# Timeout Connection are not being monitored by packetbeat

**URL:** <https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [October 3, 2015, 4:38pm UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581 "2015-10-03T16:38:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 3, 2015, 4:38pm UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/1 "2015-10-03T16:38:15Z")

</div>

I have noticed one more issue where packetbeat is not sending data for connection timeouts on nginx running on application servers. So whenever there is any 504 on nginx logs there is no corresponding log in packetbeats.

Is that mean packetbeat is not catering connection timeouts ??

Every other http response code looks like working fine but looks like all 50X response codes got some monitoring problem.

Thanks,  
Suraj

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 3, 2015, 5:10pm UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/2 "2015-10-03T17:10:07Z")

</div>

Hi @5uraj, how many seconds is the timeout period for your Nginx server?

---

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 4, 2015, 2:54am UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/3 "2015-10-04T02:54:56Z")

</div>

I have 60 seconds timeout on nginx and then proxy\_pass timeout is 30 seconds.

---

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 4, 2015, 3:31am UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/4 "2015-10-04T03:31:11Z")

</div>

Timeout requests are giving me :

WARN Response from unknown transaction. Ignoring: TcpTuple src[X.0.X.X:80] dst[X.0.X.X:59509] stream\_id[14]

Looks like we are ignoring those connections which are NOT getting closed properly with FIN/ACK.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 4, 2015, 9:42am UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/5 "2015-10-04T09:42:14Z")

</div>

The issue is that after 10 seconds Packetbeat stops tracking the state of a transaction. The transaction timeout is not currently configurable. I will open an issue on Github for making the timeout configurable.

---

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 4, 2015, 11:09am UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/6 "2015-10-04T11:09:20Z")

</div>

Where can I change in code itself and re-build for now, till the time we make it configurable.

---

<div class="post-metadata">

**Author:** ![5uraj](https://avatars.discourse-cdn.com/v4/letter/5/fbc32d/32.png) [@5uraj](https://discuss.elastic.co/u/5uraj)\
**Post date:** [October 4, 2015, 11:55am UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/7 "2015-10-04T11:55:55Z")

</div>

Got it, changed DefaultTransactionExpiration variable, It really helps.  
Looking forward to make it configurable per protocol basis.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 11, 2015, 1:41pm UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/8 "2015-10-11T13:41:40Z")

</div>

Glad to hear you were able to change the timeout and that it is working. I created the following issue to track this enhancement:

> <https://github.com/elastic/beats/issues/300>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:58pm UTC](https://discuss.elastic.co/t/timeout-connection-are-not-being-monitored-by-packetbeat/31581/9 "2017-07-05T21:58:39Z")

</div>


