# Filebeat unable to output logs to kafka

**URL:** https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359
**Category:** Beats
**Tags:** filebeat
**Created:** [July 11, 2021, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359 "2021-07-11T13:55:44Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![itsec](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@itsec](https://discuss.elastic.co/u/itsec)
#### Post date: [July 11, 2021, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/1 "2021-07-11T13:55:44Z")

</div>

I had setup a 3 node clusters and my kafka / zookeeper are running  
i can create a topic and insert msg to the topic and read its output

- filebeat version 7.12.0 (amd64), libbeat 7.12.0
- kafka 2.13-2.7.0
- zookeeper 3.5.8

However, filebeat is not able to output to kafka.

Here's my filebeat config  
filebeat.inputs:

- type: log  
enabled: true

- /xxxx/xxxxx/xxxxxx/xxx/xxxx.txt

filebeat.config.modules:

# Glob pattern for configuration loading

path: ${path.config}/modules.d/\*.yml

# Set to true to enable config reloading

reload.enabled: true

# Period on which files under path should be checked for changes

reload.period: 10s

output.kafka:

enabled: true

hosts: ["192.100.100.120:9092", "192.100.100.122:9092", "192.100.100.123:9092"]

topic: TutorialTopic  
#topic: `%{[TutorialTopic]}`

# Authentication details. Password is required if username is set.

username: 'xxxxxx'  
password: 'xxxxxx'

i can start filebeat and from the logs

"mac": [  
"00:0c:29:02:xx:xx",  
"00:0c:29:02:xx:xx"  
],  
"hostname": "xxxxxxx"  
}  
}  
2021-07-11T21:51:04.644+0800 DEBUG [harvester] log/log.go:107 End of file reached: /xxxxxx.txt; Backoff now.

i do have 1 error  
ERROR [kafka] kafka/client.go:317 Kafka (topic=TutorialTopic): kafka: client has run out of available brokers to talk to (Is your cluster reachable?)

Any advises are deeply appreciated.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [July 11, 2021, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/2 "2021-07-11T15:51:12Z")

</div>

> [@itsec](#):
>
> ERROR [kafka] kafka/client.go:317 Kafka (topic=TutorialTopic): kafka: client has run out of available brokers to talk to (Is your cluster reachable?)

This means that filebeat cannot communicate with your Kafka Brokers.

Maybe the machine running filebeat cannot talk with the broker nodes or your Kafka configuration for listeners and advertised listeners is wrong.

Can you try to create a topic from the same machine that is running filebeat using the Kafka console scripts and using the same endpoints?

---

<div class="post-metadata">

### Author: ![itsec](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@itsec](https://discuss.elastic.co/u/itsec)
#### Post date: [July 17, 2021, 4:06am UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/3 "2021-07-17T04:06:50Z")

</div>

Hi Leandro,  
the server running filebeat are running low on resources. Is there any way to add messages to the topic without installing kafka?

---

<div class="post-metadata">

### Author: ![itsec](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@itsec](https://discuss.elastic.co/u/itsec)
#### Post date: [July 20, 2021, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/4 "2021-07-20T14:46:47Z")

</div>

i test the port via nc and its good  
[root@:XXX102 filebeat]# nc -zv 192.100.100.120 9092  
Ncat: Version 7.50 ( [Ncat - Netcat for the 21st Century](https://nmap.org/ncat) )  
Ncat: Connected to 192.100.100.120:9092.  
Ncat: 0 bytes sent, 0 bytes received in 0.02 seconds.

i can list its brokers and topic  
[root@XKAF101 bin]# ~/kafka/bin/zookeeper-shell.sh XKAF101:2181 ls /brokers/ids

Connecting to XKAF101:2181

WATCHER::

WatchedEvent state:SyncConnected type:None path:null  
[1, 2, 3]

[root@XKAF101 bin]# ~/kafka/bin/zookeeper-shell.sh XKAF101:2181 ls /brokers/topics

Connecting to XKAF101:2181

WATCHER::

WatchedEvent state:SyncConnected type:None path:null  
[TutorialTopic, \_\_consumer\_offsets]

i wonder what's wrong and i did a tcp dump and the packets hit the kafka server #1

22:46:09.151310 00:0c:29:f2:82:30 (oui Unknown) \> 00:0c:29:2e:30:b2 (oui Unknown), IPv4, length 128: XKAF102.42938 \> XKAF101.XmlIpcRegSvc: tcp 62  
0x0000: 4500 0072 ab22 4000 4006 45a8 c064 647a E..r."@.@.E..ddz  
0x0010: c064 6478 a7ba 2384 ee8e 706e 9407 e5d8 .ddx..#...pn....  
0x0020: 8018 3908 9c69 0000 0101 080a 0012 14aa ..9..i..........  
0x0030: 0014 1dc9 0000 003a 0001 000c 0000 08c3 .......:........  
0x0040: 0012 6272 6f6b 6572 2d32 2d66 6574 6368 ..broker-2-fetch  
0x0050: 6572 2d30 0000 0000 0200 0001 f400 0000 er-0............  
0x0060: 0100 a000 0000 442e a41c 0000 08c2 0101 ......D.........

---

<div class="post-metadata">

### Author: ![itsec](https://avatars.discourse-cdn.com/v4/letter/i/77aa72/32.png) [@itsec](https://discuss.elastic.co/u/itsec)
#### Post date: [August 9, 2021, 3:30am UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/5 "2021-08-09T03:30:27Z")

</div>

i tested 3 hosts via another server and the brokers are up  
i believed it is due to some configurations which either on the kafka or filebeat which i'm not able to figure it up.  
[root@kafdrop /]kafkacat -Lb XKAF101:9092  
Metadata for all topics (from broker 1: XKAF101:9092/1):  
3 brokers:  
broker 2 at XKAF102:9092  
broker 3 at XKAF103:9092  
broker 1 at XKAF101:9092 (controller)  
4 topics:  
topic "TutorialTopic" with 1 partitions:  
partition 0, leader 2, replicas: 2,1, isrs: 2,1  
topic "testtest" with 3 partitions:  
partition 0, leader 1, replicas: 1,3, isrs: 3,1  
partition 1, leader 2, replicas: 2,1, isrs: 2,1  
partition 2, leader 3, replicas: 3,2, isrs: 2,3  
topic "test" with 3 partitions:  
partition 0, leader 2, replicas: 2,3, isrs: 3,2  
partition 1, leader 3, replicas: 3,1, isrs: 3,1  
partition 2, leader 1, replicas: 1,2, isrs: 2,1  
topic "\_\_consumer\_offsets" with 3 partitions:  
partition 0, leader 1, replicas: 1,2, isrs: 2,1  
partition 1, leader 2, replicas: 2,3, isrs: 3,2  
partition 2, leader 3, replicas: 3,1, isrs: 3,1

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 27, 2021, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/6 "2021-08-27T14:00:24Z")

</div>

From the filebeat server test the connection to all of your brokers, use the kafka console scripts, you don't need to run kafka on this server, just use the scripts to publish and consume from your brokers.

If this works without any problem, change the filebeat [log level](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html#configuration-logging) to debug and see if gives you more information.

Also enable the debug logs in your kafka cluster and see if this give you more information.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 24, 2021, 4:01pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-output-logs-to-kafka/278359/7 "2021-09-24T16:01:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
