# Cannot get Beats to monitor with Metricbeat

**URL:** <https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [March 4, 2021, 9:46pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293 "2021-03-04T21:46:47Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 4, 2021, 9:46pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/1 "2021-03-04T21:46:47Z")

</div>

Hi

Elastic 7.11.1

I have configured metricbeat, and I have got rid of this legacy monitoring, but I cannot seem to get rid of this message:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/0/20e34d62c599377280b53be2650676f908e64f1c.png)

I click onto "Monitor with Metricbeat"

I have done:  
metricbeat modules enable beat-xpack

I also have enabled these modules:

```
# ls -lh /etc/metricbeat/modules.d/*.yml
-rw-r--r-- 1 root root 255 Mar 4 19:21 /etc/metricbeat/modules.d/beat-xpack.yml
-rw-r--r-- 1 root root 340 Mar 4 18:15 /etc/metricbeat/modules.d/elasticsearch-xpack.yml
-rw-r--r-- 1 root root 280 Mar 4 18:15 /etc/metricbeat/modules.d/kibana-xpack.yml
-rw-r--r-- 1 root root 822 Feb 15 15:48 /etc/metricbeat/modules.d/system.yml

```

I have modified metribeat.yml and checked all these modules.d/ file contents.

```
# cat /etc/metricbeat/modules.d/beat-xpack.yml
# Module: beat
# Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.11/metricbeat-module-beat.html

- module: beat
  xpack.enabled: true
  period: 10s
  hosts: ["http://localhost:5066"]
  username: "beats_system"
  password: "XXXXXXXXXXXXXXXXXXX"

```

Regards  
Raul

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [March 5, 2021, 12:56am UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/2 "2021-03-05T00:56:04Z")

</div>

Looks like this was introduced in [[Monitoring] "Internal Monitoring" deprecation warning by igoristic · Pull Request #72020 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/72020)

@chrisronline how would you recommend identifying which `.monitoring-*` indices are legacy?

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [March 5, 2021, 3:34pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/3 "2021-03-05T15:34:05Z")

</div>

Hi @raulk89,

Did you disable legacy monitoring collection through the ES cluster settings?

Can you share the result of `GET _cluster/settings`?

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 5, 2021, 4:09pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/4 "2021-03-05T16:09:34Z")

</div>

I did yeah.  
Here is the output.

```
{
  "persistent" : {
    "xpack" : {
      "monitoring" : {
        "elasticsearch" : {
          "collection" : {
            "enabled" : "false"
          }
        }
      }
    }
  },
  "transient" : { }
}
```

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 5, 2021, 4:29pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/5 "2021-03-05T16:29:52Z")

</div>

Seems like, the problem was this:

```
/etc/metricbeat/metricbeat.yml

# ============================= X-Pack Monitoring ==============================
# Metricbeat can export internal metrics to a central Elasticsearch monitoring
# cluster. This requires xpack monitoring to be enabled in Elasticsearch. The
# reporting is disabled by default.

# Set to true to enable the monitoring reporter.
#monitoring.enabled: false

```

Which is strange. Since there is a statement:

> The reporting is disabled by default

So it should have been false. When I uncommented this value, like this:

`monitoring.enabled: false`

Then after some 30 seconds, kibana started showing **N/A** for metricbeat monitoring..

So, seems like this "monitoring.enabled" default value is actually true..?

To get rid of this **N/A** , I had to additionally add these to metricbeat.yml

```
http.enabled: true
http.port: 5066

```

Then I got these blue messages:

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75e61d0c86611ac5322d71abe892c1397ad71474.png)

Raul

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [March 5, 2021, 6:07pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/6 "2021-03-05T18:07:14Z")

</div>

Hmm. That doesn't sound like intended behavior, but I'll ping @Mario_Castro for some perspective on the Metricbeat side of things.

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 14, 2021, 5:02pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/7 "2021-03-14T17:02:42Z")

</div>

Hi

What is the status with this one..?

Raul

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 23, 2021, 1:20pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/8 "2021-03-23T13:20:16Z")

</div>

> [@chrisronline](#):
>
> Hmm. That doesn't sound like intended behavior, but I'll ping @Mario_Castro for some perspective on the Metricbeat side of things.

Have you had any luck..?

Regards  
Raul

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [March 23, 2021, 1:52pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/9 "2021-03-23T13:52:34Z")

</div>

Are you still having an issue? I was under the impression you sorted it out

---

<div class="post-metadata">

**Author:** ![raulk89](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@raulk89](https://discuss.elastic.co/u/raulk89)\
**Post date:** [March 23, 2021, 3:04pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/10 "2021-03-23T15:04:57Z")

</div>

> [@chrisronline](#):
>
> I was under the impression you sorted it out

Correct, but I understood this was not intended behavior.  
Any info on that..?

Raul

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2021, 3:05pm UTC](https://discuss.elastic.co/t/cannot-get-beats-to-monitor-with-metricbeat/266293/11 "2021-04-20T15:05:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
