# Filebeat temporarily unable to connect to ES

**URL:** <https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 1, 2019, 9:09am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697 "2019-02-01T09:09:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [February 1, 2019, 9:09am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697/1 "2019-02-01T09:09:34Z")

</div>

If Filebeat, running as a service, cannot temporarily connect to the destination Elasticsearch instance then what is the process?  
Does it continually retry until the destination is available?  
Does it just error out?

Is there any documentation of the process?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2019, 9:14am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697/2 "2019-02-01T09:14:11Z")

</div>

> [@Garry](#):
>
> Does it continually retry until the destination is available?

Yes.

> [@Garry](#):
>
> Does it just error out?

No. It will write to [the internal queue](https://www.elastic.co/guide/en/beats/filebeat/6.6/configuring-internal-queue.html) if you have this configured and will then stop reading data in order to avoid data loss until it is again able to send data.

---

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [February 1, 2019, 9:43am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697/3 "2019-02-01T09:43:32Z")

</div>

'No. It will write to the internal queue if you have this configured and will then stop reading data in order to avoid data loss until it is again able to send data.'

Where would this internal queue be configured?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2019, 10:09am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697/4 "2019-02-01T10:09:00Z")

</div>

Seems like I forgot to include the link. Have updated my previous post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2019, 10:09am UTC](https://discuss.elastic.co/t/filebeat-temporarily-unable-to-connect-to-es/166697/5 "2019-03-01T10:09:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
