# Shiping logs from kubernetes to elasticsearch using beats - Failed to connect: Get http://xxxxxx.us-central1.gcp.cloud.es.io:9243: read tcp 13.17.4.10:40766-\>31.177.77.2:9243: read: connection reset by peer

**URL:** <https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236>\
**Category:** Beats\
**Created:** [December 18, 2017, 1:23pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236 "2017-12-18T13:23:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinaWork](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dinaWork](https://discuss.elastic.co/u/dinaWork)\
**Post date:** [December 18, 2017, 1:23pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236/1 "2017-12-18T13:23:01Z")

</div>

following

> **[Shipping Kubernetes logs with Filebeat](https://www.elastic.co/blog/shipping-kubernetes-logs-to-elasticsearch-with-filebeat)**
>
> We recently wrote about the new Filebeat features to retrieve & enrich Docker logs using Filebeat, and since the 6.0 release, you can leverage the same technology when running Kubernetes. Metadata...

beats fails to ship logs  
get the following log:

```auto
ERR Failed to connect: Get http://xxxxxx.us-central1.gcp.cloud.es.io:9243: read tcp 13.17.4.10:40766->31.177.77.2:9243: read: connection reset by peer
11:38:19.230 reload.go:222: INFO Dynamic config reloader stopped
11:38:19.230 crawler.go:135: INFO Crawler stopped
11:38:19.230 registrar.go:210: INFO Stopping Registrar
11:38:19.230 registrar.go:165: INFO Ending Registrar
11:38:19.231 forwarder.go:35: INFO Prospector outlet closed
11:38:19.234 metrics.go:51: INFO Total non-zero values: beat.info.uptime.ms=40449 beat.memstats.gc_next=25194960 beat.memstats.memory_alloc=13894472 beat.memstats.memory_total=43826552 filebeat.events.active=4130 filebeat.events.added=4140 filebeat.events.done=10 filebeat.harvester.closed=4 filebeat.harvester.open_files=16 filebeat.harvester.running=16 filebeat.harvester.started=20 libbeat.config.module.running=1 libbeat.config.module.starts=1 libbeat.config.reloads=2 libbeat.output.read.errors=6 libbeat.output.type=elasticsearch libbeat.output.write.bytes=1434 libbeat.pipeline.clients=0 libbeat.pipeline.events.active=4116 libbeat.pipeline.events.failed=4 libbeat.pipeline.events.filtered=20 libbeat.pipeline.events.published=4116 libbeat.pipeline.events.retry=150 libbeat.pipeline.events.total=4140 registrar.states.current=6 registrar.states.update=6 registrar.writes=8
11:38:19.234 metrics.go:52: INFO Uptime: 40.449909073s
11:38:19.234 beat.go:284: INFO filebeat stopped.

```

here is the full log:

> <https://gist.github.com/DinaWork/96c5b6b7319e9b1d570ac63cc6b5b954>

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 18, 2017, 1:39pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236/2 "2017-12-18T13:39:38Z")

</div>

Should that not be `https` (or maybe you should leave the protocol out)?

---

<div class="post-metadata">

**Author:** ![dinaWork](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dinaWork](https://discuss.elastic.co/u/dinaWork)\
**Post date:** [December 20, 2017, 9:38am UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236/3 "2017-12-20T09:38:38Z")

</div>

@Christian_Dahlqvist thanks!  
I changed

```auto
        - name: ELASTICSEARCH_HOST
          value: xxxxxxxxxxx.us-central1.gcp.cloud.es.io

```

to

```auto
        - name: ELASTICSEARCH_HOST
          value: https://xxxxxxxxxxx.us-central1.gcp.cloud.es.io

