# "\_cat/nodes" API reports "transport" IP instead of "http" IP

**URL:** <https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166>\
**Category:** Elasticsearch\
**Created:** [May 11, 2023, 7:36am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166 "2023-05-11T07:36:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeremy\_Lecour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_lecour/32/1416_2.png) [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Post date:** [May 11, 2023, 7:36am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166/1 "2023-05-11T07:36:46Z")

</div>

Hi,

I have a 2-nodes cluster with this setup for the networking configuration :

```auto
http.host: [_local_,_ens192_]
http.port: 9200

transport.host: [_ens161_]
transport.port: 9300

```

And here is my network setup :

```auto
# ip -br a
lo UNKNOWN 127.0.0.1/8
ens161 UP 172.19.4.230/24
ens192 UP 172.19.3.230/24

```

When I query the CAT API for nodes I get this :

```auto
# curl "http://172.19.3.230:9200/_cat/nodes"
172.19.4.231 38 96 2 0.00 0.01 0.00 cdfhilmrstw - host01
172.19.4.230 19 97 3 0.01 0.08 0.08 cdfhilmrstw * host00

```

The reported IP addresses are for the "transport" network and not the "http" network.  
It seems weird since the API is mostly used to understand the state of the cluster and it prevents sniffing for clients or monitoring.

Is it normal?  
Is there a way to change this?

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 11, 2023, 9:30am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166/2 "2023-05-11T09:30:59Z")

</div>

You can select the columns you want to display. See [cat nodes API | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/cat-nodes.html#cat-nodes-api-query-params)

So here, use `http`:

```
curl "http://172.19.3.230:9200/_cat/nodes?v&h=n,http"

```

---

<div class="post-metadata">

**Author:** ![Jeremy\_Lecour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_lecour/32/1416_2.png) [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Post date:** [May 11, 2023, 10:40am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166/3 "2023-05-11T10:40:38Z")

</div>

Thank you David for the solution.  
Sorry for not noticing this myself in the docs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2023, 10:41am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166/4 "2023-06-08T10:41:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
