# Could not retrieve remote IP address for beats input

**URL:** https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815
**Category:** Logstash
**Created:** [October 22, 2017, 6:36pm UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815 "2017-10-22T18:36:13Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 22, 2017, 6:36pm UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/1 "2017-10-22T18:36:13Z")

</div>

"Could not retrieve remote IP address for beats input."

> <https://github.com/logstash-plugins/logstash-input-beats/blob/master/lib/logstash/inputs/beats/message_listener.rb#L34>

I see this warning regularly. (even though the comment says it should never happen)

My setup is 6.0.0-rc1  
beats are running on a remote server in docker containers.

ELK stack is deployed with this docker-compose repo:  
[decomposed/elk](https://github.com/dcomposed/elk)  
It uses the official elastic docker images.

Any advice how to troubleshoot this error message?

---

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 23, 2017, 3:47pm UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/2 "2017-10-23T15:47:36Z")

</div>

More details:  
In bursts of less than 0.1 seconds, I get around 30 of these errors:

[2017-10-23T14:59:17,540][WARN][logstash.inputs.beats] Could not retrieve remote IP address for beats input.  
... 30 more...  
[2017-10-23T14:59:17,549][WARN][logstash.inputs.beats] Could not retrieve remote IP address for beats input.

There are 3 events that were stashed at 14:59:17.019 - one ajax request (got a 200) and two gitlab runner requests (got 204s) All three have remote\_ip fields with valid ips (one is a 172 address from another docker container on the same box)

Again I ask for help to troubleshoot/investigate, as the error does not explicitly tie itself to a specific request...

---

<div class="post-metadata">

### Author: ![rzr\_mallox](https://avatars.discourse-cdn.com/v4/letter/r/df705f/32.png) [@rzr\_mallox](https://discuss.elastic.co/u/rzr_mallox)
#### Post date: [November 16, 2017, 12:50am UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/3 "2017-11-16T00:50:44Z")

</div>

After updating to version 6 of the ELK stack I've had similar issues, along with documents not being able to be indexed because they have 2 document types (this seems to be related to old plugins not having been properly updated).

Have you found any fix for this?

---

<div class="post-metadata">

### Author: ![lcorsini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcorsini/32/19170_2.png) [@lcorsini](https://discuss.elastic.co/u/lcorsini)
#### Post date: [November 16, 2017, 12:42pm UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/4 "2017-11-16T12:42:13Z")

</div>

Both errors happen for me too

```
[2017-11-16T13:38:41,327][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"filebeat-2017.11.15", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3f81832e>], :response=>{"index"=>{"_index"=>"filebeat-2017.11.15", "_type"=>"doc", "_id"=>"uH7WxF8BDa1ley8Gmc9y", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"Rejecting mapping update to [filebeat-2017.11.15] as the final mapping would have more than 1 type: [log, doc]"}}}}
[2017-11-16T13:38:41,328][WARN][logstash.inputs.beats] Could not retrieve remote IP address for beats input.
```

---

<div class="post-metadata">

### Author: ![Hush077](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hush077/32/22500_2.png) [@Hush077](https://discuss.elastic.co/u/Hush077)
#### Post date: [November 17, 2017, 1:40am UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/5 "2017-11-17T01:40:57Z")

</div>

Same issue opened a ticket here: [https://github.com/logstash-plugins/logstash-input-beats/issues/269](https://github.com/logstash-plugins/logstash-input-beats/issues/269)

---

<div class="post-metadata">

### Author: ![Hush077](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hush077/32/22500_2.png) [@Hush077](https://discuss.elastic.co/u/Hush077)
#### Post date: [November 17, 2017, 2:43am UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/6 "2017-11-17T02:43:23Z")

</div>

> [@gotjoshua](#):
>
> begin  
> hash.get("@metadata").put("ip\_address", ctx.channel().remoteAddress().getAddress().getHostAddress())  
> rescue #should never happen, but don't allow an error here to stop beats input  
> input.logger.warn("Could not retrieve remote IP address for beats input.")  
> end

Going to: vim /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-beats-5.0.2-java/lib/logstash/inputs/beats/message\_listener.rb

And deleting:

```auto
begin
    hash.get("@metadata").put("ip_address", ctx.channel().remoteAddress().getAddress().getHostAddress())
  rescue #should never happen, but don't allow an error here to stop beats input
    input.logger.warn("Could not retrieve remote IP address for beats input.")
end

```

Fixes the issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 15, 2017, 2:43am UTC](https://discuss.elastic.co/t/could-not-retrieve-remote-ip-address-for-beats-input/104815/7 "2017-12-15T02:43:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
