# Sending log from filebeat to logstash error: Failed to publish events caused by: lumberjack protocol error

**URL:** <https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 20, 2019, 3:15am UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332 "2019-10-20T03:15:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam/32/56209_2.png) [@Sam](https://discuss.elastic.co/u/Sam)\
**Post date:** [October 20, 2019, 3:15am UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/1 "2019-10-20T03:15:14Z")

</div>

Halo guys  
I'm new with ELK Stack  
I try to send IIS log from FileBeat to Logstash and further but it doesn't work. I get an error _Failed to publish events caused by: lumberjack protocol error_ when start FileBeat (Logstash is running)

Here all my config

_filebeat.yml_

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - e:\\elk\\iislog\\*
  exclude_lines: ['#']
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
output.logstash:
  hosts: ["localhost:5044"]

```

_logstash.yml_

```
 node.name: main
 pipeline.id: main
 pipeline.workers: 2
 http.host: "localhost"
 http.port: 5044

```

_logstash.iis.conf_

```
input {  
   beats {
        port => "5044"
    }
}

output {

}

```

_iis.yml_

```
- module: iis
  # Access logs
  access:
    enabled: true
    var.paths: 
        - e:\elk\iislog\*.log
  error:
    enabled: true

```

Logstash screen stand at line _Successfully started Logstash API endpoint {:port=\>5044}_ All stack are version 7.4.0

Can you guys show me what am i doing wrong  
Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 20, 2019, 6:54am UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/2 "2019-10-20T06:54:33Z")

</div>

> [@Sam](#):
>
> http.host: "localhost" http.port: 5044

Change this monitoring port to the default 9600 as it clashes with the beats input. You can not have two different things bind to the same port.

---

<div class="post-metadata">

**Author:** ![Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam/32/56209_2.png) [@Sam](https://discuss.elastic.co/u/Sam)\
**Post date:** [October 20, 2019, 12:30pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/3 "2019-10-20T12:30:58Z")

</div>

Thanks for your help, i change the config like you said and now it throws new error  
_dial tcp [::1]:5044: connectex: No connection could be made because the target machine actively refused it._  
Can you help me ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 20, 2019, 12:56pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/4 "2019-10-20T12:56:32Z")

</div>

I assume you did not change the beats plugin config?

---

<div class="post-metadata">

**Author:** ![Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam/32/56209_2.png) [@Sam](https://discuss.elastic.co/u/Sam)\
**Post date:** [October 20, 2019, 1:02pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/5 "2019-10-20T13:02:20Z")

</div>

I disabled iis module  
Now my filebeat.yml is

```
filebeat.inputs:

- type: log
  enabled: true

  paths:
    - e:\elk\iislog\*
  exclude_lines: ['#']
output.logstash:
  hosts: ["localhost:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  ssl.certificate_authorities: ["E:\\elk\\cert\\server.crt"]

  # Certificate for SSL client authentication
  ssl.certificate: "E:\\elk\\cert\\server.crt"

  # Client Certificate Key
  ssl.key: "E:\\elk\\cert\\server.key"

```

and the logstash.iis.conf is

```
input {  
   beats {
        port => 5044
	ssl => true
	ssl_certificate_authorities => "E:\elk\cert\server.crt"
	ssl_certificate => "E:\elk\cert\server.crt"
	ssl_key => "E:\elk\cert\server.key"
	ssl_verify_mode => "peer"
	}
}

output {
	stdout { 
	     
	}
}

```

and the logstash.yml unchange

start logstash  
`logstash -f logstash.iis.conf`  
start filebeat  
`filebeat -e -c filebeat.yml`

---

<div class="post-metadata">

**Author:** ![Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam/32/56209_2.png) [@Sam](https://discuss.elastic.co/u/Sam)\
**Post date:** [October 20, 2019, 2:35pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/6 "2019-10-20T14:35:15Z")

</div>

My bad  
I using the config file in one folder and edit file in other location

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2019, 2:35pm UTC](https://discuss.elastic.co/t/sending-log-from-filebeat-to-logstash-error-failed-to-publish-events-caused-by-lumberjack-protocol-error/204332/7 "2019-11-17T14:35:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
