# \[publisher\_pipeline\_output\] pipeline /output.go:154 Failed to connect to backoff(async(tcp://logstash-xxx-xxx.apps.-xxx.xxx:443)): EOF

**URL:** <https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451>\
**Category:** Logstash\
**Created:** [March 6, 2021, 8:24pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451 "2021-03-06T20:24:33Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 6, 2021, 8:24pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/1 "2021-03-06T20:24:33Z")

</div>

Hello Guys,  
Thanks in advance for taking your time to look into the issue i am experiencing.

Error in File beat at the time of Debug  
[publisher\_pipeline\_output] pipeline /output.go:154 Failed to connect to backoff(async(tcp://logstash-xxx-xxx.apps.-xxx.xxx:443)): EOF

When i try to connect to the Logstash instance via Telnet it works fine (I get blank screen) However, at the time of connecting it with Logstash i am getting this error.

Hope to get some assistance on this.

Thanks in Advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 6, 2021, 8:44pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/2 "2021-03-06T20:44:34Z")

</div>

You are saying that telnet connects to port 443? Is TLS enabled on that port?

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 7, 2021, 3:33am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/3 "2021-03-07T03:33:36Z")

</div>

Hi Badger,  
For some reason i believed that Port 443 by default has TLS enabled - However if we speak of defaultpipeline.yml - I do have SSL Enabled within that and so it is enabled in Filebeat.yml

Does that help?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 7, 2021, 3:55am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/4 "2021-03-07T03:55:54Z")

</div>

Hi @Rohan-boogeyman

Perhaps you could post your filebeat.yml and the Logstash pipeline for the filebeat input, that would help us understand your configuration.

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 7, 2021, 4:31am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/5 "2021-03-07T04:31:21Z")

</div>

Thanks @stephenb !

Please details below - let me know if there's something else you require to assist on this issue.

**#================Filebeat Yml Logstash output =============================**  
output.logstash:  
hosts: ["[openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com:443](http://openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com:443)"]  
ssl.certificate\_authorities: ["C:\certs\openshift logstash\xxx\_xxx\_G2\_Intermediate\_CA.cer", "C:\certs\openshift logstash\xxx\_xxx\_G2\_Root\_CA.cer"]  
ssl.certificate: "C:\certs\openshift logstash\openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com.cer"  
ssl.key: "C:\certs\openshift logstash\openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx-pkcs8.key"  
ssl.enabled: true

**================Logstash File beat Input: =============================**  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/etc/logstash/conf.d/xxx\_xxx\_G2\_Intermediate\_CA.cer", "/etc/logstash/conf.d/xxx\_xxx\_G2\_Root\_CA.cer"]  
ssl\_certificate =\> "/etc/logstash/conf.d/openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com.cer"  
ssl\_key =\> "/etc/logstash/conf.d/openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com-pkcs8.key"  
ssl\_verify\_mode =\> "peer"  
}  
}

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 7, 2021, 5:17am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/6 "2021-03-07T05:17:51Z")

</div>

Well the first things I see is you have the logstash output of the filebeats file configured to

`openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com:443`

But it should be configured to port 5044 Because you have Logstash beats input listening on 5044. (Normal beats listening port for Logstash)

`openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.com:5044`

That would be the first thing I would fix.

Then report back.

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 7, 2021, 5:33am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/7 "2021-03-07T05:33:05Z")

</div>

Thanks for your prompt response @stephenb but i tried that too and i was getting an error message:

2021-03-07T00:30:40.906-0500 ERROR [publisher\_pipeline\_output] pipeline  
/output.go:154 Failed to connect to backoff(async(tcp://openshift-logstash-xxx  
-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx:5044)): dial tcp 10.240.196.184  
:5044: connectex: No connection could be made because the target machine activel  
y refused it.

Now this port worked fine when we had no certs applied - issues started happening only when we took the approach of having ssl route.  
Also to add earlier - i was using Logstash node [ulvocpd082.xxx.xxx.com](http://ulvocpd082.xxx.xxx.com) and its Service Port 32460 to connect with Filebeats and since this idea of using SSL certs was introduced i was recommended to use "complete route" along with port "443" and i started experiencing issues.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 7, 2021, 6:07am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/8 "2021-03-07T06:07:40Z")

</div>

Right now you need to get your ports, ssl and certs settled / fixed.

If you listen on 5044 then you send on 5044, if you want to use 443 , then you need to send on 443 and listen on Logstash beats input on 443, which is fine. Don't mix and match.

2nd / Next You have tried to set up the most strictest SSL policies at the very beginning.

First I would try less strict and then iterate to strict.

Example on the file beat log stash output section

I would look at [these](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#_verification_mode) settings.

