# Whats different with "protocol node" or "protocol http" in logstash output

**URL:** <https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901>\
**Category:** Elasticsearch\
**Created:** [September 24, 2015, 8:49am UTC](https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901 "2015-09-24T08:49:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [September 24, 2015, 8:49am UTC](https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901/1 "2015-09-24T08:49:20Z")

</div>

Hi All,

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html)

In logstash output elasticsearch plugin, there are 3 protocols to talk to elasticsearch,

I don't really understand whats different beacuse the protocol both "node" and "http" are using http port to communicate (it can be found in elasticsearch.yml), someone can help to explain what is it mean or differentiation? thanks

```
############################## Network And HTTP ###############################

# Elasticsearch, by default, binds itself to the 0.0.0.0 address, and listens
# on port [9200-9300] for HTTP traffic and on port [9300-9400] for node-to-node
# communication. (the range means that if the port is busy, it will automatically
# try the next port).

# Set the bind address specifically (IPv4 or IPv6):
#
#network.bind_host: 192.168.0.1

# Set the address other nodes will use to communicate with this node. If not
# set, it is automatically derived. It must point to an actual IP address.
#
#network.publish_host: 192.168.0.1

# Set both 'bind_host' and 'publish_host':
#
#network.host: 192.168.0.1

# Set a custom port for the node to node communication (9300 by default):
#
#transport.tcp.port: 9300

# Enable compression for all communication between nodes (disabled by default):
#
#transport.tcp.compress: true

# Set a custom port to listen for HTTP traffic:
#
#http.port: 9200

```

Jason

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2015, 9:04am UTC](https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901/2 "2015-09-24T09:04:11Z")

</div>

> I don't really understand whats different beacuse the protocol both "node" and "http" are using http port to communicate

No, the node protocol uses port 9300-9399 just like the transport protocol. Additional reading: [Talking to Elasticsearch | Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/_talking_to_elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [September 25, 2015, 2:15am UTC](https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901/3 "2015-09-25T02:15:52Z")

</div>

> [@magnusbaeck](#):
>
> the node protocol uses port 9300-9399 just like the transport protocol. Additional reading

Hi Magnus, thanks, its very helpful

Jason

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:48pm UTC](https://discuss.elastic.co/t/whats-different-with-protocol-node-or-protocol-http-in-logstash-output/29901/4 "2017-07-05T23:48:10Z")

</div>


