# Read error looking for ack: EOF

**URL:** <https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880>\
**Category:** Logstash\
**Created:** [August 5, 2015, 10:51am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880 "2015-08-05T10:51:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![anilmaddukuri](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@anilmaddukuri](https://discuss.elastic.co/u/anilmaddukuri)\
**Post date:** [August 5, 2015, 10:51am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/1 "2015-08-05T10:51:31Z")

</div>

I am new to ELK stack. My configuration contains logstash-forwarder pushing my server logs to logstash residing in a seperate instance. But recently i found two issues.

1. Logstash-forwarder is able to connect to logstash server but imediately throwing the error

Setting trusted CA from file: /path/to//logstash-forwarder.crt  
2015/08/05 10:18:39.416031 Connecting to [x.x.x.x]:8140  
2015/08/05 10:18:39.467751 Connected to x.x.x.x  
2015/08/05 10:18:39.543006 Read error looking for ack: EOF

and the same log is repeated again and again

1. My logstash server seems to be starting fine if i start it as a service but after sometime it stops abruptly. In Logstash.err log i see the following

Error: Your application used more memory than the safety cap of 500M.  
Specify -J-Xmx####m to increase it (#### = cap size in MB).  
Specify -w for full OutOfMemoryError stack trace

But i dont think my application is taking that much memory. Moreover the same configuration is working in other instances.  
versions i am using are: 0.4.0 for logstash-forwarder and 1.4.2 for logstash.

please suggest any fix for this as i could find anything on the internet.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 7, 2015, 1:49am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/2 "2015-08-07T01:49:17Z")

</div>

What versions of everything are you using? OS?

What is different between the instance you are using here and the other ones that work?

---

<div class="post-metadata">

**Author:** ![anilmaddukuri](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@anilmaddukuri](https://discuss.elastic.co/u/anilmaddukuri)\
**Post date:** [August 7, 2015, 8:45am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/3 "2015-08-07T08:45:42Z")

</div>

> [@warkolm](#):
>
> hat is different between the instance you are using here and the other ones that work?

I am using EC2 instances for this. OS is Amazon linux with AMI ID: ami-c57c05b2. And regarding the second question there is no difference between the working ones and this one. That is what confuses me the most.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 7, 2015, 9:17am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/4 "2015-08-07T09:17:52Z")

</div>

I'd upgrade to 1.5.3 for LS for starters.

How much RAM do these instances have?

---

<div class="post-metadata">

**Author:** ![anilmaddukuri](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@anilmaddukuri](https://discuss.elastic.co/u/anilmaddukuri)\
**Post date:** [August 7, 2015, 9:22am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/5 "2015-08-07T09:22:40Z")

</div>

Ram is 2GB out of which around 1GB is free

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/read-error-looking-for-ack-eof/26880/6 "2017-07-06T05:32:38Z")

</div>


