# Too many socket connection to coordinating nodes?

**URL:** <https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689>\
**Category:** Logstash\
**Created:** [December 12, 2019, 4:28pm UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689 "2019-12-12T16:28:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [December 12, 2019, 4:28pm UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/1 "2019-12-12T16:28:17Z")

</div>

Hello,

While investigating on "[main] Marking url as dead." errors, I noticed that I have lots of socket connection established from my logstash to the two coordinating nodes :

```
netstat -nat | grep 9200 | wc -l
93

```

Logstash output conf :

```
output {
if [identifiant] == "CUSTOMER1" {
  elasticsearch {
      ilm_enabled => true
      hosts => ["https://192.168.145.7:9200", "https://192.168.145.8:9200"]
      user => "elastic"
      password => "pasword"
      ssl => true
      cacert => "/etc/logstash/certs/ca.pem"
      index => "ims_customer1_logs"
  }
}
}

output {
if [identifiant] == "CUSTOMER2" {
  elasticsearch {
      ilm_enabled => true
      hosts => ["https://192.168.145.7:9200", "https://192.168.145.8:9200"]
      user => "elastic"
      password => "pasword"
      ssl => true
      cacert => "/etc/logstash/certs/ca.pem"
      index => "ims_customer2_logs"
  }
}
}

output {
if [identifiant] == "CUSTOMER3" {
  elasticsearch {
      ilm_enabled => true
      hosts => ["https://192.168.145.7:9200", "https://192.168.145.8:9200"]
      user => "elastic"
      password => "pasword"
      ssl => true
      cacert => "/etc/logstash/certs/ca.pem"
      index => "ims_customer3_logs"
  }
}
}

output {
if [identifiant] == "CUSTOMER4" {
  elasticsearch {
      ilm_enabled => true
      hosts => ["https://192.168.145.7:9200", "https://192.168.145.8:9200"]
      user => "elastic"
      password => "pasword"
      ssl => true
      cacert => "/etc/logstash/certs/ca.pem"
      index => "ims_customer4_logs"
  }
}
}

```

Do you think this is a normal behavior ? maybe this is related to the lost connection to elasticsearch errors ?

Thanks for your help ! 🙂

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [December 16, 2019, 8:04am UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/2 "2019-12-16T08:04:44Z")

</div>

Does anybody with a similar setup can check if he has the same behavior ?

Thank you ! 🙂

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [December 17, 2019, 9:29pm UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/3 "2019-12-17T21:29:57Z")

</div>

@Christian_Dahlqvist @DavidTurner any chance to have a quick feedback ? 😉

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 17, 2019, 10:13pm UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/4 "2019-12-17T22:13:00Z")

</div>

I cannot speak to the error, but if the only difference between the elasticsearch outputs is the index name then I would combine them...

```
filter {
    if [identifiant] == "CUSTOMER1" {
        mutate { add_field => { "[@metadata][index]" => "ims_customer1_logs"
    }
    if [identifiant] == "CUSTOMER2" {
        mutate { add_field => { "[@metadata][index]" => "ims_customer2_logs"
    }
    if [identifiant] == "CUSTOMER3" {
        mutate { add_field => { "[@metadata][index]" => "ims_customer3_logs"
    }
    if [identifiant] == "CUSTOMER4" {
        mutate { add_field => { "[@metadata][index]" => "ims_customer4_logs"
    }
}

```

Then reference that in your elasticsearch output

```
     index => "%{[@metadata][index]}"

```

More details in the [best practices](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#_writing_to_different_indices_best_practices) section of the elasticsearch output documentation.

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [December 20, 2019, 8:20am UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/6 "2019-12-20T08:20:36Z")

</div>

Hello @Badger, yes that's a good practice indeed. I will try this and see if it's better. Thank you

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 6, 2020, 9:22am UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/7 "2020-01-06T09:22:41Z")

</div>

@Badger's solution has solved the issue : from 93 connections to cooordinating nodes, I'm around 20 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2020, 9:22am UTC](https://discuss.elastic.co/t/too-many-socket-connection-to-coordinating-nodes/211689/8 "2020-02-03T09:22:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
