# AWS NLB config infront of FileBeats Instance

**URL:** <https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 1, 2021, 5:24pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065 "2021-04-01T17:24:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi342883](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravi342883/32/74643_2.png) [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Post date:** [April 1, 2021, 5:24pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/1 "2021-04-01T17:24:46Z")

</div>

Hi All,

I'm trying to setup a AWS Network Load Balancer (NLB) in-front of Filebeat instance. Need help in 1. How to configure the NLB &  
2. How to do health check in NLB.

Note:  
This setup is to collect the logs from various devices (over UDP) into Elastic Search via Filebeat agent.  
Devices --\> NLB--\> FileBeat --\> ES

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 3, 2021, 2:47pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/2 "2021-04-03T14:47:32Z")

</div>

This seems more like a question for aws not elasticsearch

---

<div class="post-metadata">

**Author:** ![Ravi342883](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravi342883/32/74643_2.png) [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Post date:** [April 6, 2021, 6:43pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/3 "2021-04-06T18:43:23Z")

</div>

I have a query related to the FileBeat server running on the EC2 (target).

The NLB health checks are configured as TCP. Is the filebeat is capable of handling TCP health checks originating from the NLB ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 7, 2021, 2:01am UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/4 "2021-04-07T02:01:40Z")

</div>

As answered in the other post, I think that your problem is that the AWS NLB can't do a health check using UDP, so you will need to do the health check using TCP or HTTP/HTTPS.

You can do that adding a TCP input in filebeat that will be used only for this healthcheck, than in your target group you configure the health check to use this port.

Or you can try this [experimental feature](https://www.elastic.co/guide/en/beats/filebeat/7.12/http-endpoint.html) that exposes the metrics http endpoint, and use this endpoint as the target for the health check.

---

<div class="post-metadata">

**Author:** ![Ravi342883](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravi342883/32/74643_2.png) [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Post date:** [April 7, 2021, 4:14pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/5 "2021-04-07T16:14:03Z")

</div>

Thank you for your response - @leandrojmp

I tried the first option - configuring additional TCP input on port 9001. But, no luck - still TG is in **unhealthy** state. Would you please have a look at my setup below?

**Filebeat Config:**  
#------------------------------ Udp input --------------------------------  
filebeat.inputs:

- type: udp  
enabled: true  
host: "localhost:53"  
max\_message\_size: 10KiB

#------------------------------ TCP input --------------------------------

- type: tcp  
enabled: true  
host: "localhost:9001"  
max\_connections: 0  
timeout: 300s

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

**Filebeat Startup Log:**  
2021-04-07T16:53:20.053+0100 INFO [crawler] beater/crawler.go:71 Loading Inputs: 3  
2021-04-07T16:53:20.053+0100 DEBUG [registrar] registrar/registrar.go:140 Starting Registrar  
2021-04-07T16:53:20.054+0100 INFO [crawler] beater/crawler.go:141 Starting input (ID: 10329058212159632590)  
2021-04-07T16:53:20.054+0100 INFO udp/input.go:99 Starting UDP input  
2021-04-07T16:53:20.054+0100 INFO [UDP] dgram/server.go:96 **Started listening for UDP connection**  
2021-04-07T16:53:20.054+0100 INFO [crawler] beater/crawler.go:141 Starting input (ID: 6776719849853723096)  
2021-04-07T16:53:20.054+0100 DEBUG [cfgfile] cfgfile/reload.go:132 Checking module configs from: /etc/filebeat/modules.d/\*.yml  
2021-04-07T16:53:20.054+0100 DEBUG [cfgfile] cfgfile/reload.go:146 Number of module configs found: 0  
2021-04-07T16:53:20.054+0100 INFO [crawler] beater/crawler.go:108 Loading and starting Inputs completed. Enabled inputs: 2  
2021-04-07T16:53:20.054+0100 INFO [input.tcp] tcp/input.go:106 Starting TCP input {"address": "localhost:9001"}  
2021-04-07T16:53:20.055+0100 INFO cfgfile/reload.go:164 Config reloader started  
2021-04-07T16:53:20.055+0100 DEBUG [cfgfile] cfgfile/reload.go:194 Scan for new config files  
2021-04-07T16:53:20.055+0100 DEBUG [cfgfile] cfgfile/reload.go:213 Number of module configs found: 0  
2021-04-07T16:53:20.055+0100 DEBUG [reload] cfgfile/list.go:63 Starting reload procedure, current runners: 0  
2021-04-07T16:53:20.055+0100 DEBUG [reload] cfgfile/list.go:81 Start list: 0, Stop list: 0  
2021-04-07T16:53:20.055+0100 INFO cfgfile/reload.go:224 Loading of config files completed.  
2021-04-07T16:53:20.055+0100 INFO [tcp] streaming/listener.go:73 **Started listening for TCP connection {"address": "localhost:9001"}**  
2021-04-07T16:53:30.055+0100 DEBUG [input] input/input.go:139 Run input

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

**Checked the listen port in unix:**  
[root@d1entesttlsr001 ~]# netstat -tulpn | grep LISTEN  
tcp 0 0 127.0.0.1:9001 0.0.0.0:\* LISTEN 24620/filebeat

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

**NLB Health check settings:**  
Protocol : TCP  
Port : 9001  
Status : unhealthy  
Status details : Health checks failed

Much appreciated your help.

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 7, 2021, 6:27pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/6 "2021-04-07T18:27:27Z")

</div>

You can't listen on only localhost, you need to change the host to `0.0.0.0:9001`, the same thing applies to your UDP input.

If you want to listen for connections from outside your machine, even from the same network, you can't use localhost as it will only listen to local requests. The NLB won't be able to talk to your filebeat if you are listening only on localhost.

This is not an Filebeat issue, it is an AWS issue, there is not much to do on the filebeat side.

---

<div class="post-metadata">

**Author:** ![Ravi342883](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravi342883/32/74643_2.png) [@Ravi342883](https://discuss.elastic.co/u/Ravi342883)\
**Post date:** [April 8, 2021, 2:46pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/7 "2021-04-08T14:46:40Z")

</div>

Thanks a lot @leandrojmp. It worked 🙂

I think, I have missed the basic on this - to 0.0.0.0 instead of localhost . Same applies for UDP as well.

**Summarizing the use-case here for the benefit of others:**  
Requirement:  
Network Devices(UDP) --\> AWS NLB --\> FileBeat --\> ES

Points to remember:

1. AWS NLB/TG cannot do health check over UDP.
2. Need to define a TCP input in Filebeat for this health check alone.

**FB config below:**  
#------------------------------ Udp input --------------------------------  
filebeat.inputs:

- type: udp  
enabled: true  
host: "0.0.0.0:53"  
max\_message\_size: 10KiB

#------------------------------ TCP input --------------------------------

- type: tcp  
enabled: true  
host: "0.0.0.0:9001"  
max\_connections: 0  
timeout: 300s

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^  
**Checked the listen port in unix:**  
[root@d1entesttlsr001 ~]# netstat -tulpn | grep LISTEN  
tcp6 0 0 :::9001 :::\* LISTEN 1449/filebeat

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^  
\*\* AWS NLB Health check settings:\*\*  
Protocol : TCP  
Port : 9001  
Status : healthy

Thank you once again.

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 4:47pm UTC](https://discuss.elastic.co/t/aws-nlb-config-infront-of-filebeats-instance/269065/8 "2021-05-06T16:47:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
