# Winlogbeat Nginx Proxy to Logstash - Connection Reset

**URL:** <https://discuss.elastic.co/t/winlogbeat-nginx-proxy-to-logstash-connection-reset/131967>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [May 15, 2018, 3:11pm UTC](https://discuss.elastic.co/t/winlogbeat-nginx-proxy-to-logstash-connection-reset/131967 "2018-05-15T15:11:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![douglas](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@douglas](https://discuss.elastic.co/u/douglas)\
**Post date:** [May 15, 2018, 3:11pm UTC](https://discuss.elastic.co/t/winlogbeat-nginx-proxy-to-logstash-connection-reset/131967/1 "2018-05-15T15:11:09Z")

</div>

Hello,

I have the following setup:

[Nginx Port 80]

Forwards to

[Logstash Port 5044]

Directly connects and speaks with

[Elasticsearch Port 9200]

This works with Metricbeat fine, all requests and conversations happen.

Here is my nginx setup:

```
user root;
worker_processes auto;
load_module /usr/lib/nginx/modules/ngx_stream_module.so;
error_log /var/log/nginx/error.log warn;
pid /var/run/nginx.pid;
events {
  worker_connections 1024;
}

stream {
log_format basic '$time_iso8601 $remote_addr '
                   '$protocol $status $bytes_sent $bytes_received '
                   '$session_time $upstream_addr '
                   '"$upstream_bytes_sent" "$upstream_bytes_received" "$upstream_connect_time"';

# Enable access_log statements for debugging

access_log /var/log/nginx/stream.log basic;

upstream syslog_servers {
server logstash:514;
}

server {
listen 514;
listen 514 udp;

proxy_responses 0;
proxy_pass syslog_servers;
proxy_buffer_size 4096k;

# access_log /var/log/nginx/stream.log basic;
}

upstream logstash_beats_servers {
server logstash:5044;
}

server {
listen 80;
proxy_responses 1;

proxy_connect_timeout 30s;

proxy_pass logstash_beats_servers;
proxy_buffer_size 4096k;

access_log /var/log/nginx/winlogbeat.log basic;
}

}

daemon off;

```

Here is my beats configuration:

```
input {
  beats {
    port => 5044
    type => beats
  }
}

output {
  if [type] == "beats" {
    elasticsearch {
    hosts => "elasticsearch:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
    }
  }
}

```

I have captured the error in Nginx:

```
2018/05/15 14:23:50 [error] 1794#1794: *527214 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.10:5044", bytes from/to client:3876/18, bytes from/to upstream:18/3876
2018/05/15 14:28:01 [error] 1795#1795: *528980 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.11:5044", bytes from/to client:1669/6, bytes from/to upstream:6/1669
2018/05/15 14:29:36 [error] 1795#1795: *529380 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.12:5044", bytes from/to client:3196/12, bytes from/to upstream:12/3196

```

I have also captured the problem in Winlogbeat log:

```
2018-05-15T16:05:56.893+0100	ERROR	logstash/async.go:235	Failed to publish events caused by: EOF
2018-05-15T16:05:56.895+0100	ERROR	logstash/async.go:235	Failed to publish events caused by: client is not connected
2018-05-15T16:05:57.896+0100	ERROR	pipeline/output.go:92	Failed to publish events: client is not connected

```

I am unsure what the difference in the conversation is between Metricbeat -\> Logstash and Winlogbeat -\> Logstash, I was of the understanding they both used the lumberjack protocol on 5044

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [May 16, 2018, 2:46pm UTC](https://discuss.elastic.co/t/winlogbeat-nginx-proxy-to-logstash-connection-reset/131967/2 "2018-05-16T14:46:44Z")

</div>

Winlogbeat and Metricbeat both uses the same exact code for the Lumberjack output. I haven't used Nginx as a proxy other than with the HTTP protocol. Since Lumberjack is not based on HTTP I am not sure how it will behave in that condition, since Lumberjack is a persistent connection with two way communication.

```auto
2018/05/15 14:23:50 [error] 1794#1794: *527214 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.10:5044", bytes from/to client:3876/18, bytes from/to upstream:18/3876
2018/05/15 14:28:01 [error] 1795#1795: *528980 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.11:5044", bytes from/to client:1669/6, bytes from/to upstream:6/1669
2018/05/15 14:29:36 [error] 1795#1795: *529380 recv() failed (104: Connection reset by peer) while proxying connection, client: 192.168.1.10, server: 0.0.0.0:80, upstream: "172.18.0.12:5044", bytes from/to client:3196/12, bytes from/to upstream:12/3196

```

This look like Logstash killed the connection? Maybe because it hit the `client_timeout` value on the beat input side?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2018, 2:46pm UTC](https://discuss.elastic.co/t/winlogbeat-nginx-proxy-to-logstash-connection-reset/131967/3 "2018-06-13T14:46:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
