# Physicals host with beats to server with ELK docker containers?

**URL:** <https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [July 26, 2023, 9:26pm UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352 "2023-07-26T21:26:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rhyejam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rhyejam/32/123929_2.png) [@rhyejam](https://discuss.elastic.co/u/rhyejam)\
**Post date:** [July 26, 2023, 9:26pm UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352/1 "2023-07-26T21:26:37Z")

</div>

So here’s my conundrum. Currently using a vm with a bunch of docker containers on it. Included in these is the ELK docker compose by deviantony on GitHub

Now I have a few laptops that I want forwarding logs to the server hosting the vm with ELK on it. The docker compose exposes 5044 and I want to forward via winlogbeat from the laptops… except it’s just not happening

Every time I get beats configged okay the test output comes back as unable to reach logstash.

The ELK stack is on a docker bridge network atm but 5601,9200 and 5044 are all exposed and listening. Beats fails to connect with both elasticsearch and logstash outputs configured.

My question is, has anyone managed to forward to a logstash container from beats? And if so how should I change my approach (worked with elastic for a couple of years but still dipping my toes into docker so explain like I’m 5 plz)

---

<div class="post-metadata">

**Author:** ![eMitch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emitch/32/93607_2.png) [@eMitch](https://discuss.elastic.co/u/eMitch)\
**Post date:** [July 27, 2023, 1:48am UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352/2 "2023-07-27T01:48:00Z")

</div>

Hi @rhyejam and welcome to the community!

I believe that if the containers are using a bridged network driver, then you have to make sure you're configuring beats to send to the docker HOST with the exposed port.

for example, let's say my physical host is `server01` which is running docker and I have a Logstash container setup as `logstash-container01` which is exposing port `5044`. Then i have another device (laptop) called `laptop01` with Beats installed. In Beats (on the laptop), I would specify the output to be `server01:5044`. The bridged network in docker would then route the traffic intended for 5044 down into the container for Logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2023, 1:48am UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352/3 "2023-08-24T01:48:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