First I would try this

`ssl.verfication_mode: none`

Also in the Logstash beats input you set the most strict [ssl\_verify\_mode](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-ssl_verify_mode) policy which will be fine but I think you need to start and get the connectivity and then fix your SSL.

Perhaps start with and then refine

`ssl_verify_mode => none`

Note this is not for production but should test whether the connectivity works.

then if all that works you can start to try to use the stricter SSL policies and verification modes

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 7, 2021, 6:37am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/9 "2021-03-07T06:37:37Z")

</div>

> [@stephenb](#):
>
> ssl.verfication\_mode: none

Hi @stephenb,

fixed both and i am still getting:  
2021-03-07T01:32:00.410-0500 ERROR [publisher\_pipeline\_output] pipeline /output.go:154 Failed to connect to backoff(async(tcp://openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx:443)): EOF

===================Filebeat YML=======================================  
hosts: ["openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx:443"]  
ssl.certificate\_authorities: ["C:\certs\openshift logstash\xxx\_xxx\_G2\_Intermediate\_CA.cer", "C:\certs\openshift logstash\xxx\_xxx\_G2\_Root\_CA.cer"]  
ssl.certificate: "C:\certs\openshift logstash\openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx.cer"  
ssl.key: "C:\certs\openshift logstash\openshift-logstash-xxx-xxx-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx.key"  
ssl.enabled: true  
ssl.verfication\_mode: none

======================= Logstash Defaultpipeline.yml====================  
input {  
beats {  
port =\> 443  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/etc/logstash/conf.d/xxx\_xxx\_G2\_Intermediate\_CA.cer", "/etc/logstash/conf.d/xxx\_xxx\_G2\_Root\_CA.cer"]  
ssl\_certificate =\> "/etc/logstash/conf.d/openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx.cer"  
ssl\_key =\> "/etc/logstash/conf.d/openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx-pkcs8.key"  
ssl\_verify\_mode =\> "none"  
}  
}

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 7, 2021, 6:53am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/10 "2021-03-07T06:53:02Z")

</div>

At this point I suspect you have a connectiivty issues between the two hosts on those ports, a Firewall, routing, proxy, nat or something. I notice you are running in open shift, does it only allow certain ports? Does ssl termination happen elsewhere? I am not an open shift expert so I will not be able to help much there.

An easy way to test is start Logstash with the ssl disabled.

`ssl => false`

Or comment out all the ssl settings

Then try to telnet from the filebeat host to the logstash host it should connect, if it does not you have a connectivity issue. I I'm not an open shift expert so I will not be able to help you with that.

From the filebeat server / container

`telnet openshift-logstash-xxx-dev-cl1-xxx-xxx.apps.c1-ocp-dc1.xxx.xxx.xxx 443`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 7, 2021, 7:08am UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/11 "2021-03-07T07:08:42Z")

</div>

Also how are you starting logstash can you see in the logstash startup logs that Logstash is actually starting , starting the right pipeline and listening on the right port?.. you should be able to see all that in the logs

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 10, 2021, 6:27pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/12 "2021-03-10T18:27:05Z")

</div>

@stephenb - So this issue got resolved - had to involve an OCP guy - so it appears Host configuration in filebeat Yml file was supposed to point to 443 - and Filebeat Input within Logstash was 5044 - That part was correct.  
Issue was OCP was configured as "NodePort" which had to be changed to "ClusterIP" to allow full route be used to send logs from Beats to Logstash.

---

<div class="post-metadata">

**Author:** ![Rohan-boogeyman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan-boogeyman/32/81377_2.png) [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Post date:** [March 10, 2021, 6:32pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/13 "2021-03-10T18:32:12Z")

</div>

Now Logs are flowing fine - however i am getting a new error within OCP that has to do with "Connection reset by peer" in logstash - for which i did apply suggestion [[Solved] Filebeat -\> Logstash : connection reset by peer](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012)  
even though I increased client\_inactivity\_timeout to 60k within Logstash - still continue to get this error.  
Logs are flowing just fine from Filebeat to Kibana but this error is something i'd like to have fixed to ensure a clean implementation of certs.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 10, 2021, 7:42pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/14 "2021-03-10T19:42:50Z")

</div>

Hi @Rohan-boogeyman

That is good news, glad things are working better!

Interesting configuration / network topology.

With respect to your other issue connection reset peer, in light of your moderately complex architecture and network topology, running logstash in openshift, it is possible there may be a component (A switch, router, FW, Load Balancer) in between filebeat and logstash which may be terminating the connection, I have seen this before.

Can you ask your OCP person if long lived connections are allowed? Or is there anything that mught be affecting long lived connections.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2021, 7:43pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451/15 "2021-04-07T19:43:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
