# UDP listener problem

**URL:** <https://discuss.elastic.co/t/udp-listener-problem/98677>\
**Category:** Logstash\
**Created:** [August 29, 2017, 11:51am UTC](https://discuss.elastic.co/t/udp-listener-problem/98677 "2017-08-29T11:51:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 29, 2017, 11:51am UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/1 "2017-08-29T11:51:13Z")

</div>

Hey i have a probleme with UDP:

my conf : firewalld and selinux disable

logtstash 5.5-2

**my conf :**

> input {  
> udp {  
> port =\> 9556  
> host =\> "1.1.1.55"  
> workers =\> 2  
> codec =\> netflow {  
> versions =\> [5, 9]  
> target =\> "nf"  
> }  
> type =\> "netflow"  
> }`

logstash.yml :

> #  
> path.data: /var/lib/logstash  
> #  
> pipeline.workers: 2  
> #  
> # How many workers should be used per output plugin instance  
> #  
> pipeline.output.workers: 1  
> #  
> pipeline.batch.size: 125  
> #  
> #  
> pipeline.batch.delay: 5  
> #  
> #he pipeline configuration for the main pipeline  
> #  
> path.config: /etc/logstash/conf.d/\*  
> #  
> #  
> #  
> # log.level: info  
> path.logs: /var/log/logstash  
> #  
> # ------------ Other Settings --------------  
> #  
> # Where to find custom plugins  
> # path.plugins:

**my error :** `2017-08-29T16:57:27,428][INFO][logstash.pipeline] Pipeline main started [2017-08-29T16:57:27,429][INFO][logstash.inputs.udp] Starting UDP listener {:address=>"1.1.1.55:9556"} [2017-08-29T16:57:27,445][INFO][logstash.inputs.udp] UDP listener started {:address=>"1.1.1.55:9556", :receive_buffer_bytes=>"106496", :queue_size=>"2000"} [2017-08-29T16:57:27,452][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600} [2017-08-29T17:01:30,404][INFO][logstash.runner] Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash [2017-08-29T17:01:41,465][WARN][logstash.runner] SIGTERM received. Shutting down the agent. [2017-08-29T17:01:41,473][WARN][logstash.agent] stopping pipeline {:id=>"main"} [2017-08-29T17:01:41,832][WARN][logstash.inputs.udp] UDP listener died {:exception=>#<IOError: closed stream>, :backtrace=>["org/jruby/RubyIO.java:3705:in `select'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:93:in `udp_listener'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:56:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:456:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:449:in `start\_input'"]}`

help me plz

---

<div class="post-metadata">

**Author:** ![amiguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amiguez/32/21466_2.png) [@amiguez](https://discuss.elastic.co/u/amiguez)\
**Post date:** [August 29, 2017, 12:25pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/2 "2017-08-29T12:25:20Z")

</div>

From the message:  
**[logstash.runner] Using config.test\_and\_exit mode. Config Validation Result: OK.**

logstash is executed in 'test configuration mode'? In that case it is normal that it exits.

---

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 29, 2017, 12:40pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/3 "2017-08-29T12:40:36Z")

</div>

i run this command :

> /usr/share/logstash/bin/logstash -t -f /etc/logstash/conf.d/0001-input-netflow.conf --path.settings /etc/logstash/

and after i restart logstash and i have :

```
[2017-08-29T17:38:14,833][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"http://localhost:9200/"}
[2017-08-29T17:39:49,357][INFO][logstash.runner] Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash
[2017-08-29T18:01:57,325][WARN][logstash.runner] SIGTERM received. Shutting down the agent.
[2017-08-29T18:01:57,340][WARN][logstash.agent] stopping pipeline {:id=>"main"}
[2017-08-29T18:01:57,450][WARN][logstash.inputs.udp] UDP listener died {:exception=>#<IOError: closed stream>, :backtrace=>["org/jruby/RubyIO.java:3705:in `select'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:93:in `udp_listener'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:56:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:456:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:449:in `start_input'"]}

```

---

<div class="post-metadata">

**Author:** ![amiguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amiguez/32/21466_2.png) [@amiguez](https://discuss.elastic.co/u/amiguez)\
**Post date:** [August 29, 2017, 12:52pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/4 "2017-08-29T12:52:40Z")

