# Filebeat not sending logs to multiple hosts specified in \[output.elasticsearch:\] section

**URL:** <https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097>\
**Category:** Beats\
**Created:** [March 29, 2018, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097 "2018-03-29T13:39:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AVM](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@AVM](https://discuss.elastic.co/u/AVM)\
**Post date:** [March 29, 2018, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/1 "2018-03-29T13:39:15Z")

</div>

Hi Team,  
I have a cluster with 3 nodes. All nodes are master and data eligible nodes. One of them is configured for kibana in kibana.yml (in [elasticsearch.url] section). I am using filebeat to send logs directly to elasticsearch. When all nodes are up and running, logs received properly and cluster health is green.

I have configured filebeat to send data to multiple elasticsearch hosts.  
output.elasticsearch:

# Array of hosts to connect to.

hosts: ["172.16.4.11:9200","172.16.4.12:9200","172.16.4.19:9200"]  
protocol: "https"  
and in kibana.yml - elasticsearch.url: "[http://172.16.4.19:9200](http://172.16.4.19:9200)"

But the problem is when first node 172.16.4.11 is down then filebeat doesn't send logs to other two nodes. When 172.16.4.11 is again up then all logs are received. Why logs are not getting received when first node is down? When 172.16.4.12 is down and other two are up then it is working. I want filebeat to send logs to one of the other two nodes when 172.16.4.11 is not running. Please help me to solve this issue.

I have set discovery.zen.minimum\_master\_nodes to 2 in elasticsearch.yml. So, when one of them will be down then cluster will work properly.

Elasticsearch - version 6.2.2  
Kibana - version 6.2.2  
Filebeat - version 6.2.2  
OS - Ubuntu 16.04 and CentOS 6.6

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 29, 2018, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/2 "2018-03-29T14:50:30Z")

</div>

Have you checked Elasticsearch and Filebeat logs?

e.g. is filebeat sending, but getting errors from the other two hosts?

---

<div class="post-metadata">

**Author:** ![AVM](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@AVM](https://discuss.elastic.co/u/AVM)\
**Post date:** [March 29, 2018, 5:57pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/3 "2018-03-29T17:57:38Z")

</div>

In Elasticsearch logs, I got this  
[Node1]--\> 172.16.4.12

[WARN][o.e.c.a.s.ShardStateAction] [Node1] [filebeat-6.2.2-2018.03.29][0] received shard failed for shard id [[filebeat-6.2.2-2018.03.29][0]], allocation id [EPFzVuq8TKGswCiryn1KTg], primary term [18], message [mark copy as stale]  
[WARN][o.e.c.a.s.ShardStateAction] [Node1] [filebeat-6.2.2-2018.03.29][2] received shard failed for shard id [[filebeat-6.2.2-2018.03.29][2]], allocation id [EBpijFXORy-YpgxOmXZMJg], primary term [17], message [mark copy as stale]  
[WARN][o.e.c.a.s.ShardStateAction] [Node1] [filebeat-6.2.2-2018.03.29][1] received shard failed for shard id [[filebeat-6.2.2-2018.03.29][1]], allocation id [NV9iYF1BRq6a9Xi3t1vk8g], primary term [16], message [mark copy as stale]  
[INFO][o.e.c.r.a.AllocationService] [Node1] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[slog][2], [slog][3], [slog][0]] ...]).  
[INFO][o.e.c.r.a.AllocationService] [Node1] Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[slog][3]] ...]).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 29, 2018, 7:19pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/4 "2018-03-29T19:19:13Z")

</div>

There might be more errors in ES about the cluster going RED. Seems the issue is due to some shards not being available due to missing replication or replicated shards being handled by same node.

If the first node is down you get a `RED` status when querying the [cluster health](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html). If so, you have some shards having no primary shard assigned right now.

The [Index Shard Stores API](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/indices-shards-stores.html#indices-shards-stores) might help you getting an overview of your current shards usage.

Any errors in the Filebeat logs?

---

<div class="post-metadata">

**Author:** ![AVM](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@AVM](https://discuss.elastic.co/u/AVM)\
**Post date:** [March 30, 2018, 5:27am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/5 "2018-03-30T05:27:13Z")

</div>

Hello, the problem is solved.I checked filebeat logs again. It was not getting connected to 4.12 and 4.19. I commented protocol: "https" in filebeat.yml.  
The filebeat logs when 172.16.4.11 is not running.

ERROR pipeline/output.go:74 Failed to connect: Get [https://172.16.4.11:9200](https://172.16.4.11:9200): dial tcp 172.16.4.11:9200: getsockopt: connection refused  
ERROR pipeline/output.go:74 Failed to connect: Get [https://172.16.4.12:9200](https://172.16.4.12:9200): http: server gave HTTP response to HTTPS client  
ERROR pipeline/output.go:74 Failed to connect: Get [https://172.16.4.19:9200](https://172.16.4.19:9200): http: server gave HTTP response to HTTPS client

But now it's working fine. When one of the master is down filebeat sends logs to other two. Thank you for your help!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2018, 7:41am UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-multiple-hosts-specified-in-output-elasticsearch-section/126097/7 "2018-04-27T07:41:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
