Just some general remarks.
Every producer (your case: filebeat) specifies an ack mode (acks
https://docs.confluent.io/current/installation/configuration/producer-configs.html#producer-configurations),
which incarnates your requirements for availability and
durability.
You also specify a replication factor per topic (from your logs 2)
that impacts durability and availability as well.
There is also an ISR requirement (broker configuration
min.insync.replicas) that impacts successful writes (probably 2 in
your case?)
What can happen (depending on your settings; lets assume acks=all,
min.isr=2, replication.factor=2)
If you lose a broker, you cannot produce anymore, as the ISR
requirement is not met.
Your producer should see exceptions like NotEnoughReplicas or
alike.
Quick recommendation: Increase the replication factor to 3 and
retest.
In general, I propose to either involve your service provider (if
you have one) and/or read the docs on configuration options.
Hth,
Andreas