# \[Solved\] Filebeat -\> Logstash : connection reset by peer

**URL:** <https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 24, 2017, 4:31pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012 "2017-05-24T16:31:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![CyrilD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyrild/32/18492_2.png) [@CyrilD](https://discuss.elastic.co/u/CyrilD)\
**Post date:** [May 24, 2017, 4:31pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/1 "2017-05-24T16:31:48Z")

</div>

Hi there !

I'm testing a pipe like that for dumping my logs : filebeat -\> logstash -\> elasticsearch and I have strange errors from filebeat :

```
2017-05-24T18:08:51+02:00 DBG Try to publish 2 events to logstash with window size 105
2017-05-24T18:08:51+02:00 DBG handle error: read tcp 172.17.1.5:45543->172.17.105.2:5044: read: connection reset by peer
2017-05-24T18:08:51+02:00 DBG 0 events out of 2 events sent to logstash. Continue sending
2017-05-24T18:08:51+02:00 DBG close connection
2017-05-24T18:08:51+02:00 DBG closing
2017-05-24T18:08:51+02:00 ERR Failed to publish events caused by: read tcp 172.17.1.5:45543->172.17.105.2:5044: read: connection reset by peer
2017-05-24T18:08:51+02:00 INFO Error publishing events (retrying): read tcp 172.17.1.5:45543->172.17.105.2:5044: read: connection reset by peer
2017-05-24T18:08:51+02:00 DBG close connection
2017-05-24T18:08:51+02:00 DBG send fail

```

These errors are happening every 3~5 minutes. I'm only dumping /var/log/syslog on a quiet host (2 or 3 lines per minutes) so I don't think there is an overload.

As you can see, my filebeat host has for IP 172.17.1.5 and my logstash host has for IP 172.17.105.2  
I did a lot of network tests between my two hosts and I'm pretty sure there is no problems at all on network side.

Filebeat configuration is like that :

```
filebeat:
  prospectors:
  - document_type: syslog
    exclude_lines: [snmpd+(.)*(Connection from UDP)+]
    input_type: log
    paths: [/var/log/syslog]

output:
  logstash:
    hosts: ["logbucket01:5044"]

logging:
  to_syslog: false
  level: debug

```

And the relevant Logstash configuration is like that :

```
input { 
    beats {
        port => 5044
    }
}

```

Here are my versions :

```
filebeat_host# /usr/share/filebeat/bin/filebeat --version 
filebeat version 5.4.0 (amd64), libbeat 5.4.0

logstash_host# /usr/share/logstash/bin/logstash --version
logstash 5.4.0

```

I installed both of them with the official deb files.

I did not see any useful log on logstash side, even in debug mode there is no problem at all. I don't see anything in any system logs on both hosts.

Does anybody has an idea on how to solve that ? I can't imagine to go further with such errors on a simple case like that. I must have done something wrong somewhere but I have no idea where to look. I read a few post on the same errors but they are either abandoned or concerning something I dont use (ssl, tls..). So .. no clues.

If you need more informations just tell me I'll provide everything useful to solve this.

Thanks a lot,

Cyril

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 25, 2017, 12:19pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/2 "2017-05-25T12:19:14Z")

</div>

Logstash could be resetting the connection due to inactivity, in which case this shouldn't be a problem. You can try increasing the [client\_inactivity\_timeout](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-client_inactivity_timeout) on the LS side.

But from the logs, it looks like it's happening when sending. This could mean there is something blocking the LS pipeline. Does the problem occur if you output only to stdout or to a file from LS?

---

<div class="post-metadata">

**Author:** ![CyrilD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyrild/32/18492_2.png) [@CyrilD](https://discuss.elastic.co/u/CyrilD)\
**Post date:** [May 29, 2017, 9:21am UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/3 "2017-05-29T09:21:38Z")

</div>

Hi Andrew,

Thanks for your answer, I'll try to increase the client\_inactivity\_timeout to see if the error still occur. This settings looks promising !

I don't understand what you mean by "output only to stdout or to a file from LS?". Do you mean I should drop the elasticsearch output and replace it with a stdout output to test if the problem still occur ? Because since I get the error on the filebeat side, and nothing at all in logstash logs I doubt the elasticsearch output is the problem so I'm not sure I get your idea (my english is not very good). If the inactivity timeout has no effect, I will give it a try even if I'm not sure I understood correctly because it's easy to do.

I'll let you know the results, let me know if I get the second part of your message.

Thanks again !

---

<div class="post-metadata">

**Author:** ![CyrilD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyrild/32/18492_2.png) [@CyrilD](https://discuss.elastic.co/u/CyrilD)\
**Post date:** [May 29, 2017, 12:04pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/4 "2017-05-29T12:04:16Z")

</div>

Hi Andrew,

I think the settings did the trick. It's very weird because I changed the settings, restarted logstash and the problem occurred again during 5 or 6 minutes, then it stopped and now that's a few hours I have no errors anymore.

I also upgraded my kernel of my logstash server but I don't think that was the root cause.

I did not try the output to stdout since the problem seems to be resolved.

Thanks for your time,

Cyril

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 1, 2017, 2:41pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/5 "2017-06-01T14:41:53Z")

</div>

Using stdout instead of ES would have helped if there was a problem with ES output. For example, if ES was being overloaded or slow, the backpressure could eventually cause Logstash to sever the connections to Beats.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2017, 2:42pm UTC](https://discuss.elastic.co/t/solved-filebeat-logstash-connection-reset-by-peer/87012/6 "2017-06-29T14:42:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
