# Question regarding specifying "localhost" and deploying to Lambda

**URL:** <https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [August 15, 2019, 11:35am UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332 "2019-08-15T11:35:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheSwede86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theswede86/32/52444_2.png) [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Post date:** [August 15, 2019, 11:35am UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/1 "2019-08-15T11:35:53Z")

</div>

Running on my localhost (i.e. my laptop):  
ES 7.3 w. Basic-license (port 9200 is verified and returns info)  
Kibana 7.3 w. Basic-license (port 5601 is verified and returns the Kibana interface)  
Functionbeat 7.3 from the link provided when starting Kibana;

> **[Download Functionbeat • Serverless Shipper | Elastic](https://www.elastic.co/downloads/beats/functionbeat)**
>
> Download Functionbeat, the lightweight, serverless shipper for cloud data.

^ The hash when downloading either through selecting "OSS" or "Basic" is the same

My "functionbeat.yml";

> ```
> functionbeat.provider.aws.endpoint: "s3.amazonaws.com"
> functionbeat.provider.aws.deploy_bucket: "mybucket"
> functionbeat.provider.aws.functions:
> - name: cloudwatch-logs
> enabled: true
> type: cloudwatch_logs
> triggers:
> - log_group_name: myloggroup
> 
> output.elasticsearch:
> hosts: ["localhost:9200"]
> username: "elastic"
> password: "changeme"
> setup.kibana:
> host: "localhost:5601"
> 
> ```

Deploying to Lambda goes fine, I change the timeout of the Lambda which defaults to 3sec to 1min30sec and up the RAM to 512 but then when I try and "Check data" in Kibana it says "No data has been received from Functionbeat yet".

When I check the CloudWatch-logs for the Lambda I see this;  
`INFO	[license-manager]	licenser/manager.go:265	Cannot retrieve license, retrying later, error: Get http://localhost:9200: dial tcp [::1]:9200: socket: address family not supported by protocol`

Since I specified "localhost" which makes sense on my local computer I guess I can't specify it as "localhost" when I upload it as a Lambda?  
How does Lambda know what my "localhost" was, i.e. "localhost" is always "localhost" and dependent on the host you run it on and the actual IP varies depending on host, or am I missing something?

I haven't started Functionbeat locally except for running;  
.\functionbeat.exe setup  
.\functionbeat.exe deploy cloudwatch-logs

AFAIK it creates it as a Lambda and Functionbeat does not need to be started on your "localhost" (i.e. my laptop)?

Sorry if I've missed something, great tutorial when starting Kibana and going to "Add log data" \> "CloudWatch Logs" just think I misunderstand something.

Best Regards & Thanks in advance - TheSwede86

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 15, 2019, 12:01pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/2 "2019-08-15T12:01:52Z")

</div>

The lambda function gets deployed on AWS, it is not running locally on your machine, and once depoyed it doesn't know about your laptop. You need an Elasticsearch running in the Cloud, like [Elastic Cloud](https://www.elastic.co/de/cloud/).

---

<div class="post-metadata">

**Author:** ![TheSwede86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theswede86/32/52444_2.png) [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Post date:** [August 16, 2019, 12:20pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/3 "2019-08-16T12:20:22Z")

</div>

Thank you for your reply.

What I did to solve it to have the following in my Functionbeat.yml:

> **[Functionbeat.yml - Pastebin.com](https://pastebin.com/1iRPKGDQ)**
>
> Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.

The " security\_group\_ids" is the SecurityGroupID of the SG I created in advance that the Lambda will use and "role" is the IAM-role we use for our Lambdas which needed some added permissions since we normally don't deploy Lambdas in a VPC. The IP-specified is the internal IP of the host running ES and Kibana.

The ES and Kibana host are the internal IP of the server hosting those applications and on that server I needed to edit the following;

...\elasticsearch\config\elasticsearch.yml;

> cluster.name: myEScluster  
> node.name: myHostname  
> network.host: internal-ipOfhost  
> cluster.initial\_master\_nodes: ["myHostname"]

---\kibana\config\kibana.yml

> server.host: "internal-ipOfhost"  
> elasticsearch.hosts: ["[http://internal-ipOfhost:9200](http://internal-ipOfhost:9200)]

That should be it, hopefully it helps someone 🙂

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 18, 2019, 11:35pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/4 "2019-08-18T23:35:55Z")

</div>

Thank you for sharing the details of your solution!

---

<div class="post-metadata">

**Author:** ![asad\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asad_ali/32/47894_2.png) [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Post date:** [August 20, 2019, 4:19pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/5 "2019-08-20T16:19:09Z")

</div>

This is strange and contrary, to my post here

> [@Ghost index unable to populate itself under '\_docs' | functionbeat](https://discuss.elastic.co/t/ghost-index-unable-to-populate-itself-under-docs-functionbeat/195873):
>
> I'm using functionbeat 7.1, and after great pain and countless night i was able to deploy 'function'. The inbuilt tutorial is very insufficient for development setups, as it lacks 'in-between' setups/details and configuration. For e.g i had to add env variable ENABLED\_FUNCTONS to name of function name given in functions.yml to make it work. My uncommented \*.yml looks like functionbeat.provider.aws.functions: - name: fun-aws enabled: true type: cloudwatch\_logs description: "lambd…

My ES is not exposed to internet but when I run ./functionbeat im getting messages on my cli?

---

<div class="post-metadata">

**Author:** ![asad\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asad_ali/32/47894_2.png) [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Post date:** [August 20, 2019, 4:20pm UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/6 "2019-08-20T16:20:23Z")

</div>

So in that case if ES is not routable, when you running ./functionbeat there should be no msgs on CLI?

pls see this

> [@Ghost index unable to populate itself under '\_docs' | functionbeat](https://discuss.elastic.co/t/ghost-index-unable-to-populate-itself-under-docs-functionbeat/195873):
>
> I'm using functionbeat 7.1, and after great pain and countless night i was able to deploy 'function'. The inbuilt tutorial is very insufficient for development setups, as it lacks 'in-between' setups/details and configuration. For e.g i had to add env variable ENABLED\_FUNCTONS to name of function name given in functions.yml to make it work. My uncommented \*.yml looks like functionbeat.provider.aws.functions: - name: fun-aws enabled: true type: cloudwatch\_logs description: "lambd…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 6:20am UTC](https://discuss.elastic.co/t/question-regarding-specifying-localhost-and-deploying-to-lambda/195332/7 "2019-09-10T06:20:23Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
