# Can not monitor Logstash in Kibana

**URL:** https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715
**Category:** Kibana
**Created:** [February 20, 2018, 7:13pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715 "2018-02-20T19:13:44Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 7:13pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/1 "2018-02-20T19:13:44Z")

</div>

Hello friends, I'm testing an elastic stack installation on a single server before going to production environment, I have intalled Elasticsearch 6.2.1 wiht X-Pack, and the same with Kibana 6.2.1, I followed the installation order; thist two are working fine and I can monitor them with kibana.  
Then I installed Logstash and configure it:

`xpack.monitoring.elasticsearch.url: ["http://localhost:9200"]`

but can not see logstash in kibana; I don't know what I'm missing...

 ![Monitoring%20%20%20stack%20ecoa57%20%20%20Overview](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f5e47c89ea92e346418137d7b9fc3829488d745.png)

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [February 20, 2018, 7:33pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/2 "2018-02-20T19:33:16Z")

</div>

Did you [install X-Pack on Logstash](https://www.elastic.co/guide/en/logstash/current/installing-xpack-log.html) as well?

---

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 7:34pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/3 "2018-02-20T19:34:05Z")

</div>

Yes I did  
I installed it with the same local file for the 3 of them

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [February 20, 2018, 7:38pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/4 "2018-02-20T19:38:49Z")

</div>

That looks fine to me. Were there any errors or warnings when you restarted Logstash?

---

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 7:44pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/5 "2018-02-20T19:44:26Z")

</div>

I'm seeing this warn in the log:

`[WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=>"http://localhost:9200/"}`

everything else is `INFO`, no errors

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [February 20, 2018, 7:45pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/6 "2018-02-20T19:45:20Z")

</div>

And Logstash is also version 6.2.1? Can you share the full configuration file?

---

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 7:49pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/7 "2018-02-20T19:49:40Z")

</div>

```auto
root@elasticsearch:~# /usr/share/logstash/bin/logstash --version
logstash 6.2.1

```

how can I upload my config file logstash.yml?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [February 20, 2018, 7:54pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/8 "2018-02-20T19:54:58Z")

</div>

You should be able to paste it here as long as you format it as preformatted text using the UI tools.

---

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 7:57pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/9 "2018-02-20T19:57:23Z")

