# Unable to get logstash guide example working

**URL:** https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109
**Category:** Logstash
**Created:** [February 6, 2016, 4:24am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109 "2016-02-06T04:24:07Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![samba1](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@samba1](https://discuss.elastic.co/u/samba1)
#### Post date: [February 6, 2016, 4:24am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/1 "2016-02-06T04:24:07Z")

</div>

I'm following along with this: [https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html)

And was on the second part.

I decided to not do twitter to avoid signing up for a dev key and giving them my phone, and instead am just doing the beats part.

First I tried without SSL, and was getting the error:

`Beats Input: Remote connection closed {:peer=>"127.0.0.1:58326", :exception=>#<Lumberjack::Beats::Connection::ConnectionClosed: Lumberjack::Beats::Connection::ConnectionClosed wrapping: Lumberjack::Beats::Parser::UnsupportedProtocol, unsupported protocol 72>, :level=>:warn}`

Then I added SSL stuff, and now get

```
The error reported is: 
  No message available

```

For reference, my logstash config is:

```
input {
    beats {
        port => "5043"
    }
}
output {
    elasticsearch {
    }
    file {
        path => "/tmp/logstash-out"
    }
}

```

and my filebeat.yml is

```
filebeat:
  prospectors:
    -
      paths:
        - "/var/log/*.log"
      fields:
        type: syslog
output:
  elasticsearch:
    enabled: true
    hosts: ["http://localhost:5043"]

```

I'm just trying to get something going to see it working.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 6, 2016, 4:28am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/2 "2016-02-06T04:28:45Z")

</div>

You have beats sending directly to ES, not to LS, and on a bad port.  
Maybe you intended to use the Logstash output as mentioned [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html#config-filebeat-logstash).

---

<div class="post-metadata">

### Author: ![samba1](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@samba1](https://discuss.elastic.co/u/samba1)
#### Post date: [February 6, 2016, 3:31pm UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/4 "2016-02-06T15:31:49Z")

</div>

I thought was odd, but I was following the guide (which I mis-linked originally, it's [https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html))

I feel like I tried that, as well, but I will try again.

---

<div class="post-metadata">

### Author: ![samba1](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@samba1](https://discuss.elastic.co/u/samba1)
#### Post date: [February 7, 2016, 4:44pm UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/7 "2016-02-07T16:44:30Z")

</div>

Setting it to localhost:5044 gives a "connection refused", even though logstash is indeed running.

That's because logstash does indeed run on port 5043, so the "elasticsearch" in the thing I linked is right, just mislabeled, I think.

Is there accurate documentation on connecting filebeats and logstash anywhere?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 9, 2016, 1:18am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/8 "2016-02-09T01:18:47Z")

</div>

What's your config look like now?

---

<div class="post-metadata">

### Author: ![samba1](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@samba1](https://discuss.elastic.co/u/samba1)
#### Post date: [February 9, 2016, 11:57pm UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/9 "2016-02-09T23:57:26Z")

</div>

I've tried reducing it to just this:

```auto
input {
    beats {
        port => "5043"
    }
}
output {
    elasticsearch {
    }
    file {
        path => "/tmp/logstash-out"
    }
}

```

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 10, 2016, 12:18am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/10 "2016-02-10T00:18:22Z")

</div>

What about filebeat?

---

<div class="post-metadata">

### Author: ![samba1](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@samba1](https://discuss.elastic.co/u/samba1)
#### Post date: [February 10, 2016, 10:15pm UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/11 "2016-02-10T22:15:12Z")

</div>

I've tried a number of setups, here's one:

```auto
filebeat:
  prospectors:
    -
      paths:
        - "/var/log/foo.log"
      input_type: log
output:
  elasticsearch:
    hosts: ["localhost:9200"]
  logstash:
    hosts: ["localhost:5043"]

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/unable-to-get-logstash-guide-example-working/41109/12 "2017-07-06T05:12:10Z")

</div>


