# Docker Filebeat can't connect to Docker bridge network despite ELK being able to

**URL:** <https://discuss.elastic.co/t/docker-filebeat-cant-connect-to-docker-bridge-network-despite-elk-being-able-to/146408>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 28, 2018, 5:59pm UTC](https://discuss.elastic.co/t/docker-filebeat-cant-connect-to-docker-bridge-network-despite-elk-being-able-to/146408 "2018-08-28T17:59:32Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![shirakaba](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@shirakaba](https://discuss.elastic.co/u/shirakaba)\
**Post date:** [August 29, 2018, 8:57am UTC](https://discuss.elastic.co/t/docker-filebeat-cant-connect-to-docker-bridge-network-despite-elk-being-able-to/146408/3 "2018-08-29T08:57:08Z")

</div>

> Are you sure about the elasticsearch endpoint?

I guess not. I think I may have inherited the `elk:<port>` idea from somewhere, but looking back, it appears that on macOS, I was using a feature that doesn't exist on Linux (as far as I understand), `host.docker.internal`:

```auto
output.elasticsearch.hosts: ['host.docker.internal:9200']
setup.kibana.host: "host.docker.internal:5601"

```

> Have your tried run the container or image on the same network and ping the different hosts.

They are all on the same `elk` network, but my issue I suppose is not knowing the endpoint to ping.

... However, your suggestion worked!

I shall note that `nslookup` wasn't installed in my container, so I wasn't able to get visibility of hostnames, but that was no problem. Reconfiguring `filebeat.yml` as you recommended did the trick:

```auto
output.elasticsearch.hosts: ['http://elasticsearch:9200']
setup.kibana.host: http://kibana:5601

```

The startup logs looked like this ("Elasticsearch url" seems to simply echo whatever was configured in `output.elasticsearch.hosts`, as last time it said "[http://elk:9200](http://elk:9200)"):

```auto
filebeat_1 | 2018-08-29T08:40:15.640Z	INFO	elasticsearch/client.go:145	Elasticsearch url: http://elasticsearch:9200
...
filebeat_1 | 2018-08-29T08:40:18.901Z	INFO	elasticsearch/client.go:690	Connected to Elasticsearch version 6.3.2

```

Once running `bash` inside the filebeat container, trying either of the following curls gave a HTTP status 200 and returned a body:

```auto
curl http://elasticsearch:9200
curl http://kibana:5601

```

Thank you very much! Quality support again from the Elastic Team.

---

_[View the full topic](https://discuss.elastic.co/t/docker-filebeat-cant-connect-to-docker-bridge-network-despite-elk-being-able-to/146408)._