</div>

```auto
# Settings file in YAML
#
# Settings can be specified either in hierarchical form, e.g.:
#
# pipeline:
# batch:
# size: 125
# delay: 5
#
# Or as flat keys:
#
# pipeline.batch.size: 125
# pipeline.batch.delay: 5
#
# ------------ Node identity ------------
#
# Use a descriptive name for the node:
#
# node.name: test
#
# If omitted the node name will default to the machine's host name
#
# ------------ Data path ------------------
#
# Which directory should be used by logstash and its plugins
# for any persistent needs. Defaults to LOGSTASH_HOME/data
#
path.data: /var/lib/logstash
#
# ------------ Pipeline Settings --------------
#
# The ID of the pipeline.
#
# pipeline.id: main
#
# Set the number of workers that will, in parallel, execute the filters+outputs
# stage of the pipeline.
#
# This defaults to the number of the host's CPU cores.
#
# pipeline.workers: 2
#
# How many events to retrieve from inputs before sending to filters+workers
#
# pipeline.batch.size: 125
#
# How long to wait in milliseconds while polling for the next event
# before dispatching an undersized batch to filters+outputs
#
# pipeline.batch.delay: 50
#
# Force Logstash to exit during shutdown even if there are still inflight
# events in memory. By default, logstash will refuse to quit until all
# received events have been pushed to the outputs.
#
# WARNING: enabling this can lead to data loss during shutdown
#
# pipeline.unsafe_shutdown: false
#
# ------------ Pipeline Configuration Settings --------------
#
# Where to fetch the pipeline configuration for the main pipeline
#
# path.config:
#
# Pipeline configuration string for the main pipeline
#
# config.string:
#
# At startup, test if the configuration is valid and exit (dry run)
#
# config.test_and_exit: false
#
# Periodically check if the configuration has changed and reload the pipeline
# This can also be triggered manually through the SIGHUP signal
#
# config.reload.automatic: false
#
# How often to check if the pipeline configuration has changed (in seconds)
#
# config.reload.interval: 3s
#
# Show fully compiled configuration as debug log message
# NOTE: --log.level must be 'debug'
#
# config.debug: false
#
# When enabled, process escaped characters such as \n and \" in strings in the
# pipeline configuration files.
#
# config.support_escapes: false
#
# ------------ Module Settings ---------------
# Define modules here. Modules definitions must be defined as an array.
# The simple way to see this is to prepend each `name` with a `-`, and keep
# all associated variables under the `name` they are associated with, and 
# above the next, like this:
#
# modules:
# - name: MODULE_NAME
# var.PLUGINTYPE1.PLUGINNAME1.KEY1: VALUE
# var.PLUGINTYPE1.PLUGINNAME1.KEY2: VALUE
# var.PLUGINTYPE2.PLUGINNAME1.KEY1: VALUE
# var.PLUGINTYPE3.PLUGINNAME3.KEY1: VALUE
#
# Module variable names must be in the format of 
#
# var.PLUGIN_TYPE.PLUGIN_NAME.KEY
#
# modules:
#
# ------------ Cloud Settings ---------------
# Define Elastic Cloud settings here.
# Format of cloud.id is a base64 value e.g. dXMtZWFzdC0xLmF3cy5mb3VuZC5pbyRub3RhcmVhbCRpZGVudGlmaWVy
# and it may have an label prefix e.g. staging:dXMtZ...
# This will overwrite 'var.elasticsearch.hosts' and 'var.kibana.host'
# cloud.id: <identifier>
#
# Format of cloud.auth is: <user>:<pass>
# This is optional
# If supplied this will overwrite 'var.elasticsearch.username' and 'var.elasticsearch.password'
# If supplied this will overwrite 'var.kibana.username' and 'var.kibana.password'
# cloud.auth: elastic:<password>
#
# ------------ Queuing Settings --------------
#
# Internal queuing model, "memory" for legacy in-memory based queuing and
# "persisted" for disk-based acked queueing. Defaults is memory
#
# queue.type: memory
#
# If using queue.type: persisted, the directory path where the data files will be stored.
# Default is path.data/queue
#
# path.queue:
#
# If using queue.type: persisted, the page data files size. The queue data consists of
# append-only data files separated into pages. Default is 64mb
#
# queue.page_capacity: 64mb
#
# If using queue.type: persisted, the maximum number of unread events in the queue.
# Default is 0 (unlimited)
#
# queue.max_events: 0
#
# If using queue.type: persisted, the total capacity of the queue in number of bytes.
# If you would like more unacked events to be buffered in Logstash, you can increase the
# capacity using this setting. Please make sure your disk drive has capacity greater than
# the size specified here. If both max_bytes and max_events are specified, Logstash will pick
# whichever criteria is reached first
# Default is 1024mb or 1gb
#
# queue.max_bytes: 1024mb
#
# If using queue.type: persisted, the maximum number of acked events before forcing a checkpoint
# Default is 1024, 0 for unlimited
#
# queue.checkpoint.acks: 1024
#
# If using queue.type: persisted, the maximum number of written events before forcing a checkpoint
# Default is 1024, 0 for unlimited
#
# queue.checkpoint.writes: 1024
#
# If using queue.type: persisted, the interval in milliseconds when a checkpoint is forced on the head page
# Default is 1000, 0 for no periodic checkpoint.
#
# queue.checkpoint.interval: 1000
#
# ------------ Dead-Letter Queue Settings --------------
# Flag to turn on dead-letter queue.
#
# dead_letter_queue.enable: false

# If using dead_letter_queue.enable: true, the maximum size of each dead letter queue. Entries
# will be dropped if they would increase the size of the dead letter queue beyond this setting.
# Default is 1024mb
# dead_letter_queue.max_bytes: 1024mb

# If using dead_letter_queue.enable: true, the directory path where the data files will be stored.
# Default is path.data/dead_letter_queue
#
# path.dead_letter_queue:
#
# ------------ Metrics Settings --------------
#
# Bind address for the metrics REST endpoint
#
# http.host: "127.0.0.1"
#
# Bind port for the metrics REST endpoint, this option also accept a range
# (9600-9700) and logstash will pick up the first available ports.
#
# http.port: 9600-9700
#
# ------------ Debugging Settings --------------
#
# Options for log.level:
# * fatal
# * error
# * warn
# * info (default)
# * debug
# * trace
#
# log.level: info
path.logs: /var/log/logstash
#
# ------------ Other Settings --------------
#
# Where to find custom plugins
# path.plugins: []

xpack.monitoring.elasticsearch.url: ["http://localhost:9200"]
#xpack.monitoring.elasticsearch.username: "logstash_system"
#xpack.monitoring.elasticsearch.password: "3l4st1c"

```

---

<div class="post-metadata">

### Author: ![Yoel\_Navas\_Escalante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoel_navas_escalante/32/27960_2.png) [@Yoel\_Navas\_Escalante](https://discuss.elastic.co/u/Yoel_Navas_Escalante)
#### Post date: [February 20, 2018, 8:52pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/10 "2018-02-20T20:52:33Z")

</div>

Hello? Someone there?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 20, 2018, 8:52pm UTC](https://discuss.elastic.co/t/can-not-monitor-logstash-in-kibana/120715/11 "2018-03-20T20:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
