# Elastic Agent with Synthetics Integration- Adding TCP monitor break the Agent

**URL:** https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651
**Category:** Beats
**Tags:** heartbeat, elastic-agent
**Created:** [August 6, 2021, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651 "2021-08-06T13:44:29Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [August 6, 2021, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/1 "2021-08-06T13:44:29Z")

</div>

Hi All,

I have an Elastic Agent Installed with synthetic integration (heartbeat). Adding HTTP and ICMP monitors work fine but when I tried adding a TCP monitor with the correct host:port format the agent become unhealthy and the log shows the following error.

Is there any bug or known issues for the TCP monitor?

```auto
15:31:14.621 elastic_agent [elastic_agent][error] Elastic Agent status changed to: 'error'
15:31:14.622 elastic_agent [elastic_agent][error] 2021-08-06T15:31:14+02:00 - message: Application: filebeat--7.14.0[bd9f0a02-8c71-46b2-bd05-b049b05c5913]: State changed to FAILED: 1 error occurred:
	* 1 error: Error creating runner from config: need to specify the host using the `host:port` syntax accessing config

 - type: 'ERROR' - sub_type: 'FAILED'

```

Thank you.

Regards,  
Nugroho

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 9, 2021, 7:26am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/2 "2021-08-09T07:26:05Z")

</div>

Can you share the config that you used? Also can you share the heartbeat logs? You should find them under `data/elastic-agent-*/....`?

---

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [August 9, 2021, 10:05am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/3 "2021-08-09T10:05:06Z")

</div>

Hi @ruflin ,

The heartbeat does not have any error, the monitor works and I can see the result in Uptime app.

Only the Elastic Agent is unhealthy, performs multiple restart (Restart loop) and the filebeat-json.log contains the following error:

/opt/Elastic/Agent/data/elastic-agent-e127fc/logs/default/filebeat-json.log

```auto
{"log.level":"info","@timestamp":"2021-08-09T09:56:14.060Z","log.logger":"centralmgmt.fleet","log.origin":{"file.name":"management/manager.go","file.line":236},"message":"Applying settings for filebeat.modules","service.name":"filebeat","event.dataset":"filebeat-json.log","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2021-08-09T09:56:14.060Z","log.logger":"centralmgmt.fleet","log.origin":{"file.name":"management/manager.go","file.line":137},"message":"Status change to Failed: 1 error occurred:\n\t* 1 error: Error creating runner from config: need to specify the host using the `host:port` syntax accessing config\n\n","service.name":"filebeat","event.dataset":"filebeat-json.log","ecs.version":"1.6.0"}

```

```auto
12:01:40.553
elastic_agent
devops-test
[elastic_agent][error] 2021-08-09T10:01:40Z - message: Application: filebeat--7.14.0[9b863173-44e3-4e22-bf24-0e4b5d845521]: State changed to FAILED: 1 error occurred:
	* 1 error: Error creating runner from config: need to specify the host using the `host:port` syntax accessing config

 - type: 'ERROR' - sub_type: 'FAILED'
12:01:50.556
elastic_agent
devops-test
[elastic_agent][info] 2021-08-09T10:01:50Z - message: Application: filebeat--7.14.0[9b863173-44e3-4e22-bf24-0e4b5d845521]: State changed to RESTARTING: - type: 'STATE' - sub_type: 'STARTING'

```

This issue does not happen for HTTP monitor.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 9, 2021, 11:04am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/4 "2021-08-09T11:04:12Z")

</div>

Hi, sorry I missed that the errors logs come from filebeat. Any chance you could share the full policy (copy it from the Fleet UI in the yaml format)? It seems odd that filebeat is involved in this in the first place (assuming there are no filebeat inputs) so I assume something goes wrong there. I have one suspicion and will do some testing locally.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 9, 2021, 11:21am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/5 "2021-08-09T11:21:06Z")

</div>

I can also reproduce this locally. I'm suspecting that something with the routing of the `synthetics/tcp` input type goes wrong.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [August 9, 2021, 11:24am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/6 "2021-08-09T11:24:56Z")

</div>

I filed [[Elastic Agent] Adding synthetics/tcp input does not work · Issue #27277 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/27277) so we can follow up and track it.

---

<div class="post-metadata">

### Author: ![nugroho-expereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugroho-expereo/32/78333_2.png) [@nugroho-expereo](https://discuss.elastic.co/u/nugroho-expereo)
#### Post date: [August 9, 2021, 11:31am UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/7 "2021-08-09T11:31:50Z")

</div>

Thank you @ruflin. I will follow the Github issue.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 6, 2021, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-with-synthetics-integration-adding-tcp-monitor-break-the-agent/280651/8 "2021-09-06T13:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
