# Filebeat 5.6.16 modifies logstash URL:PORT in runtime

**URL:** <https://discuss.elastic.co/t/filebeat-5-6-16-modifies-logstash-url-port-in-runtime/178663>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 26, 2019, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-5-6-16-modifies-logstash-url-port-in-runtime/178663 "2019-04-26T14:32:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [April 26, 2019, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-5-6-16-modifies-logstash-url-port-in-runtime/178663/1 "2019-04-26T14:32:57Z")

</div>

Hi  
I am running filebeat 5.6.16 on Ubuntu 18.04 x64

Here is my filebeat output section configuration:  
output.logstash:

> Blockquote  
> hosts: ["[glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904](http://glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904)"]  
> bulk\_max\_size: 10000

When I start the filebeat i see that it can not ship log files to logstash, and see the following in debug mode:

> Blockquote  
> 2019/04/26 14:20:12.147710 sync.go:96: DBG 0 events out of 9996 events sent to logstash host glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904:10200. Continue sending  
> 2019/04/26 14:20:12.147726 sync.go:63: DBG close connection to logstash host glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904:10200  
> 2019/04/26 14:20:12.147739 sync.go:105: ERR Failed to publish events (host: glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904:10200), caused by: EOF  
> 2019/04/26 14:20:12.147752 single.go:91: INFO Error publishing events (retrying): EOF  
> 2019/04/26 14:20:12.147763 sync.go:63: DBG close connection to logstash host glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904:10200  
> 2019/04/26 14:20:12.147773 single.go:156: DBG send fail  
> 2019/04/26 14:20:13.147995 sync.go:58: DBG connect to logstash host glog-tcp-1480968407.us-east-1.elb.amazonaws.com:12904:10200

Where does it take "10200" to add after port number and why it happens ?  
The same behaviour inspected when running in docker.

Have to say that the same configuration worked fine with filebeat 1.3.1

Would be glad to get some assistance

---

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [April 26, 2019, 9:18pm UTC](https://discuss.elastic.co/t/filebeat-5-6-16-modifies-logstash-url-port-in-runtime/178663/2 "2019-04-26T21:18:14Z")

</div>

I have found where was the problem. I was trying to send events to previous generation Elastic load balancer on AWS, and for some reason its behavior was non predictable. As a troubleshooting I have defined first all elastic ips of log aggregators to use them in round robin manner in filebeat configuration file, and it worked fine. Next step i have created new generation network load balancer to handle TCP:12904 traffic and it also worked fine.  
Issue can be closed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2019, 9:18pm UTC](https://discuss.elastic.co/t/filebeat-5-6-16-modifies-logstash-url-port-in-runtime/178663/3 "2019-05-24T21:18:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
