# Metricbeats using port 9243 instead of 443

**URL:** <https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661>\
**Category:** Beats\
**Tags:** docker, metricbeat\
**Created:** [March 25, 2022, 6:11am UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661 "2022-03-25T06:11:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alphabet5](https://avatars.discourse-cdn.com/v4/letter/a/3ab097/32.png) [@alphabet5](https://discuss.elastic.co/u/alphabet5)\
**Post date:** [March 25, 2022, 6:11am UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/1 "2022-03-25T06:11:18Z")

</div>

Using elastic cloud I am trying to connect metricbeats with the provided cloud.id/auth.

I'm seeing this in the logs

```auto
{"log.level":"info","@timestamp":"2022-03-25T05:56:18.524Z","log.logger":"publisher_pipeline_output","log.origin":{"file.name":"pipeline/client_worker.go","file.line":141},"message":"Attempting to reconnect to backoff(elasticsearch(https://{elastic_url}.us-east-2.aws.elastic-cloud.com:9243)) with 250 reconnect attempt(s)","service.name":"metricbeat","ecs.version":"1.6.0"}

```

The docs [here](https://www.elastic.co/guide/en/beats/metricbeat/current/configure-cloud-id.html) state that it should be using 443 by default.

```auto
The base64 encoded cloud.id found in the Elasticsearch Service web console does not explicitly specify a port. This means that Metricbeat will default to using port 443 when using cloud.id, not the commonly configured cloud endpoint port 9243.

```

Any idea why 9243 would be showing up in the logs if 443 should be used by default?

Using [docker.elastic.co/beats/metricbeat:8.1.1](http://docker.elastic.co/beats/metricbeat:8.1.1) with a pretty simple metricbeat.yml

```auto
cloud:
  id: ${CLOUDID}
  auth: ${CLOUDAUTH}
metricbeat.modules:
- module: vsphere
  enabled: true
  metricsets: ["datastore", "host", "virtualmachine"]
  period: 10s
  hosts: ["https://1.2.3.4/sdk"]
  username: ${USERNAME}
  password: ${PASSWORD}
  # If insecure is true, don't verify the server's certificate chain
  insecure: true
  # Get custom fields when using virtualmachine metric set. Default false.
  # get_custom_fields: false

```

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [March 25, 2022, 2:16pm UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/2 "2022-03-25T14:16:28Z")

</div>

It could be due to using an 'older' cloud.id that still has port 9243 as part of it. You should base64 decode the part of the cloud.id to confirm the URL does not have a port specified.

If it does, you could regenerate a new version of the cloud.id that either excludes the port (9243) or explicitly specifies 443.

---

<div class="post-metadata">

**Author:** ![alphabet5](https://avatars.discourse-cdn.com/v4/letter/a/3ab097/32.png) [@alphabet5](https://discuss.elastic.co/u/alphabet5)\
**Post date:** [March 25, 2022, 3:03pm UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/3 "2022-03-25T15:03:44Z")

</div>

That was exactly the issue. Thanks for the help! I didn't see the :9243 embedded in there before.

---

<div class="post-metadata">

**Author:** ![alphabet5](https://avatars.discourse-cdn.com/v4/letter/a/3ab097/32.png) [@alphabet5](https://discuss.elastic.co/u/alphabet5)\
**Post date:** [March 25, 2022, 3:40pm UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/4 "2022-03-25T15:40:12Z")

</div>

Do you have information on how to generate a new cloud id? Does that require a new deployment? Not finding anything in the documentation.

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [March 26, 2022, 1:40am UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/5 "2022-03-26T01:40:16Z")

</div>

It does not require a new deployment. Take the decoded portion and edit it as you want (replace 9243 with 443 or completely remove `:9243`) and just base64 encode it again. The format of the Cloud ID is the deployment name, a colon and then the encoded portion is the Cloud Provider/Region domain (with optional port number), Elasticsearch Cluster ID and Kibana ID separated by '$' characters.

Example - replace vars with your values and if you want the port or not:

```auto
echo -n '{cloud_domain}{:optional_port}${es_id}${kibana_id}' | base64

```

- Make sure to use the '-n' option for the echo command so as to not encode any CR/LF chars as part of new cloud.id you are generating.

Once you have that, prepend the same deployment name from your current cloud.id with a colon to this new version and use this in your configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2022, 3:41am UTC](https://discuss.elastic.co/t/metricbeats-using-port-9243-instead-of-443/300661/6 "2022-04-23T03:41:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
