# Transport.go 125 SSL client failed to connect with dial tcp \<IP:Address of ELK\>5044 getsockopt connection refused

**URL:** <https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706>\
**Category:** Beats\
**Created:** [August 23, 2018, 11:00am UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706 "2018-08-23T11:00:56Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![murthy.mvvs](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Post date:** [August 23, 2018, 11:00am UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/1 "2018-08-23T11:00:56Z")

</div>

Hi Team,  
The filebeat seems to be running, but giving the following error.  
**transport.go:125: SSL client failed to connect with: dial tcp \<IP address where elastic search, logstash and kibana are hosted\>: getsockopt: connection refused**

All the services in ELK are running

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 23, 2018, 3:55pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/2 "2018-08-23T15:55:56Z")

</div>

@Vishnu_Murty I have a few question to help debug that issue.

- Can you include your filebeat configuration in this thread.
- I believe you are using the elasticsearch output in the filebeat configuration, if so can you do a web request to the elasticsearch api from the filebeat machine?

```auto
curl "http:/remoteip:9200"
```

---

<div class="post-metadata">

**Author:** ![murthy.mvvs](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Post date:** [September 11, 2018, 3:15pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/3 "2018-09-11T15:15:55Z")

</div>

> [@pierhugues](#):
>
> curl "http:/remoteip:9200"

curl "[http://xx.xx.xx.xx:9200](http://xx.xx.xx.xx:9200)"

curl: (7) Failed connect to xx.xx.xx.x:9200; Connection refused

---

<div class="post-metadata">

**Author:** ![murthy.mvvs](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Post date:** [September 11, 2018, 3:17pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/4 "2018-09-11T15:17:04Z")

</div>

The above is error which I receive when I execute curl "[http://xx.xx.xx.xx:9200](http://xx.xx.xx.xx:9200)"

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 11, 2018, 3:22pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/5 "2018-09-11T15:22:49Z")

</div>

This should have **https** not **http**

```auto
curl "https://remoteip:9200"

```

Is Elasticsearch listening to the right IP address, by default it answer to localhost.  
Did you set these options?

```auto
#
# Set the bind address to a specific IP (IPv4 or IPv6):
#
#network.host: 192.168.0.1
#
# Set a custom port for HTTP:
#
#http.port: 9200
#
# For more information, consult the network module documentation.

```

---

<div class="post-metadata">

**Author:** ![murthy.mvvs](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Post date:** [September 12, 2018, 4:30am UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/6 "2018-09-12T04:30:48Z")

</div>

> [@pierhugues](#):
>
> curl "https://

# ---------------------------------- Network -----------------------------------

# 

# Set the bind address to a specific IP (IPv4 or IPv6):

# 

network.host: localhost

# 

# Set a custom port for HTTP:

# 

http.port: 9200

# 

# For more information, see the documentation at:

# \<[Networking settings | Reference](http://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html&gt);

# 

# --------------------------------- Discovery ----------------------------------

# 

# Pass an initial list of hosts to perform discovery when new node is started:

# The default list of hosts is ["127.0.0.1", "[::1]"]

---

<div class="post-metadata">

**Author:** ![murthy.mvvs](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@murthy.mvvs](https://discuss.elastic.co/u/murthy.mvvs)\
**Post date:** [September 12, 2018, 4:33am UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/7 "2018-09-12T04:33:07Z")

</div>

root@ELK-Stack-Log-ubuntu:/etc/elasticsearch# systemctl status elasticsearch  
● elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)  
Active: active (running) since Fri 2018-08-03 10:33:34 UTC; 1 months 9 days ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 1888 ExecStartPre=/usr/share/elasticsearch/bin/elasticsearch-systemd-pre-exec (code=exited, status=0/SUCCESS)  
Main PID: 1892 (java)  
Tasks: 52  
Memory: 1.6G  
CPU: 3d 22h 39min 8.383s  
CGroup: /system.slice/elasticsearch.service  
└─1892 /usr/bin/java -Xms256m -Xmx2g -Djava.awt.headless=true -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+Hea

Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at sun.nio.fs.UnixException.translateToIOException(UnixException.java:86)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:102)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:107)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at sun.nio.fs.UnixFileSystemProvider.newDirectoryStream(UnixFileSystemProvider.java:427)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at java.nio.file.Files.newDirectoryStream(Files.java:457)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at org.apache.lucene.store.FSDirectory.listAll(FSDirectory.java:191)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at org.apache.lucene.store.FSDirectory.listAll(FSDirectory.java:203)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at org.elasticsearch.index.store.FsDirectoryService$1.listAll(FsDirectoryService.java:127)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at org.apache.lucene.store.FilterDirectory.listAll(FilterDirectory.java:57)  
Sep 12 04:31:40 ELK-Stack-Log-ubuntu elasticsearch[1892]: at org.apache.lucene.store.FilterDirectory.listAll(FilterDirectory.java:57)

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 12, 2018, 12:14pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/8 "2018-09-12T12:14:43Z")

</div>

> [@murthy.mvvs](#):
>
> network.host: localhost

@murthy.mvvs I supposed Filebeat and Elasticsearch are on two different machines? By for security reason, elasticsearch will only answer requests from localhost (same machine), if you want to receive events from another machine, you have to make sure you bind it to the correct IP it need to listen to.

```auto
# replace the X with the IP address and restart elasticsearch.
network.host: XXX.XXX.XXX.XXX

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2018, 2:25pm UTC](https://discuss.elastic.co/t/transport-go-125-ssl-client-failed-to-connect-with-dial-tcp-ip-address-of-elk-5044-getsockopt-connection-refused/145706/9 "2018-10-10T14:25:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
