# Filebeat - Kafka output via proxy

**URL:** <https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 18, 2025, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077 "2025-03-18T13:58:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tajriis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tajriis/32/140619_2.png) [@Tajriis](https://discuss.elastic.co/u/Tajriis)\
**Post date:** [March 18, 2025, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/1 "2025-03-18T13:58:06Z")

</div>

Hello,  
Im collecting logs via filebeat and send them to kafka which is on cloud.  
I need a proxy for my server to reach the kafka output.  
Is it possible ?  
There is nothing in the documentation regarding kafka output and proxy.  
I tried proxy\_url: ´[http://ip](http://ip):port´ but filebeat does not even try to use proxy.

Could anyone help please ?

Thanks

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 18, 2025, 7:35pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/2 "2025-03-18T19:35:23Z")

</div>

Not expert on filebeat at all, but I see nothing in the filebeat documentation that makes it clear that the kafka output supports a proxy. The docs are explicit for (eg) filebeat's elasticsearch output (via proxy\_url).

And, e.g. logstash's Kafka output explicitly does _not_ support a proxy, as set out in its documentation.

That's at least a little suggestive that you might be unlucky here.

> **[Kafka output plugin | Logstash Reference \[8.17\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-kafka.html)**

> **[Configure the Kafka output | Filebeat Reference \[8.17\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/kafka-output.html)**

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 19, 2025, 12:13am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/3 "2025-03-19T00:13:53Z")

</div>

Kafka does not use HTTP, so you cannot use an HTTP proxy in front of Kafka.

> [@Tajriis](#):
>
> I need a proxy for my server to reach the kafka output.  
> Is it possible ?

Can you provide more context on this? Where is your Kafka is running? It is not clear why you need a proxy if Kafka does not use HTTP.

---

<div class="post-metadata">

**Author:** ![Tajriis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tajriis/32/140619_2.png) [@Tajriis](https://discuss.elastic.co/u/Tajriis)\
**Post date:** [March 19, 2025, 7:43am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/4 "2025-03-19T07:43:57Z")

</div>

Thanks for the answers.  
Kafka output is in azure confluence cloud.  
The server running filebeat does not have direct access to the internet. We can add firewall rules to reach the kafka server (this works), but the logs are not published because it needs to communicate with other kafka brokers as well. We added rules for these brokers as well, logs of some kafka topics started to be published, but not all, since there were other brokers in use that we were not aware of. We are worried that from time to time more brokers may come / something may change and the connection will not work again. That is why we came up with a proxy that will reach all brokers - our HTTP proxy.  
In the meantime, I did some more research and as you said, it cannot be used for Kafka. However, I found Kafka proxy. According to some documentation I read, this is exactly what we need.  
One of the situations where this can help is - _Network topologies preventing direct access to broker nodes_

Don't you know if it could really solve our issue ?  
Thanks

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 19, 2025, 8:31am UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/5 "2025-03-19T08:31:36Z")

</div>

This isn't really an elastic stack / filebeat question now (that was answered).

It's more to do with your own topology, network setup, and dynamics of your environment/organisation.

> [@Tajriis](#):
>
> However, I found Kafka proxy. According to some documentation I read, this is exactly what we need.

That's pretty imprecise, but anyways relates to _some documentation_ about some other, unspecified, third party tool ?

Personally speaking, when I read

> [@Tajriis](#):
>
> We added rules for these brokers as well, logs of some kafka topics started to be published, but not all, since there were other brokers in use that we were not aware of  
> ...  
> We are worried that from time to time more brokers may come / something may change and the connection will not work again

then I'd consider that as a communication issue within your organization/partners. If your fear is that something will be changed that impacts you, but such changes are outwith your knowledge and control, there is no technical solution that can absolutely protect you from problems that might create.

---

<div class="post-metadata">

**Author:** ![Tajriis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tajriis/32/140619_2.png) [@Tajriis](https://discuss.elastic.co/u/Tajriis)\
**Post date:** [March 19, 2025, 12:21pm UTC](https://discuss.elastic.co/t/filebeat-kafka-output-via-proxy/376077/6 "2025-03-19T12:21:48Z")

</div>

Yes, it is a third party too. There seems to be more "Kafka proxies", one for example is from Confluent. Nevertheless as you said, it is outside the scope of elastic/filebeat.

Yes, the communication is the main issue here, there are many middlemen without enough information, therefore the best solution is to have something like a proxy that can possibly connect to all the brokers on port 9092 without needing to know their IPs.

I found the answer that HTTP proxy cannot be used. I will search for some other solution.

Thanks for your time
