# Elasticsearch and Logstash monitoring not showing all logstash nodes

**URL:** <https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213>\
**Category:** Elastic Search\
**Created:** [May 16, 2025, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213 "2025-05-16T09:49:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbocquet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbocquet/32/105594_2.png) [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Post date:** [May 16, 2025, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/1 "2025-05-16T09:49:24Z")

</div>

Hi,

Something strange...

I have a 3 nodes cluster : elk1, elk2, and elk3.

- nodes elk1 and elk3 are "clones" for redondancy purpose and have logstash installed.
- node elk2 has only elasticsearch installed and is a warm/cold data storage for both elk1 and elk3.

In the management tab, I can see all my logstash pipelines stats from elk1 ans elk3, but I only see 1 logstash node.

 ![Cluster overview](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f52fed9fb71c55c65219600300fcb64c00db210.png)  
 ![Logstash overview](https://us1.discourse-cdn.com/elastic/original/3X/5/5/5555efa1075f3552059a99ee0ca918890612a9e1.png)  
 ![Logstash pipelines](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68407eabd2bd77ebba105fd993f9cb4b884c987b.png)

Any explaination is welcome.

Thx

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 16, 2025, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/2 "2025-05-16T11:01:46Z")

</div>

> [@sbocquet](#):
>
> nodes elk1 and elk3 are "clones" for redondancy purpose

Are all your nodes configured to be master eligible? You have 3 nodes in the cluster, so the 3 nodes should be configured as maste eligible in this case.

> [@sbocquet](#):
>
> In the management tab, I can see all my logstash pipelines stats from elk1 ans elk3, but I only see 1 logstash node.

How are you getting the monitoring data? Using metricbeat? Please share `logstash.yml` and `metricbeat.yml` of both nodes.

---

<div class="post-metadata">

**Author:** ![sbocquet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbocquet/32/105594_2.png) [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Post date:** [May 16, 2025, 11:45am UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/3 "2025-05-16T11:45:15Z")

</div>

Hi,

Only elk1 and elk3 are master at the moment.  
I gonna make elk2 master is necessary.

Metrics are configured with logstash.yml

For elk1 :

```auto
xpack.monitoring.elasticsearch.hosts: ["https://elkglbvprd1.mycorp.fr:9200"]
xpack.monitoring.elasticsearch.ssl.truststore.path: "/etc/logstash/certs/elastic-stack-ca.p12"
xpack.monitoring.elasticsearch.ssl.truststore.password: "MYCORP"
xpack.monitoring.elasticsearch.ssl.keystore.path: "/etc/logstash/certs/http.p12"
xpack.monitoring.elasticsearch.ssl.keystore.password: "MYCORP"
xpack.monitoring.elasticsearch.ssl.verification_mode: certificate

```

For elk3 :

```auto
xpack.monitoring.elasticsearch.hosts: ["https://elkglbvprd3.mycorp.fr:9200"]
xpack.monitoring.elasticsearch.ssl.truststore.path: "/etc/logstash/certs/elastic-stack-ca.p12"
xpack.monitoring.elasticsearch.ssl.truststore.password: "MYCORP"
xpack.monitoring.elasticsearch.ssl.keystore.path: "/etc/logstash/certs/http.p12"
xpack.monitoring.elasticsearch.ssl.keystore.password: "MYCORP"
xpack.monitoring.elasticsearch.ssl.verification_mode: certificate

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 16, 2025, 2:54pm UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/4 "2025-05-16T14:54:54Z")

</div>

> [@sbocquet](#):
>
> Only elk1 and elk3 are master at the moment.  
> I gonna make elk2 master is necessary.

This is a requirement, if your master node goes down your entire cluster will go down, you do not have a resilient cluster with just 2 master nodes, the minimum is 3 master nodes.

> [@sbocquet](#):
>
> Metrics are configured with logstash.yml

This is the legacy monitoring, not sure what is the issue here, but I think it is missing the `xpack.monitoring.enabled: true` configuration.

Not sure why it is working even without it.

---

<div class="post-metadata">

**Author:** ![sbocquet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbocquet/32/105594_2.png) [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Post date:** [May 16, 2025, 3:12pm UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/5 "2025-05-16T15:12:36Z")

</div>

Sorry, didn't put the full conf. file.

```auto
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.username: "logstash_system"
xpack.monitoring.elasticsearch.password: "my_logstash_pwd"

```

One thing I find strange in the logstash monitoring page is the IP address : 127.0.0.1  
As each logstash report to its own elasticsearch, monitoring datas are maybe sent with the localhost address, and so both have "127.0.0.1" and maybe elasticsearch is lost betweeen the two ?

To compare, Elasticsearch nodes have their IP correct.

 ![Elasticsearch nodes](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14353eab34e0fbc005d3535bef7a85ae5b5a733b.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 16, 2025, 3:45pm UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/6 "2025-05-16T15:45:20Z")

</div>

> [@sbocquet](#):
>
> As each logstash report to its own elasticsearch, monitoring datas are maybe sent with the localhost address, and so both have "127.0.0.1" and maybe elasticsearch is lost betweeen the two ?

Not sure if this is the issue, but this is expected because this IP address is the IP of the logstash API, which per default will bind to `127.0.0.1`.

Being honest, not sure what is the problem here, but I've never used this legacy monitoring with Logstash, always used Metricbeat, I would suggest that you see if you can change the monitoring to use Metricbeat at least.

The Legacy monitoring was deprecated on 7.16.

---

<div class="post-metadata">

**Author:** ![sbocquet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sbocquet/32/105594_2.png) [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Post date:** [May 16, 2025, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-and-logstash-monitoring-not-showing-all-logstash-nodes/378213/7 "2025-05-16T15:47:37Z")

</div>

OK... Found the solution.

The elk3 server was cloned from the elk1 one.  
Logstash as a UUID set in /var/lib/logstash when started for the first time but this file isn't deleted when stopped.

So both servers had the same UUID... and so was the monitoring stats problems.

To solve that, just:

- Stop logstash service
- Delete the /var/lib/logstash/uuid file
- Start logstash service
- New file is generated and monitoring is OK now.

Cheers.
