# Filebeat container is starting listening UDP need to change to TCP

**URL:** <https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [November 15, 2018, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908 "2018-11-15T16:48:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ranjith\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranjith_m/32/19272_2.png) [@Ranjith\_M](https://discuss.elastic.co/u/Ranjith_M)\
**Post date:** [November 15, 2018, 4:48pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/1 "2018-11-15T16:48:19Z")

</div>

Filebeat Version : 6.5

We need to know how can configure the haproxy module for filebeat . Currently the filebeat container is starting listening UDP connections in localhost:9001, we need to know how change the protocol and the address throuth module configuration. The desired configuration should be {"protocol": "tcp"} and connection {"address": ":9001"}.

Below a trace for container start.

2018-11-15T16:12:47.540Z DEBUG [cfgfile] cfgfile/reload.go:176 Scan for new config files  
2018-11-15T16:12:47.541Z DEBUG [cfgfile] cfgfile/cfgfile.go:177 Load config from file: /usr/share/filebeat/modules.d/haproxy.yml  
2018-11-15T16:12:47.541Z DEBUG [cfgfile] cfgfile/reload.go:195 Number of module configs found: 1  
2018-11-15T16:12:47.541Z DEBUG [reload] cfgfile/list.go:62 Starting reload procedure, current runners: 0  
2018-11-15T16:12:47.541Z DEBUG [reload] cfgfile/list.go:80 Start list: 1, Stop list: 0  
2018-11-15T16:12:47.541Z WARN [cfgwarn] syslog/input.go:111 EXPERIMENTAL: Syslog input type is used  
2018-11-15T16:12:47.541Z DEBUG [processors] processors/processor.go:66 Processors:  
2018-11-15T16:12:47.541Z DEBUG [reload] cfgfile/list.go:101 Starting runner: haproxy (log)  
2018-11-15T16:12:47.541Z INFO input/input.go:114 Starting input of type: syslog; ID: 14175615836827865463  
2018-11-15T16:12:47.541Z INFO cfgfile/reload.go:205 Loading of config files completed.  
2018-11-15T16:12:47.541Z INFO [syslog] syslog/input.go:173 Starting Syslog input {"protocol": "udp"}  
2018-11-15T16:12:47.545Z INFO [udp] udp/server.go:66 Started listening for UDP connection {"address": "localhost:9001"}

**Configuration File**

filebeat.yml:  
filebeat.config:  
inputs:  
path: {path.config}/inputs.d/\*.yml reload.enabled: false modules: path: {path.config}/modules.d/\*.yml  
reload.enabled: false

```
output.kafka:
  hosts: ["XXXXXXXXXXXXXXXXXXXXXXXX"]
  topic: 'XXXXXXXXXXX'
  partition.round_robin:
    reachable_only: false

  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000
  version: '0.10.2'

logging.level: debug

```

* * *

```auto
  haproxy.yml: |-
    - module: haproxy
      log:
        enabled: true

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2018, 1:13pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/2 "2018-11-16T13:13:14Z")

</div>

You can try to use the module `input` configuration to disable the udp input and enable tcp:

```auto
- module: haproxy
  log.enabled: true
  input:
    protocol.udp.enabled: false
    protocol.tcp.host: "localhost:9001"

```

---

<div class="post-metadata">

**Author:** ![xhottam](https://avatars.discourse-cdn.com/v4/letter/x/b9bd4f/32.png) [@xhottam](https://discuss.elastic.co/u/xhottam)\
**Post date:** [November 19, 2018, 12:39pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/3 "2018-11-19T12:39:49Z")

</div>

With this configuration :

2018-11-19T12:31:31.412Z ERROR instance/beat.go:824 Exiting: Fileset haproxy/input is configured but doesn't exist

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 19, 2018, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/4 "2018-11-19T15:13:29Z")

</div>

There is an error in the sample config. This should work:

```auto
- module: haproxy
  log:
    enabled: true
    input:
      protocol.udp.enabled: false
      protocol.tcp.host: "localhost:9001"

```

---

<div class="post-metadata">

**Author:** ![xhottam](https://avatars.discourse-cdn.com/v4/letter/x/b9bd4f/32.png) [@xhottam](https://discuss.elastic.co/u/xhottam)\
**Post date:** [November 20, 2018, 10:49am UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/5 "2018-11-20T10:49:41Z")

</div>

Thanks for you support, currently with the last format conf is working but :

- We have set configure "option httplog" in haproxy's side but the events are being sent without any format. In metadata struct in pipeline field you can see filebeat-6.5.0-haproxy-log-pipeline, but no any format comes. The fileset is empty, only in message field have the access log.
- Have filebeat haproxy's module any requirement about Haproxy's version?

"@timestamp": "2018-11-20T10:47:06.000Z",  
"@metadata": {  
"beat": "filebeat",  
"type": "doc",  
"version": "6.5.0",  
"truncated": false,  
"pipeline": "filebeat-6.5.0-haproxy-log-pipeline"  
},  
"source": "127.0.0.1:43424",  
"process": {},  
"fileset": {  
"name": "log",  
"module": "haproxy"  
},  
"prospector": {  
"type": "syslog"  
},  
"input": {  
"type": "syslog"  
},  
"beat": {  
"name": "XXXXXXXXXXXXXXXXXX",  
"hostname": "XXXXXXXXXXXXXXXX",  
"version": "6.5.0"  
},  
"host": {  
"name": "XXXXXXXXXXXXXXXXXX"  
},  
"message": "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX",  
"syslog": {  
"priority": 142,  
"severity\_label": "Informational",  
"facility": 17,  
"facility\_label": "local1"  
},  
"event": {  
"severity": 6  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 12:49pm UTC](https://discuss.elastic.co/t/filebeat-container-is-starting-listening-udp-need-to-change-to-tcp/156908/6 "2018-12-18T12:49:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
