# Elastic-Agent vs Metricbeat standalone

**URL:** <https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270>\
**Category:** Elastic Security\
**Created:** [October 15, 2020, 8:50pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270 "2020-10-15T20:50:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [October 15, 2020, 8:50pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/1 "2020-10-15T20:50:45Z")

</div>

Hi,

**Note: Running in Windows Server 2012**

I have a couple of questions about the `Metricbeat` service running under `Elastic-Agent`:

1. Can modules (for example `MSSQL`) be activated like the standalone version of Metricbeat?
2. How do I load the dashboards in Kibana? Should I modify the file `C:\Program Files\Elastic-Agent\data\install\metricbeat-7.9.2-windows-x86_64\metricbeat.yml` to add the connection information and be able to run command `.\metricbeat.exe setup`?
3. After installing `Elastic-Agent` I don't see that an index like `metricbeat-7.9.2-x` has been created in Elasticsearch. Apparently this `Metricbeat` sends data only to index `.ds-metrics-elastic.agent.metricbeat-default`. I assume that the preconfigured dashboards that the `Metricbeat` installation incorporates will not have data to show, since it reads from the index `metricbeat-7.9.2-x` that is not being created?
4. If this `Metricbeat` does not allow me (due to the previous questions) to make use of the dashboards and the `MSSQL` data I want to monitor, can I install a standalone version of `Metricbeat` on the same machine where `Elastic-Agent` is running, without both `Metricbeat` processes coming into conflict?

Note: I acknowledge that this topic is about beats and I considered putting it in the Beats section, but since these are specific questions about beasts running under Elastic-Agent, I think it makes more sense to post it in this section. Please forgive me if I'm wrong.

Thank you

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [October 15, 2020, 10:37pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/2 "2020-10-15T22:37:14Z")

</div>

1. Not currently that I have found. If you do find it please share. They have mentioned it. Think one agent to rule them all but it's still "beta" for ingest manager. Best to stick with the beats for SQL for awhile as that's a tested method and you don't want to loss data.
2. Not currently an option that's documented but should be coming in soon.
3. Create and index called metric-\* and you'll be able to see them. Between the default metricbeat and metrics you will end up with a conflict in the index on host.ip if you have an older beat sending still to metricbeat.
4. Yes. Disable duplicate options "cpu, ram, disk io" in system in the metricbeat so your not getting duplicate data it helps drastically in terms of performance. I forgot that one a few times.... This is only required on 2012/2012r2. On 2016+ you can disable system completely and you will get metrics.

As a word of friendly advise start going through your visualizations and adding metric-\* to them after you create the index so you can slow roll the move over to the ingest agent. The beats will still be around for a long time for custom data import.

Elastic-Agent isn't Elastic Security. That is Elastic Endpoint which is another part of the ingest manager. So many things to keep tabs on....

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [October 16, 2020, 12:49pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/3 "2020-10-16T12:49:31Z")

</div>

Hi @PublicName, and thank you for taking your time to answer my questions. Here a few comments:

- I did modify file `C:\Program Files\Elastic-Agent\data\install\metricbeat-7.9.2-windows-x86_64\metricbeat.yml` temporarily to add connection information. After that I was able to run command `.\metricbeat.exe setup`. Metricbeat dashboards where successfully loaded into Kibana and index `metricbeat-7.9.2-x` was created as part of the process. After that I reverted the changes in the `.yml` file. The setup process worked fine, but the index `metricbeat-7.9.2-x` is not receiving any data because the Metricbeat process running under Elastic-Agent apparently only ships data to index `.ds-metrics-elastic.agent.metricbeat-default`. So even when I was able to get the dashboards and index, they are useless.

- Ended up (for now) disabling the `system` integration for this server. Then installed the standalone Metricbeat, which is working fine.

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [October 16, 2020, 4:15pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/4 "2020-10-16T16:15:39Z")

</div>

Well that's one way of doing it. Was hoping for a more gui driven based as it can be updated from the gui side.

Create a index pattern metric.\* and you will see the metrics. That will cover the different ones all the data goes into.

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [February 25, 2021, 1:48pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/5 "2021-02-25T13:48:21Z")

</div>

Feel free to correct me if I'm wrong but in 7.11.2 it seems like the metricbeat dashboards that we're used to can now be found in the [Metrics System] Overview instead of the [Metricbeat System] Overview. In other words, [Metrics System] Overview = [Metricbeat System] Overview when utilizing the Elastic Agent.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:15am UTC](https://discuss.elastic.co/t/elastic-agent-vs-metricbeat-standalone/252270/6 "2022-11-04T08:15:31Z")

</div>


