# Problem with crashing UDP Sender in Logstash

**URL:** <https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032>\
**Category:** Logstash\
**Created:** [April 30, 2019, 7:42am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032 "2019-04-30T07:42:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pipari](https://avatars.discourse-cdn.com/v4/letter/p/a587f6/32.png) [@pipari](https://discuss.elastic.co/u/pipari)\
**Post date:** [April 30, 2019, 7:42am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032/1 "2019-04-30T07:42:51Z")

</div>

Hi,  
We use logstash to send UDP data through a secure interface that only allows communication in one direction. It worked very well intil I introduced a little more load to it.

Running ELK stack 6.6.0 with filebeat and auditbeat at the same version.

Now I get this error:

----- ERROR MESSAGE ----- Start  
logstash[16381]: [2019-04-30T09:21:57,882][FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<Errno::EMSGSIZE: Message too long - No message available\>, :backtrace=\>["org/jruby/ext/socket/RubyUDPSocket.java:438:in `send'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-udp-3.0.6/lib/logstash/outputs/udp.rb:24:in`block in register'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-codec-json-3.0.5/lib/logstash/codecs/json.rb:42:in `encode'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-udp-3.0.6/lib/logstash/outputs/udp.rb:31:in`receive'", "/usr/share/logstash/logstash-core/lib/logstash/outputs/base.rb:89:in `block in multi_receive'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/outputs/base.rb:89:in `multi_receive'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:114:in`multi\_receive'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:97:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:373:in`block in output\_batch'", "org/jruby/RubyHash.java:1343:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:372:in`output\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:324:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:287:in`block in start\_workers'"]}  
----- ERROR MESSAGE ----- Stop

------------- CONFIGURATION ---------- Stop  
We have a configuration that looks like this:

Server1  
filebeat/auditbeat -\> logstash -\> UDP to server 2

Logstash configuration:  
input {  
beats {  
port =\>   
ssl =\> true  
ssl\_certificate =\> ""  
ssl\_key =\> ""  
}

}  
output {  
udp {  
host =\> ""  
port =\>   
codec =\> "json"  
}  
}

Server2  
UDP from server 1 -\> logstash -\> elasticsearch

Logstash configuration:  
input {  
udp {  
port =\>   
codec =\> "json"  
type =\> "source\_udp"  
}  
}

------------- CONFIGURATION ---------- Start

Any one knows what im doing wrong? Or what to tweak to make it work with more load?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 30, 2019, 7:56am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032/2 "2019-04-30T07:56:24Z")

</div>

Don't use UDP to send data between Logstash hosts. UDP does offer any delivery guarantees and has a limitation on size. Instead use TCP plugins or maybe even a lumberjack output paired with a beats input plugin on the receiving side.

---

<div class="post-metadata">

**Author:** ![pipari](https://avatars.discourse-cdn.com/v4/letter/p/a587f6/32.png) [@pipari](https://discuss.elastic.co/u/pipari)\
**Post date:** [April 30, 2019, 8:00am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032/3 "2019-04-30T08:00:21Z")

</div>

Don´t have any choice. We use a data diode (unidirectional) between the servers for protection.

I know its not a good solution but with the data diode I have to use UDP.

For reference. A unit like this one:

> **[Data Diode Integrated 1000BaseT to 1000BaseT | Fibersystem](https://www.fibersystem.com/product/data-diode-integrated-1000baset-to-1000baset/)**
>
> Data Diodes are used to allow secure networks to receive data from open/general purpose networks. Unidirectional transfer of data over fiber cable or copper cable between two networks with hardware…

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 30, 2019, 8:10am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032/4 "2019-04-30T08:10:42Z")

</div>

Then I suspect you may need to guard against messages that are too large and filter these out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2019, 8:10am UTC](https://discuss.elastic.co/t/problem-with-crashing-udp-sender-in-logstash/179032/5 "2019-05-28T08:10:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