</div>

remove the '-t'

Anyways... i could not reproduce the messages that you get when closing down Logstash. 🤔

---

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 29, 2017, 1:09pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/5 "2017-08-29T13:09:31Z")

</div>

when i stop logstash and start logstash ( systemctl start logstash.service)

i have :

> [2017-08-29T18:22:24,674][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
> [2017-08-29T18:22:24,676][INFO][logstash.pipeline] Pipeline main started  
> [2017-08-29T18:22:24,678][INFO][logstash.inputs.udp] Starting UDP listener {:address=\>"1.1.1.55:9556"}  
> [2017-08-29T18:22:24,692][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2017-08-29T18:22:24,695][INFO][logstash.inputs.udp] UDP listener started {:address=\>"1.1.1.55:9556", :receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"}  
> [2017-08-29T18:30:17,968][WARN][logstash.runner] SIGTERM received. Shutting down the agent.  
> [2017-08-29T18:30:17,977][WARN][logstash.agent] stopping pipeline {:id=\>"main"}  
> [2017-08-29T18:30:18,315][WARN][logstash.inputs.udp] UDP listener died {:exception=\>#\<IOError: closed  
> stream\>, :backtrace=\>["org/jruby/RubyIO.java:3705:in `select'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:93:in `udp\_listener'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-udp-3.1.1/lib/logstash/inputs/udp.rb:56:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:456:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:449:in `start\_input'"]}

---

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 29, 2017, 2:52pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/6 "2017-08-29T14:52:02Z")

</div>

now i have this :

> [2017-08-29T20:11:40,130][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
> [2017-08-29T20:11:40,132][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
> [2017-08-29T20:11:40,196][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
> [2017-08-29T20:11:40,198][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
> [2017-08-29T20:11:40,232][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
> [2017-08-29T20:11:40,235][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
> [2017-08-29T20:11:40,250][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
> [2017-08-29T20:11:40,252][INFO][logstash.pipeline] Pipeline main started  
> [2017-08-29T20:11:40,253][INFO][logstash.inputs.udp] Starting UDP listener {:address=\>"1.1.1.55:9556"}  
> [2017-08-29T20:11:40,268][INFO][logstash.inputs.udp] UDP listener started {:address=\>"1.1.1.55:9556", :receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"}  
> [2017-08-29T20:11:40,279][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

> netstat -aux  
> Connexions Internet actives (serveurs et Ã©tablies)  
> Proto Recv-Q Send-Q Adresse locale Adresse distante Etat  
> udp6 0 0 1.1.1.55:9556 [::]:\*

and with tcpdump i can see the netflow

but i have nothing

---

<div class="post-metadata">

**Author:** ![amiguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amiguez/32/21466_2.png) [@amiguez](https://discuss.elastic.co/u/amiguez)\
**Post date:** [August 29, 2017, 4:55pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/7 "2017-08-29T16:55:36Z")

</div>

> [@pierre1](#):
>
> and with tcpdump i can see the netflow

Do you mean that you see the traffic arriving into that host/port?

Test first with an console output instead of Elasticsearch (or in addition to) to see if at least it is processed.  
Actually you could also check the logstash API endpoint to see if there are events processed

---

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 29, 2017, 6:12pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/8 "2017-08-29T18:12:10Z")

</div>

In my output i have in a file and ES but i am nothing

---

<div class="post-metadata">

**Author:** ![pierre1](https://avatars.discourse-cdn.com/v4/letter/p/a8b319/32.png) [@pierre1](https://discuss.elastic.co/u/pierre1)\
**Post date:** [August 30, 2017, 6:55pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/9 "2017-08-30T18:55:17Z")

</div>

i think there is a bug with UDP / netflow :

In all case i receive the flow

first :  
when my elk server can't communicate with my network equipment but i can see the netflow in it network interface with tcpdump, i have no data processed

second case :

when my elk server can communicate with my network equipment and i can see the netflow in it network interface with tcpdump, i have data processed

it does not mean anything, with UDP there is not communication as in TCP

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2017, 6:55pm UTC](https://discuss.elastic.co/t/udp-listener-problem/98677/10 "2017-09-27T18:55:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