```

now I dont get `failed to connect` , but still filebeat fails with the log:

```auto
08:35:47.409927 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.info.uptime.ms=30002 beat.memstats.gc_next=30422496 beat.memstats.memory_alloc=15212880 beat.memstats.memory_total=141696232 filebeat.events.active=4119 filebeat.events.added=13031 filebeat.events.done=8912 filebeat.harvester.open_files=20 filebeat.harvester.running=20 filebeat.harvester.started=20 libbeat.config.module.running=1 libbeat.config.module.starts=1 libbeat.config.reloads=2 libbeat.output.read.bytes=157671 libbeat.output.type=elasticsearch libbeat.output.write.bytes=8987379 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=4117 libbeat.pipeline.events.filtered=20 libbeat.pipeline.events.published=13008 libbeat.pipeline.events.retry=50 libbeat.pipeline.events.total=13029 libbeat.pipeline.queue.acked=8892 registrar.states.current=20 registrar.states.update=8912 registrar.writes=184
08:35:48.006481 filebeat.go:323: INFO Stopping filebeat
08:35:48.006524 crawler.go:109: INFO Stopping Crawler
08:35:48.006536 crawler.go:119: INFO Stopping 0 prospectors
08:35:48.006559 reload.go:222: INFO Dynamic config reloader stopped
08:35:48.006580 reload.go:222: INFO Dynamic config reloader stopped
08:35:48.006589 crawler.go:135: INFO Crawler stopped
08:35:48.006613 registrar.go:210: INFO Stopping Registrar
08:35:48.006640 registrar.go:165: INFO Ending Registrar
08:35:48.007093 forwarder.go:35: INFO Prospector outlet closed
08:35:48.014069 metrics.go:51: INFO Total non-zero values: beat.info.uptime.ms=30331 beat.memstats.gc_next=33630224 beat.memstats.memory_alloc=30452528 beat.memstats.memory_total=143441184 filebeat.events.active=4116 filebeat.events.added=13026 filebeat.events.done=8910 filebeat.harvester.closed=1 filebeat.harvester.open_files=16 filebeat.harvester.running=16 filebeat.harvester.started=17 libbeat.config.module.running=1 libbeat.config.module.starts=1 libbeat.config.reloads=2 libbeat.output.read.bytes=157857 libbeat.output.type=elasticsearch libbeat.output.write.bytes=9566414 libbeat.pipeline.clients=0 libbeat.pipeline.events.active=4116 libbeat.pipeline.events.failed=1 libbeat.pipeline.events.filtered=17 libbeat.pipeline.events.published=13008 libbeat.pipeline.events.retry=50 libbeat.pipeline.events.total=13026 libbeat.pipeline.queue.acked=8892 registrar.states.current=17 registrar.states.update=8909 registrar.writes=185
08:35:48.014112 metrics.go:52: INFO Uptime: 30.331515461s
08:35:48.014121 beat.go:284: INFO filebeat stopped.
08:35:48.002759 filebeat.go:323: INFO Stopping filebeat
08:35:48.002784 crawler.go:109: INFO Stopping Crawler
08:35:48.002806 crawler.go:119: INFO Stopping 0 prospectors
08:35:48.002830 reload.go:222: INFO Dynamic config reloader stopped
08:35:48.002847 reload.go:222: INFO Dynamic config reloader stopped
08:35:48.002854 crawler.go:135: INFO Crawler stopped
08:35:48.002861 registrar.go:210: INFO Stopping Registrar
08:35:48.002888 registrar.go:165: INFO Ending Registrar
08:35:48.003162 forwarder.go:35: INFO Prospector outlet closed
08:35:48.003223 forwarder.go:35: INFO Prospector outlet closed
08:35:48.003251 forwarder.go:35: INFO Prospector outlet closed
08:35:48.009565 metrics.go:51: INFO Total non-zero values: beat.info.uptime.ms=30602 beat.memstats.gc_next=30422496 beat.memstats.memory_alloc=17696448 beat.memstats.memory_total=144179800 filebeat.events.active=4116 filebeat.events.added=13231 filebeat.events.done=9115 filebeat.harvester.closed=3 filebeat.harvester.open_files=17 filebeat.harvester.running=17 filebeat.harvester.started=20 libbeat.config.module.running=1 libbeat.config.module.starts=1 libbeat.config.reloads=2 libbeat.output.read.bytes=161229 libbeat.output.type=elasticsearch libbeat.output.write.bytes=9187054 libbeat.pipeline.clients=0 libbeat.pipeline.events.active=4116 libbeat.pipeline.events.failed=3 libbeat.pipeline.events.filtered=20 libbeat.pipeline.events.published=13208 libbeat.pipeline.events.retry=50 libbeat.pipeline.events.total=13231 libbeat.pipeline.queue.acked=9092 registrar.states.current=20 registrar.states.update=9112 registrar.writes=189
08:35:48.009588 metrics.go:52: INFO Uptime: 30.602265961s
08:35:48.009595 beat.go:284: INFO filebeat stopped.

```

here is the full log:

> <https://gist.github.com/DinaWork/f6aeb30029544bac64f6e2b9f181c1a2>

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [December 20, 2017, 10:45am UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236/4 "2017-12-20T10:45:38Z")

</div>

Uhm,

From the log it looks like everything worked, and then a normal stop was triggered, are you sure you didn't delete the pod? You can get the history with `kubectl describe`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 1:30pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-failed-to-connect-get-http-xxxxxx-us-central1-gcp-cloud-es-io-9243-read-tcp-13-17-4-10-40766-31-177-77-2-9243-read-connection-reset-by-peer/112236/5 "2018-01-08T13:30:21Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
