# Bind Metricbeats to specific ip address

**URL:** <https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 30, 2019, 7:05am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273 "2019-01-30T07:05:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![cdroescher](https://avatars.discourse-cdn.com/v4/letter/c/67e7ee/32.png) [@cdroescher](https://discuss.elastic.co/u/cdroescher)\
**Post date:** [January 30, 2019, 7:05am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/1 "2019-01-30T07:05:55Z")

</div>

Hi everyone,

I want to bind Metricbeats to a specific IP-address. Is there a way to do so?  
For a Elasticsearch node I am able to set it in /etc/elasticsearch/elasticsearch.yml but for Metricbeats I am missing a setting like this.

**elasticsearch.yml** :  
...  
---------------------------------- Network -----------------------------------

Set the bind address to a specific IP (IPv4 or IPv6):

**network.host: 0.0.0.0**  
...

Your help is highly appreciated!

Thanks and regards,  
Chris

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 30, 2019, 7:18am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/2 "2019-01-30T07:18:19Z")

</div>

Do you mean for when it sends data to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![cdroescher](https://avatars.discourse-cdn.com/v4/letter/c/67e7ee/32.png) [@cdroescher](https://discuss.elastic.co/u/cdroescher)\
**Post date:** [January 30, 2019, 7:41am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/3 "2019-01-30T07:41:23Z")

</div>

Hi Mark,

yes, we want to send to ES-nodes. We have multiple network interfaces on the machine where Metricbeats is running. And just a particular one can reach the Elasticsearch node.

To communicate via curl from the machine where the Metricbeats is installed to the ES node it would be for instance work with:  
curl --interface **10.30.150.32** -XGET [http://10.30.134.155:9200/\_cat/indices](http://10.30.134.155:9200/_cat/indices)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 30, 2019, 7:42am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/4 "2019-01-30T07:42:16Z")

</div>

I don't think you will need to worry. The OS will just pick the interface it needs to send to that IP.

---

<div class="post-metadata">

**Author:** ![cdroescher](https://avatars.discourse-cdn.com/v4/letter/c/67e7ee/32.png) [@cdroescher](https://discuss.elastic.co/u/cdroescher)\
**Post date:** [January 30, 2019, 7:49am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/5 "2019-01-30T07:49:13Z")

</div>

The Problem is that the connection will work in case if the interface could be specified like in the curl command. If I use curl without "--interface" parameter the connection will not work. I think that's why Metricbeats is currently not able to connect to that particular ES-node. I am missing the setting in the metricbeats.yml " **network.host**" to bind the Metricbeats-process to a specific IPv4 address on the server.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 30, 2019, 7:52am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/6 "2019-01-30T07:52:33Z")

</div>

That's kind of odd. It's been a while since I have looked at this sort of problem but surely the OS should be handling routing so this isn't necessary?

---

<div class="post-metadata">

**Author:** ![lpotensky](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@lpotensky](https://discuss.elastic.co/u/lpotensky)\
**Post date:** [January 30, 2019, 8:36am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/7 "2019-01-30T08:36:40Z")

</div>

Hi Mark, let me drop some more info here. Imagine that you have a host you like to monitor using Metricbeat. There are 3 network interfaces on that host with following IP addresses - 10.30.146.32, 10.30.150.32, 10.30.154.32. The default route configured through interface having IP 10.30.146.32. But the desired IP address for Metricbeat to send data to Elasticsearch is 10.30.150.32.

So in general if you try to open TCP connection and you define only the remote (destination/server's) IP address and the remote port the OS will automatically pick a "suitable" local (source/client's) IP address and a random local unused port to bind to.

But there is a possibility to specify the local (source/client's) IP address and the local port to bind to when opening TCP connection. The Metricbeat does not support such configuration option.

---

<div class="post-metadata">

**Author:** ![lpotensky](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@lpotensky](https://discuss.elastic.co/u/lpotensky)\
**Post date:** [January 30, 2019, 9:07am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/8 "2019-01-30T09:07:24Z")

</div>

I had a quick look into beats source code and the idea would be to use

`net.Dialer{Timeout: timeout, LocalAddr: localAddr}`

to specify a local bind address.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2019, 9:07am UTC](https://discuss.elastic.co/t/bind-metricbeats-to-specific-ip-address/166273/9 "2019-02-27T09:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
