# Unable to ship logs from beats to logstash

**URL:** <https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [October 7, 2022, 8:57am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048 "2022-10-07T08:57:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 7, 2022, 8:57am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/1 "2022-10-07T08:57:31Z")

</div>

I have configured beats to ouput logs to logstash via 2 servers. The problem is that for some reason logs are not being shipped to Logstash, I even ran a tcpdump on logstash servers and can't find anything relevant. What can I check from beats side ? Network is open.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 10, 2022, 3:53pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/2 "2022-10-10T15:53:18Z")

</div>

Hey @charlot_Attard,

What beats are you using? Could you share the configuration? Do you see anything in Beats logs?

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 12, 2022, 9:49am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/3 "2022-10-12T09:49:37Z")

</div>

HI @jsoriano,

Thanks for your reply.

Beats Version is 7.16.6

Basically we are shipping logs from a filebeat windows server to a Logstash Linux Server. On the filebeat server we are not seeing any exceptions but on the Logstash server we are seeing an exception similar to the below

" local:0.0.0.0:5044 remote: IPOFBEATSSERVER Handling exception  
Received fatal alert: bad\_certificate  
An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last"

Beats is configured with the below certs

ssl\_enable: true  
ssl.certificate\_authorities:  
ssl.certificate:  
ssl.key:

Thanks,

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 13, 2022, 6:13pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/4 "2022-10-13T18:13:59Z")

</div>

Can you share the whole Beats configuration? Where is this ssl configuration enclosed?  
I guess they have actual values in the configuration?

> [@charlot\_Attard](#):
>
> Received fatal alert: bad\_certificate

The error clearly seems to point to some issue with some certificate.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 17, 2022, 1:58pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/5 "2022-10-17T13:58:54Z")

</div>

> [@jsoriano](#):
>
> I guess they have actual values in the configuration?

Hello @jsoriano

Thanks for your help and sorry for not replying before.

What I noticed is that when configuring filebeat.yml to connect to logstash servers with hostnames, there is no network activity on the logstash servers. I confirmed this with a tcpdump. When I configured filebeat to connect to logstash servers with IP's there is network connectivity.

Do you have an idea of what might be the problem ?

Thanks a lot,  
Charlot

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 17, 2022, 2:02pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/6 "2022-10-17T14:02:14Z")

</div>

> [@charlot\_Attard](#):
>
> What I noticed is that when configuring filebeat.yml to connect to logstash servers with hostnames, there is no network activity on the logstash servers. I confirmed this with a tcpdump. When I configured filebeat to connect to logstash servers with IP's there is network connectivity.

Ok, this, and the `bad certificate` error may indicate that some certificate is only valid when using the IP, but not when using the hostname. This could be because the certificate has the IP as alternate name but not the hostname.

How are you generating these certificates? Can you check what alternate names and IPs they have?

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 17, 2022, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/7 "2022-10-17T14:03:34Z")

</div>

The bad\_certificate i am getting is because I tried to connect from filebeat to logstash via IP and the certificates were generated with the hostname of the servers.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 17, 2022, 2:16pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/8 "2022-10-17T14:16:22Z")

</div>

@jsoriano

So at first I had hostnames configured and after not seeing any network activity on the logstash servers I decided to switch for IP's. When I did I start seeing network activity via tcpdump and on logstash logs bad\_certificate ( Reason being because the certs were generated with hostname as CN. (I confirmed this now again with openssl). So the bottom line that I came up with is that the filebeat agent establishes a session with IP's but not with hostnames. Please note that I used host files to bypass any DNS issues on filebeat servers and also tried nslookup which worked on filebeat agents.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 17, 2022, 2:54pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/9 "2022-10-17T14:54:25Z")

</div>

To discard any issue with the logstash output or logstash communication, did you try to output to console or to file?

You could you try to comment out the logstash output in the configuration, and add a [file output](https://www.elastic.co/guide/en/beats/filebeat/8.4/file-output.html)? Then check if filebeat is writing events to these files.

If it is not, then there may be no problem with the logstash output, but the problem is in filebeat collecting logs.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 17, 2022, 3:08pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/10 "2022-10-17T15:08:50Z")

</div>

> [@jsoriano](#):
>
> To discard any issue with the logstash output or logstash communication, did you try to output to console or to file?

Thanks for the good suggestion @jsoriano

I did it and it worked, so beats is able to catch and write logs. So the problem lies with sending events to logstash I believe

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 17, 2022, 3:21pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/11 "2022-10-17T15:21:51Z")

</div>

Ok, so the issue seems to be in the logstash output, yes. Try to enable debug logging for it, for that, run filebeat with `-d logstash`.  
If Filebeat fails to connect or to send events to Logstash there should be something in the logs.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 17, 2022, 3:22pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/12 "2022-10-17T15:22:39Z")

</div>

> [@charlot\_Attard](#):
>
> Beats Version is 7.16.6

Btw, you can also consider updating Filebeat, at least to last 7.17 if you don't want to jump to 8.x yet.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 17, 2022, 3:38pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/13 "2022-10-17T15:38:16Z")

</div>

I m getting this

Unable to write data to the transport connection An established connection was aborted by the software in your host machine

Quite intresting googling a bit about it.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 18, 2022, 9:03am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/14 "2022-10-18T09:03:25Z")

</div>

Hello @jsoriano ,

What is happening now Im getting

DNS lookup failure no such host.

NSLookup on the server works and I also did a host file.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 18, 2022, 9:24am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/15 "2022-10-18T09:24:54Z")

</div>

Umm, it could be that beats is not using the host file 🤔 You mentioned that Filebeat is running on Windows, right? How are you configuring the host file there?

How are you installing and running Filebeat?

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 18, 2022, 9:44am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/16 "2022-10-18T09:44:10Z")

</div>

> [@jsoriano](#):
>
> Umm, it could be that beats is not using the host file 🤔 You mentioned that Filebeat is running on Windows, right? How are you configuring the host file there?

I solved this by connecting filebeat to only one logstash node.

Now Im not seeing any more errors on filebeat. Is there a way to know on logstash that logs are being received by filebeat ?

Please Note : When running tcpdump on logstash now i am seeing network activity from filebeat. 🙂

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 18, 2022, 9:49am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/17 "2022-10-18T09:49:22Z")

</div>

> [@charlot\_Attard](#):
>
> Now Im not seeing any more errors on filebeat. Is there a way to know on logstash that logs are being received by filebeat ?

What outputs have you configured in logstash? You could check there if there is any document.

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 18, 2022, 10:07am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/18 "2022-10-18T10:07:56Z")

</div>

I have configured

output.logstash - I'm querying data in kibana and can't find any documents.

My idea is if it is possible to search in logstash and maybe I check where is the data being shipped from filebeat. But I don't know if logstash writes data on the logstash server of filebeat.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 18, 2022, 10:21am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/19 "2022-10-18T10:21:36Z")

</div>

I was asking about the configuration in logstash. Do you have any output configured there?

---

<div class="post-metadata">

**Author:** ![charlot\_Attard](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Post date:** [October 18, 2022, 10:28am UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048/20 "2022-10-18T10:28:18Z")

</div>

> [@jsoriano](#):
>
> I was asking about the configuration in logstash. Do you have any output configured there?

Sorry I misunderstood you @jsoriano

Output is rabbitmq

[Next page](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048.md?page=2)
