# TCP input plugin generate additional port field

**URL:** <https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459>\
**Category:** Logstash\
**Created:** [January 9, 2020, 3:34pm UTC](https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459 "2020-01-09T15:34:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lantern77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lantern77/32/22043_2.png) [@lantern77](https://discuss.elastic.co/u/lantern77)\
**Post date:** [January 9, 2020, 3:34pm UTC](https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459/1 "2020-01-09T15:34:02Z")

</div>

Hello,

For some reason, I can't seem to figure out why, but whenever we use the tcp input plugin, an addition "port" field gets added to our documents. For example "port": 39750.  
Can anyone confirm if this is default behaviour from the tcp input plugin?  
We could use filters to remove the field yes, but I would like to confirm if this is behaviour coming from this plugin, as it is no where mentioned in the documentation of:  
[https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html)

I could also be overlooking something completely and it could be on our end, but has anyone else encountered this?

I also found a possibly related issue here: [https://github.com/logstash-plugins/logstash-input-tcp/issues/146](https://github.com/logstash-plugins/logstash-input-tcp/issues/146)

Currently we are running the tcp input plugin with this configuration:

```auto
# input plugin configuration
input {

   # udp connection for transport
   udp {
      id => "UDP-INPUT"
      host => "0.0.0.0"
      port => 19503
      codec => "json"
      type => "udp"
      workers => 5
      queue_size => 5000
      tags => ["data-udp"]
   }

   # tcp connection for transport
   tcp {
      id => "TCP-INPUT"
      host => "0.0.0.0"
      port => 19503
      codec => "json_lines"
      type => "tcp"
      tags => ["data-tcp"]
   }
}

```

```auto
# output plugin configuration
output {
    # handler for the magnum devices
    elasticsearch {
        id => "ELASTICSEARCH"
        index => "device-%{+YYYY.MM.dd}"
        hosts => ["host:9200"]
        codec => "json"
        template => "/parasite/applications/configuration/global/mapping/elasticsearch-template-device.json"
        template_name => "device-template"
        template_overwrite => true
    }
}

```

Logstash version: 7.4.2

Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 9, 2020, 5:18pm UTC](https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459/2 "2020-01-09T17:18:29Z")

</div>

> [@lantern77](#):
>
> Can anyone confirm if this is default behaviour from the tcp input plugin?

[Confirmed](https://github.com/logstash-plugins/logstash-input-tcp/blob/f372baecd5b778a949e16d407196630236ebb92b/lib/logstash/inputs/tcp.rb#L259).

---

<div class="post-metadata">

**Author:** ![lantern77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lantern77/32/22043_2.png) [@lantern77](https://discuss.elastic.co/u/lantern77)\
**Post date:** [January 9, 2020, 7:00pm UTC](https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459/3 "2020-01-09T19:00:12Z")

</div>

Thanks the source code helps alot too, much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2020, 7:00pm UTC](https://discuss.elastic.co/t/tcp-input-plugin-generate-additional-port-field/214459/4 "2020-02-06T19:00:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
