# Why does Logstash close idle TCP connections with RST instead of FIN?

**URL:** <https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000>\
**Category:** Logstash\
**Created:** [June 9, 2025, 12:03pm UTC](https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000 "2025-06-09T12:03:44Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [June 9, 2025, 12:03pm UTC](https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000/1 "2025-06-09T12:03:44Z")

</div>

Hi Elastic team,

I’m trying to better understand how client\_inactivity\_timeout works in Logstash, specifically in relation to how it closes idle TCP connections.

### **Context:**

We have Winlogbeat agents sending logs over TCP to Logstash. Winlogbeat sends TCP keep-alives every ~15 seconds, and these are acknowledged by the OS on the Logstash side (confirmed via Wireshark). However, when no **log events** are sent for the duration of client\_inactivity\_timeout, Logstash closes the connection by sending a **TCP RST** (reset), **not** a FIN.

### **My question:**

> **Is it expected behavior for Logstash to terminate idle TCP connections with a RST rather than FIN/ACK?**

From a networking standpoint, I would expect FIN/ACK for a normal connection shutdown. A RST usually signals an error, and this has consequences:

- On the Winlogbeat side, it’s logged as an **error** :"An existing connection was forcibly closed by the remote host."
- This makes it appear as if something went wrong, even though it’s just an expected timeout on the Logstash side.

### **Suggestion:**

Using **FIN/ACK** would make this a clean and unambiguous connection close. It would also reduce confusion during debugging, especially since the agents treat RST as a sign of failure.

Thanks for any clarification — is this behavior intentional, and if so, could there be an option in the future to allow graceful termination?
