Problems with FIlebeat and logstash

873 views
Skip to first unread message

C. L. Martinez

unread,
Apr 30, 2018, 3:21:48 AM4/30/18
to wa...@googlegroups.com
Hi all,

 On of my wazuh's node cluster is returning the following errors:

2018-04-30T07:15:59.815Z    ERROR    logstash/async.go:235    Failed to publish events caused by: client is not connected
2018-04-30T07:16:00.815Z    ERROR    pipeline/output.go:92    Failed to publish events: client is not connected
2018-04-30T07:16:00.829Z    ERROR    logstash/async.go:235    Failed to publish events caused by: client is not connected
2018-04-30T07:16:00.829Z    ERROR    logstash/async.go:235    Failed to publish events caused by: write tcp 172.22.54.4:40520->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:01.830Z    ERROR    pipeline/output.go:92    Failed to publish events: write tcp 172.22.54.4:40520->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:01.844Z    ERROR    logstash/async.go:235    Failed to publish events caused by: client is not connected
2018-04-30T07:16:01.844Z    ERROR    logstash/async.go:235    Failed to publish events caused by: write tcp 172.22.54.4:40522->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:02.844Z    ERROR    pipeline/output.go:92    Failed to publish events: write tcp 172.22.54.4:40522->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:02.853Z    ERROR    logstash/async.go:235    Failed to publish events caused by: client is not connected
2018-04-30T07:16:02.854Z    ERROR    logstash/async.go:235    Failed to publish events caused by: write tcp 172.22.54.4:40524->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:03.854Z    ERROR    pipeline/output.go:92    Failed to publish events: write tcp 172.22.54.4:40524->172.22.59.11:5000: write: broken pipe
2018-04-30T07:16:03.859Z    ERROR    logstash/async.go:235    Failed to publish events caused by: EOF
2018-04-30T07:16:03.867Z    ERROR    logstash/async.go:235    Failed to publish events caused by: client is not connected

 This node can connect to logstash:

root@wazuhnode01:/var/log/filebeat# ncat 172.22.59.11 5000 </dev/null >/dev/null && echo "yes"
yes

 But my wazuh's manager is down due to a soft problem that I'm trying to figure out. My question is: if wazuh's manager (in a cluster configuration) is down, are  these errors normal?

Thanks.

C. L. Martinez

unread,
Apr 30, 2018, 3:31:06 AM4/30/18
to wa...@googlegroups.com
OK, problem solved. The problem was that logstash has been updated to version 6.2.4

jua...@wazuh.com

unread,
Apr 30, 2018, 3:35:11 AM4/30/18
to Wazuh mailing list
Hello C. L. Martinez,

I'm glad you managed to solve your problem so quickly!

As always, we're here to help, so don't hesitate to open a new thread whenever you run into some kind of problem.

Regards,
Juanjo
Reply all
Reply to author
Forward
0 new messages