\Program Files\nxlog  
define ROOT C:\Program Files (x86)\nxlog

Moduledir %ROOT%\modules  
CacheDir %ROOT%\data  
Pidfile %ROOT%\data\nxlog.pid  
SpoolDir %ROOT%\data  
LogFile %ROOT%\data\nxlog.log

 Module xm\_syslog Module xm\_json Module im\_internal Exec $Message = to\_json(); # For windows 2003 and earlier use the following:
# Windows Event Log
# Uncomment im\_msvistalog for Windows Vista/2008 and later Module im\_msvistalog
# Uncomment im\_mseventlog for Windows XP/2000/2003

# Module im\_mseventlog

```
Exec $EventReceivedTime = integer($EventReceivedTime) / 1000000; to_json();

```

 Module om\_tcp Host 10.151.130.119 Port 5544 Exec to\_json();

\<Route 1\>  
Path eventlog, in =\> out

I have a file logstash configure in Ser1 is:

input {  
tcp {  
port =\> 5544  
}  
}

filter {  
json {  
source =\> "message"  
}

# Remove redundant fields

mutate {  
remove\_field =\> ["message","@version"]  
}

# Create network tags based on IP

cidr {  
add\_tag =\> ["ip-src-PrivateIP"]  
address =\> ["%{IPV4\_SRC\_ADDR}"]  
network =\> ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"]  
}

cidr {  
add\_tag =\> ["ip-dst-PrivateIP"]  
address =\> ["%{IPV4\_DST\_ADDR}"]  
network =\> ["10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"]  
}

cidr {  
add\_tag =\> ["ip-webserver"]  
address =\> ["%{IPV4\_SRC\_ADDR}", "%{IPV4\_DST\_ADDR}"]  
network =\> ["172.16.0.0/24"]  
}

cidr {  
add\_tag =\> ["ip-database"]  
address =\> ["%{IPV4\_SRC\_ADDR}", "%{IPV4\_DST\_ADDR}"]  
network =\> ["10.0.0.0/24"]  
}

cidr {  
add\_tag =\> ["ip-workstation"]  
address =\> ["%{IPV4\_SRC\_ADDR}", "%{IPV4\_DST\_ADDR}"]  
network =\> ["192.168.1.0/24"]  
}

# Remove redundant fields

mutate {  
remove\_field =\> ["message"]  
}

### Create Geo info based on IP

# Netflow source IP

```
geoip {

```

source =\> "IPV4\_SRC\_ADDR"  
target =\> "src\_geoip"  
fields =\> ["country\_code2", "country\_name", "continent\_code", "region\_name", "real\_region\_name", "city\_name", "postal\_code", "timezone", "location"]  
}

# Netflow destination IP

```
geoip {
    source => "IPV4_DST_ADDR"
    target => "dst_geoip"
    fields => ["country_code2", "country_name", "continent_code", "region_name", "real_region_name", "city_name", "postal_code", "timezone", "location"]
}

```

}

output {  
stdout {  
codec =\> rubydebug  
}

And i have trouble is:

- When i use Kibana and tab Discover which to show data --\> result is No result found
- when I check Kibana 's Status --\> report is ok ( STATUS GREEN ) but check textbox LOAD --\> database = 0 ( don't hava other databases are transfered)
- When i check log on file nxlog.log --\> i have report --\> ERROR couldn't connect to tcp socket on 10.151.130.119:5544; No connection could be made because the target machine actively refused it.

I don't know where is my mistake in there?

Pls, help me to resolve my trouble

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 26, 2016, 5:31am UTC](https://discuss.elastic.co/t/nxlog-can-not-connet-to-logstash/48377/2 "2016-04-26T05:31:35Z")

</div>

Is 10.151.130.119 really the machine where Logstash runs? Is Logstash actually listening on port 5544? Can you connect to that port from the same machine? Could there be a firewall blocking the access?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/nxlog-can-not-connet-to-logstash/48377/3 "2017-07-06T05:00:36Z")

</div>


