# Failed to connect to backoff(elasticsearch(http://172.18.158.52:9200))

**URL:** https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433
**Category:** Beats
**Tags:** filebeat
**Created:** [April 15, 2024, 1:15pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433 "2024-04-15T13:15:05Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Chadi\_SHWADA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chadi_shwada/32/133224_2.png) [@Chadi\_SHWADA](https://discuss.elastic.co/u/Chadi_SHWADA)
#### Post date: [April 15, 2024, 1:15pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/1 "2024-04-15T13:15:05Z")

</div>

I currently have two servers which are as follows:

172.18.158.52 where I installed elasticsearch and kibana  
172.18.158.49 where I installed filebeat

Filebeat is able to recover the data except that I have this error in the logs:

```auto
{"log.level":"error","@timestamp":"2024-04-15T15:01:26.190+0200","log.logger":"publisher_pipeline_output","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/publisher/pipeline.(*netClientWorker).run","file.name":"pipeline/client_worker.go","file.line":148},"message":"Failed to connect to backoff(elasticsearch(http://172.18.158.52:9200)): Get \"http://172.18.158.52:9200\": EOF","service.name":"filebeat","ecs.version":"1.6.0"

```

Can you help me please

---

<div class="post-metadata">

### Author: ![Chadi\_SHWADA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chadi_shwada/32/133224_2.png) [@Chadi\_SHWADA](https://discuss.elastic.co/u/Chadi_SHWADA)
#### Post date: [April 16, 2024, 12:53pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/2 "2024-04-16T12:53:40Z")

</div>

After this error, I have this line right after

```auto
{"log.level":"info","@timestamp":"2024-04-16T14:51:39.285+0200","log.logger":"publisher_pipeline_output","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/publisher/pipeline.(*netClientWorker).run","file.name":"pipeline/client_worker.go","file.line":139},"message":"Attempting to reconnect to backoff(elasticsearch(http://172.18.158.52:9200)) with 249 reconnect attempt(s)","service.name":"filebeat","ecs.version":"1.6.0"}

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 16, 2024, 1:22pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/3 "2024-04-16T13:22:16Z")

</div>

This error means that your filebeat **cannot** connect to Elasticsearch.

Is your Elasticsearch using http or https? If it is using https, then you need to change your filebeat configuration to use https as well.

If it is using http, then you may have a network issue that you need to troubleshoot and solve before using filebeat and elasticsearch.

---

<div class="post-metadata">

### Author: ![Chadi\_SHWADA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chadi_shwada/32/133224_2.png) [@Chadi\_SHWADA](https://discuss.elastic.co/u/Chadi_SHWADA)
#### Post date: [April 16, 2024, 1:28pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/4 "2024-04-16T13:28:48Z")

</div>

Thank you Leandro for your response.

If I want to see if Elasticsearch works on the browser, I have to put [https://172.18.158.52:9200](https://172.18.158.52:9200) and it works.

If I want to access Kibana, I have to put [http://172.18.158.52:5601](http://172.18.158.52:5601) and it works.

In my filebeat.yml file I activated the "https" protocol. I restarted filebeat and now I have this error in the logs:

```auto
{"log.level":"error","@timestamp":"2024-04-16T15:26:38.952+0200","log.logger":"esclientleg","log.origin":{"function":"github.com/elastic/elastic-agent-libs/transport/httpcommon.(*HTTPTransportSettings).RoundTripper.LoggingDialer.func2","file.name":"transport/logging.go","file.line":38},"message":"Error dialing x509: certificate signed by unknown authority","service.name":"filebeat","network":"tcp","address":"172.18.158.52:9200","ecs.version":"1.6.0"}

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 16, 2024, 1:37pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/5 "2024-04-16T13:37:58Z")

</div>

> [@Chadi\_SHWADA](#):
>
> I restarted filebeat and now I have this error in the logs

You need to configure SSL in Filebeat as well, check the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#configuration-ssl).

---

<div class="post-metadata">

### Author: ![Chadi\_SHWADA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chadi_shwada/32/133224_2.png) [@Chadi\_SHWADA](https://discuss.elastic.co/u/Chadi_SHWADA)
#### Post date: [April 17, 2024, 11:59am UTC](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-172-18-158-52-9200/357433/6 "2024-04-17T11:59:21Z")

</div>

Thank you so much Leandro for your help. All it's working now.
