# \[Solved\] Does anyone have a working LSF-\>HAProxy-\>Logstash 1.5.2 indexers stack?

**URL:** <https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268>\
**Category:** Logstash\
**Created:** [July 9, 2015, 9:31pm UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268 "2015-07-09T21:31:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [July 9, 2015, 9:31pm UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268/1 "2015-07-09T21:31:07Z")

</div>

On my production cluster, I have Logstash-Forwarder connecting to my two Logstash 1.4.2 indexers via a HAProxy load balancer.

After testing an upgrade to Logstash 1.5.2 on my test cluster, I upgraded production. And everything broke.

Since my test cluster does not have HAProxy involved, I'm certain that's where the worst of my problems are located.

When I told one production LSF instance to bypass the HAProxy, the indexer started receiving events. (Though it ran into lumberjack pipeline errors...).

LSF logged messages like:

```
Loading client ssl certificate: /path/to/pemfile.pem and /path/to/keyfile.key
Setting trusted CA from file: /path/to/CAFile.crt
Connecting to [ha.pro.xy.ip]:5043 (haproxy.example.tld) 
Read error looking for ack: EOF

```

Anyway, long story short, something in how Logstash handles LSF connections changed between 1.4.2 and 1.5.2. That change made HAProxy stop working.

Any suggestions?

Note, as soon as I restored Logstash back to 1.4.2, it started working again.

Oh, and I am using the elasticsearch\_http plugin with 1.4.2, and the elasticsearch plugin with http protocol on 1.5.2.

---

<div class="post-metadata">

**Author:** ![jasonc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonc/32/3522_2.png) [@jasonc](https://discuss.elastic.co/u/jasonc)\
**Post date:** [July 10, 2015, 9:51pm UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268/2 "2015-07-10T21:51:04Z")

</div>

What is your haproxy config?

You'll need to put it into TCP mode so its passing through the connection to the SSL LSF endpoint.

I've had some luck with this config, but am still troubleshooting a member that isn't balancing properly, so it may be a wonky config:

```
listen logstashforwarder
bind x.x.x.x:6783 
mode tcp
balance roundrobin
option tcplog
server logstash-prod-node01 x.x.x.x:6783 check
server logstash-prod-node02 x.x.x.x:6783 check
```

---

<div class="post-metadata">

**Author:** ![panaman](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@panaman](https://discuss.elastic.co/u/panaman)\
**Post date:** [July 21, 2015, 4:24am UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268/3 "2015-07-21T04:24:09Z")

</div>

This is haproxy configuration is working for me.  
I am also using the latest logstash (1.5.2)

global  
chroot /var/lib/haproxy  
daemon  
group haproxy  
maxconn 4000  
pidfile /var/run/haproxy.pid  
stats socket /var/lib/haproxy/stats  
user haproxy

defaults  
log 127.0.0.1 local0  
log 127.0.0.1 local1 notice  
timeout queue 10m  
timeout connect 10s  
timeout client 10m  
timeout server 10m  
timeout check 10s

listen logstash  
bind 10.0.69.5:6969  
mode tcp  
balance leastconn  
option tcplog  
server logstash01 10.0.69.7:6969 check  
server logstash02 10.0.69.8:6969 check

listen proxystats  
bind 10.0.69.5:80  
mode http  
stats enable  
stats hide-version  
stats realm Haproxy\ Statistics  
stats uri /

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [September 2, 2015, 6:05pm UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268/4 "2015-09-02T18:05:27Z")

</div>

So, after upgrading Logstash to 1.5.4, my old configuration works just fine. I assume the ssl related bugs they fixed in the new version were the source of my problems.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/solved-does-anyone-have-a-working-lsf-haproxy-logstash-1-5-2-indexers-stack/25268/5 "2017-07-06T05:30:20Z")

</div>


