# Tcp server output, "Address already in use" after upgrade to 2.2

**URL:** <https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501>\
**Category:** Logstash\
**Created:** [March 4, 2016, 11:19am UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501 "2016-03-04T11:19:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![davemac30](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davemac30/32/8278_2.png) [@davemac30](https://discuss.elastic.co/u/davemac30)\
**Post date:** [March 4, 2016, 11:19am UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/1 "2016-03-04T11:19:55Z")

</div>

After upgrade to 2.2 (logstash-2.2.2-1.noarch from the official yum repo), logstash fails to start with the following error.

{:timestamp=\>"2016-03-04T10:45:12.833000+0000", :message=\>"The error reported is: \n Address already in use - bind - Address already in use"}

By selectively removing bits of config until the error went away, I was able to isolate the problem to the tcp server output config. I couldn't see any duplicate ports in the config and nothing other than logstash was using the port (not to mention the fact that the config was fine before the upgrade).

Still, I wondered if somehow something else in the config was causing the problem, so I decided to try a clean configuration of the 2.2 RPM in an empty container with only the tcp output configured. The Dockerfile I used is here:

> <https://gist.github.com/davemac30/7a12cda7e7b7d6d7a69d>

Exactly the same problem.

I suspect a bug in logstash and I will start delving into the source when I get some time with a view to raising this as an issue. For now I was wondering if anyone had the same problem and knew of a workaround.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 4, 2016, 12:09pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/2 "2016-03-04T12:09:27Z")

</div>

> output { tcp { port =\> 1444 host =\> "0.0.0.0" mode =\> server } }

I don't see how `mode => server` could make sense. An output should act as a TCP _client_, not a server. Also, 0.0.0.0 isn't a valid host to connect to. Did you really intend this one to be an output?

---

<div class="post-metadata">

**Author:** ![davemac30](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davemac30/32/8278_2.png) [@davemac30](https://discuss.elastic.co/u/davemac30)\
**Post date:** [March 4, 2016, 2:29pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/3 "2016-03-04T14:29:08Z")

</div>

Unless something has changed, mode =\> server is fine. In this case 0.0.0.0 is the bind address for the tcp listen socket.

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-tcp.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-tcp.html)

We provide this in dev environments so that people can watch events in real time by connecting to the socket.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 4, 2016, 2:50pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/4 "2016-03-04T14:50:44Z")

</div>

Ah, my bad. I didn't know the output could be used like that.

---

<div class="post-metadata">

**Author:** ![galk-in](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/galk-in/32/55173_2.png) [@galk-in](https://discuss.elastic.co/u/galk-in)\
**Post date:** [March 24, 2016, 12:46pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/5 "2016-03-24T12:46:43Z")

</div>

I have same problem.

---

<div class="post-metadata">

**Author:** ![galk-in](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/galk-in/32/55173_2.png) [@galk-in](https://discuss.elastic.co/u/galk-in)\
**Post date:** [March 24, 2016, 6:51pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/6 "2016-03-24T18:51:43Z")

</div>

I made [issue on github](https://github.com/elastic/logstash/issues/4892)

---

<div class="post-metadata">

**Author:** ![davemac30](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davemac30/32/8278_2.png) [@davemac30](https://discuss.elastic.co/u/davemac30)\
**Post date:** [March 25, 2016, 9:20am UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/7 "2016-03-25T09:20:45Z")

</div>

Actually, it's even easier to demonstrate this behaviour by running a container based on the official logstash:latest image:

```
$ docker run --rm -it docker.io/logstash -e "output { tcp { port => 1444 host => '0.0.0.0' mode => server } }"
Settings: Default pipeline workers: 8
The error reported is: 
  Address already in use - bind - Address already in use
```

---

<div class="post-metadata">

**Author:** ![davemac30](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davemac30/32/8278_2.png) [@davemac30](https://discuss.elastic.co/u/davemac30)\
**Post date:** [April 1, 2016, 1:46pm UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/8 "2016-04-01T13:46:22Z")

</div>

Looks like this is fixed in the 2.3.0 release - presumably by this:

> <https://github.com/elastic/logstash/pull/4905>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/tcp-server-output-address-already-in-use-after-upgrade-to-2-2/43501/9 "2017-07-06T05:04:18Z")

</div>


