# Filebeat monitoring metrics not visible in ElasticSearch

**URL:** <https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, filebeat, metricbeat\
**Created:** [September 30, 2022, 4:11pm UTC](https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596 "2022-09-30T16:11:37Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![ppine7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppine7/32/111560_2.png) [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Post date:** [October 6, 2022, 2:18pm UTC](https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596/6 "2022-10-06T14:18:49Z")

</div>

After further struggles with getting the actual ES logs (which is not that simple on hosted ES clusters at [elastic.io](http://elastic.io)!!) - I finally was able to access them and noticed many of the following WARNings:

```auto
16:32:50.998
elasticsearch.server
[elasticsearch.server][WARN] Authentication to realm found failed - Password authentication failed for ec-local-beats-monitor

```

I'm not sure who this user might be: "ec-local-beats-monitor" ?? and where it is configured/set - definitely not in my filebeat.yml config for the Filebeat process...

Could this be related to the issue with loosing/ not indexing Filebeat metrics data into ES?

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596)._
