# Filebeat uses internal dns name of Kafka Broker

**URL:** https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407
**Category:** Beats
**Tags:** filebeat
**Created:** [January 13, 2018, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407 "2018-01-13T13:53:50Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)
#### Post date: [January 13, 2018, 1:53pm UTC](https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407/1 "2018-01-13T13:53:50Z")

</div>

Hello,

We are trying to harvest csv data using filebeat to Elasticsearch. Data pipeline is set up to stream to Kafka -\> Logstash -\> Elasticsearch.

We have a hybrid cloud setup of corporate cloud data center and aws. filebeat is installed in corporate data center hosts where as Kafka, logstash and elasticsearch servers are in AWS VPC.

Kafka ip address (aws) is 10.x.x.x which is directly reachable from corporate data center hosts. 10.x.x.x IP address is configured in filebeat.yml. Here is the config file.

```auto
filebeat.registry_file: /var/lib/filebeat/registry
filebeat.shutdown_timeout: 30s
filebeat.prospectors:
- input_type: log
  paths:
    - /home/svcload3/s4/logs/perf-UI*.csv
  scan_frequency: 5s
  fields:
    log_type: perflogs
    service: load3
    product: s4
  exclude_lines: ['SourcePage']
output.kafka:
  hosts: ["10.x.x.x:9092", "10.x.x.y:9092", "10.x.x.z:9092"]
  topic: perflogs
processors:
- add_cloud_metadata:

```

**Issue** :  
In the filebeat logs, we observed that it is trying to connect to the internal dns address of kafka server which is not reachable from corporate data center hosts. How do we resolve this issue?

**Filebeat log**

```auto
2018-01-13T05:31:21-08:00 INFO Failed to connect to broker [[ip-10-x-x-x.us-west-1.compute.internal:9092 dial tcp: lookup ip-10-169-48-77.us-west-1.compute.internal on 10.x.z.z:53: no such host]]: %!s(MISSING)

```

---

<div class="post-metadata">

### Author: ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)
#### Post date: [January 15, 2018, 8:46am UTC](https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407/2 "2018-01-15T08:46:02Z")

</div>

Hi,

Please tell us what version of filebeat are you using, and, if possible, share the debug output (-d '\*') of running filebeat until the given error appears.

Thanks

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [January 15, 2018, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407/3 "2018-01-15T13:50:54Z")

</div>

The addresses used, are the addresses advertised by the kafka brokers. You have to fix the advertised listener addresses in your kafka setup.

The kafka connection setup is called [Bootstrapping](https://kafka.apache.org/protocol#protocol_partitioning). Only one of your configured hosts will be asked for the kafka cluster its metadata. Connections to actual brokers are based on the kafka cluster metadata.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 12, 2018, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-uses-internal-dns-name-of-kafka-broker/115407/4 "2018-02-12T13:57:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
