# Unable to listen on port 5044 for logstash on unbuntu 20.04

**URL:** <https://discuss.elastic.co/t/unable-to-listen-on-port-5044-for-logstash-on-unbuntu-20-04/262664>\
**Category:** Logstash\
**Created:** [January 29, 2021, 3:33pm UTC](https://discuss.elastic.co/t/unable-to-listen-on-port-5044-for-logstash-on-unbuntu-20-04/262664 "2021-01-29T15:33:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_fleming/32/81768_2.png) [@Paul\_Fleming](https://discuss.elastic.co/u/Paul_Fleming)\
**Post date:** [January 29, 2021, 3:33pm UTC](https://discuss.elastic.co/t/unable-to-listen-on-port-5044-for-logstash-on-unbuntu-20-04/262664/1 "2021-01-29T15:33:59Z")

</div>

Using Ubuntu 20.04 I have confirmed OpenSSL is running and then I have installed logstash by running the following commands.  
`  
openssl version -a  
apt install logstash -y

Edit the etc/hosts file and add the following line.

127.0.0.1 localhost  
127.0.1.1 ubuntu  
18.224.44.11 elk-master

Let’s generate an SSL certificate to secure the log data transfer from the client Rsyslog & Filebeat to the Logstash server.

To do this create a new SSL directory under Logstash configuration directory and navigate into that directory generate an SSL certificate by running following command:

mkdir -p /etc/logstash/ssl

cd /etc/logstash/

openssl req -subj '/CN=elk-master/' -x509 -days 3650 -batch -nodes -newkey rsa:2048 -keyout ssl/logstash-forwarder.key -out ssl/logstash-forwarder.crt

**Now,** we are going to create new configuration files for Logstash named ‘filebeat-input.conf’ as input file from filebeat ‘syslog-filter.conf’ for system logs processing, and ‘output-elasicsearch.conf’ file to define Elasticsearch output.

Navigate to Logstash directory create a file ‘filebeat-input.conf’ in conf.d directory by running command

cd /etc/logstash/

nano conf.d/filebeat-input.conf

input {  
beats {  
port =\> 5443  
type =\> syslog  
ssl =\> true  
ssl\_certificate =\> "/etc/logstash/ssl/logstash-forwarder.crt"  
ssl\_key =\> "/etc/logstash/ssl/logstash-forwarder.key"  
}  
}

For the system log data processing, we are going to use a filter plugin named ‘grok’. Create a new conf. file ‘syslog-filter.conf in the same directory

nano conf.d/syslog-filter.conf

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

And at last create a configuration file ‘output-elasticsearch.conf’ for the output of elasticsearch.

nano conf.d/output-elasticsearch.conf

and do the following configuration

and paste the following configuration

output {  
elasticsearch { hosts =\> ["localhost:9200"]  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"]  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

And at last, save and exit.

Now start, enable & verify the status of Logstash service.

'systemctl start logstash'  
'systemctl enable logstash'  
systemctl status logstash

systemctl start logstash  
systemctl enable logstash  
systemctl status logstash  
`

However when I entered the following command netstat plntu it shows the listening ports but it doesen't display port 5044 for logstash please help me resolve this issue.

 ![Ubuntu](https://us1.discourse-cdn.com/elastic/original/3X/8/1/815d984e58c09f99253124546d28d9304627ba90.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 1, 2021, 12:48am UTC](https://discuss.elastic.co/t/unable-to-listen-on-port-5044-for-logstash-on-unbuntu-20-04/262664/2 "2021-02-01T00:48:18Z")

</div>

Welcome to our community! 😃  
Please don't post pictures of text, they are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

What does your Logstash log show?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2021, 12:48am UTC](https://discuss.elastic.co/t/unable-to-listen-on-port-5044-for-logstash-on-unbuntu-20-04/262664/3 "2021-03-01T00:48:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
