# Data Node Offline on Kibana Dashboard

**URL:** <https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300>\
**Category:** Elasticsearch\
**Created:** [March 24, 2025, 6:29am UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300 "2025-03-24T06:29:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gardito-git](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gardito-git/32/142211_2.png) [@gardito-git](https://discuss.elastic.co/u/gardito-git)\
**Post date:** [March 24, 2025, 6:29am UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300/1 "2025-03-24T06:29:00Z")

</div>

Greetings everyone, I'm sorry I'm newbie here  
I have a single master node, single data node and 1 kibana node in our Dev ENV  
I'm trying to monitoring our Elasticsearch Cluster with this guide when I click the red button thing said "Monitor with Metricbeat"  
after the master node success I continue to master node but the data node went offline

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/0168687095eaf8f32f9a87e2a5447146ccd26014.png)  
As you can see, the data node are offline but working fine, and also it got yellow status but it's fine.

This is my master elasticsearch.yml

```auto
cat /etc/elasticsearch/elasticsearch.yml
path:
  data: /var/lib/elasticsearch
  logs: /var/log/elasticsearch
cluster:
  name: your-prop-firm
  initial_master_nodes:
    - ypf-master
node:
  name: ypf-master
  roles:
    - master
    - remote_cluster_client
network.host: 0.0.0.0
http.port: 9200
transport.port: 9300
bootstrap.memory_lock: false

xpack.security:
  enabled: true
  http.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem

  transport.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem
    # verification_mode: certificate
    verification_mode: none

```

this is my data elasticsearch.yml

```auto
cat /etc/elasticsearch/elasticsearch.yml
path:
  data: /mnt/elasticsearch/data
  logs: /mnt/elasticsearch/logs

cluster:
  name: ypg
node:
  name: ypf-data-1
  roles:
    - data
    - remote_cluster_client
network.host: 0.0.0.0
http.port: 9200
transport.port: 9300
discovery.seed_hosts:
  - "master.es.dev.xxx"
bootstrap.memory_lock: false

xpack.security:
  enabled: true
  http.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem

  transport.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem
    # verification_mode: certificate
    verification_mode: none

```

And this is my both master and node metricbeat.yml and elasticsearch-xpack.yml

```auto
cat metricbeat.yml
metricbeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

output.elasticsearch:
  hosts: ["https://master.es.dev.xxx:9200"]
  protocol: "https"
  username: "monitoring"
  password: "monitoring"
  ssl.enabled: true

setup.kibana:
  host: "https://dashboard.es.dev.xxx:5601"
  username: "monitoring"
  password: "monitoring"

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

.

```auto
cat modules.d/elasticsearch-xpack.yml
# Module: elasticsearch
# Docs: https://www.elastic.co/guide/en/beats/metricbeat/8.14/metricbeat-module-elasticsearch.html

- module: elasticsearch
  metricsets:
    - node
    - node_stats
    - index
    - index_recovery
    - enrich
    - ml_job
    - ccr
    - cluster_stats
  xpack.enabled: true
  period: 10s
  hosts: ["https://master.es.dev.xxx:9200"]
  username: "monitoring"
  password: "monitoring"
  #api_key: "foo:bar"

```

Lastly this is my kibana

```auto
cat /etc/kibana/kibana.yml
server:
  port: 5601
  host: "0.0.0.0"
  publicBaseUrl: "https://dashboard.es.dev.xxx:5601"

elasticsearch:
  hosts:
    - https://master.es.dev.xxx:9200
  username: "kibana_system"
  password: "xxx"

server.ssl:
  enabled: true
  certificate: /etc/kibana/certs/certificate.crt
  key: /etc/kibana/certs/private_key.pem

# Add monitoring configurations
monitoring.ui.container.elasticsearch.enabled: true
monitoring.ui.container.logstash.enabled: true
monitoring.ui.ccs.enabled: true

```

---

<div class="post-metadata">

**Author:** ![Musab\_Dogan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/musab_dogan/32/70691_2.png) [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Post date:** [March 25, 2025, 12:45am UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300/2 "2025-03-25T00:45:34Z")

</div>

`cluster.name`s are different in `data elasticsearch.yml` and `master elasticsearch.yml` which must be same on all nodes that you want to connect in one cluster. It's weird that you can see both nodes in the same cluster (your-prop-firm) cluster. Probably, you changed `cluster.name` in data.yml after the installation.

Make sure you are using the same cluster name on all nodes .

---

<div class="post-metadata">

**Author:** ![gardito-git](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gardito-git/32/142211_2.png) [@gardito-git](https://discuss.elastic.co/u/gardito-git)\
**Post date:** [March 25, 2025, 1:49am UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300/3 "2025-03-25T01:49:54Z")

</div>

No it's same,  
Sorry I have typo  
Good news, after I added `xpack.monitrong` things, now it go online, but the Roles on the data node are missing, here my updated elasticsearch.yml

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/324a7fb69c35f9e1c3713fe453ef088323369b76.png)

Master :

```auto
cat /etc/elasticsearch/elasticsearch.yml
path:
  data: /var/lib/elasticsearch
  logs: /var/log/elasticsearch
cluster:
  name: your-prop-firm
  initial_master_nodes:
    - ypf-master
node:
  name: ypf-master
  roles:
    - master
    - remote_cluster_client
network.host: 0.0.0.0
http.port: 9200
transport.port: 9300
bootstrap.memory_lock: false

xpack.security:
  enabled: true
  http.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem

  transport.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem
    # verification_mode: certificate
    verification_mode: none

xpack.monitoring.enabled: true
xpack.monitoring.collection.enabled: true
xpack.monitoring.elasticsearch.collection.enabled: true

```

Data :

```auto
cat /etc/elasticsearch/elasticsearch.yml
path:
  data: /mnt/elasticsearch/data
  logs: /mnt/elasticsearch/logs

cluster:
  name: your-prop-firm
node:
  name: ypf-data-1
  roles:
    - data
    - remote_cluster_client
network.host: 0.0.0.0
http.port: 9200
transport.port: 9300
discovery.seed_hosts:
  - "master.es.dev.xxx"
bootstrap.memory_lock: false

xpack.security:
  enabled: true
  http.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem

  transport.ssl:
    enabled: true
    certificate: /etc/elasticsearch/certs/certificate.crt
    key: /etc/elasticsearch/certs/private_key.pem
    # verification_mode: certificate
    verification_mode: none

xpack.monitoring.enabled: true
xpack.monitoring.collection.enabled: true
xpack.monitoring.elasticsearch.collection.enabled: true

```

So how to make this normal, shows up the Data Node Roles ?

---

<div class="post-metadata">

**Author:** ![Musab\_Dogan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/musab_dogan/32/70691_2.png) [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Post date:** [March 28, 2025, 11:28pm UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300/4 "2025-03-28T23:28:59Z")

</div>

Happy to hear it works! If the node roles flapping to `N/A` the following article can help. [Elastic Support Hub](https://support.elastic.co/knowledge/993bbd65)
