# ‼ Why is metricbeat contacting metadata.tencentyun.com?

**URL:** <https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 18, 2019, 5:21pm UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059 "2019-09-18T17:21:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [September 18, 2019, 5:21pm UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059/1 "2019-09-18T17:21:27Z")

</div>

Following some issues with our 6.x Elastic stack deployment, I deployed a new cluster to Google Cloud Platform in Belgium running Elasticsearch 7.3.2. I also updated our Filebeat deployment on our Kubernetes cluster to v7.3.2, and installed Metricbeat v7.3.2 using the official Helm chart provided by Elastic at [https://helm.elastic.co](https://helm.elastic.co) and Packetbeat v7.3.2 using custom Kubernetes resource manifests. The Metricbeat DaemonSet is running [docker.elastic.co/beats/metricbeat:7.3.2](http://docker.elastic.co/beats/metricbeat:7.3.2) as expected.

What I did not expect to find was Packetbeat reporting a large number of requests to [tencentyun.com](http://tencentyun.com). Digging into the source of these requests, I was surprised to find it is the Metricbeat pods pinging this domain (query: `IN AAAA metadata.tencentyun.com`), approximately once per second. What is going on here?

All other domains identified by Packetbeat are expected ones for our system: [google.com](http://google.com), cluster.local, [es.io](http://es.io), etc. This one is the only one that is unexplained, and I'm really surprised and concerned that it's coming from an Elastic product.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 18, 2019, 9:50pm UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059/2 "2019-09-18T21:50:48Z")

</div>

Take a look at [https://github.com/elastic/beats/issues/11145](https://github.com/elastic/beats/issues/11145) for more details on this.

TLDR it's expected due to the `add_cloud_metadata`.

---

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [September 19, 2019, 9:01am UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059/3 "2019-09-19T09:01:48Z")

</div>

Great, thanks @warkolm for the quick reply. I couldn't find that issue after searching the internet and GitHub specifically. Odd.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2019, 9:02am UTC](https://discuss.elastic.co/t/why-is-metricbeat-contacting-metadata-tencentyun-com/200059/4 "2019-10-17T09:02:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
