# Filebeat - Non-zero metrics in the last 30s

**URL:** <https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 15, 2020, 1:47am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216 "2020-07-15T01:47:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![saravananveera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravananveera/32/59765_2.png) [@saravananveera](https://discuss.elastic.co/u/saravananveera)\
**Post date:** [July 15, 2020, 1:47am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216/1 "2020-07-15T01:47:10Z")

</div>

Apparently logs are transferred from Filebeat to logstash, however the filebeat logs continiously show this message:

2020-07-15T01:18:20.789Z INFO [monitoring] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":164920,"time":{"ms":37}},"total":{"ticks":1260130,"time":{"ms":282},"value":1260130},"user":{"ticks":1095210,"time":{"ms":245}}},"info":{"ephemeral\_id":"8f755a57-1431-4a63-9a10-985fdbd764a2","uptime":{"ms":107460017}},"memstats":{"gc\_next":4985264,"memory\_alloc":3396320,"memory\_total":376637838888}},"filebeat":{"events":{"active":-16,"added":186,"done":202},"harvester":{"open\_files":1,"running":1}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":202,"active":-8,"batches":30,"total":194}},"outputs":{"kafka":{"bytes\_read":3038,"bytes\_write":81397}},"pipeline":{"clients":1,"events":{"active":3,"published":186,"total":186},"queue":{"acked":202}}},"registrar":{"states":{"current":1,"update":202},"writes":{"success":30,"total":30}},"system":{"load":{"1":0,"15":0.23,"5":0.1,"norm":{"1":0,"15":0.0575,"5":0.025}}}}}}

using:

1. logstash-6.3.1
2. kafka\_2.12-2.2.0
3. zookeeper-3.4.14
4. elasticsearch-6.3.1
5. kibana-6.3.1
6. filebeat-6.3.1

#============================= Filebeat modules ===============================

#=========================== Filebeat inputs =============================

filebeat.inputs:

- type: log

#-------------------------- Kafka Output ----------------------------------  
output.kafka:

# initial brokers for reading cluster metadata

enabled: true  
hosts: ["kafka Ip address:9092"]

# message topic selection + partitioning

topic: '%{[fields][log\_topics]}'  
partition.round\_robin:  
reachable\_only: false

required\_acks: 1  
compression: gzip  
max\_message\_bytes: 1000000

We have check the logs in the kafka there is no log on it. Can you please help to fix this issue.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [July 15, 2020, 8:48am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216/2 "2020-07-15T08:48:20Z")

</div>

Hi!

The message you see is not an error message and it logs Filebeat's internal statistics. Since logs are being shipped to Logstash then Filebeat is properly configured.

C.

---

<div class="post-metadata">

**Author:** ![saravananveera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravananveera/32/59765_2.png) [@saravananveera](https://discuss.elastic.co/u/saravananveera)\
**Post date:** [July 15, 2020, 11:14am UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216/3 "2020-07-15T11:14:16Z")

</div>

Hi @ChrsMark

Still i'm not able to receive the logs from filebeat to logstash, I have received this error log also from filebeat. kindly check and help me.

2020-07-15T11:07:21.306Z INFO kafka/log.go:36 client/metadata fetching metadata for all topics from broker [ip203.ip-139-99-112.net:9092](http://ip203.ip-139-99-112.net:9092)

Logstash conf:

input {  
kafka {  
bootstrap\_servers =\>["localhost:9092"]  
topics =\> ["sscplblogs"]  
codec =\> "json"  
add\_field =\> { "logz" =\> "plblogz" }  
}  
}

output {

if [logz] == "plblogz" {  
elasticsearch {  
hosts =\> ["Elastic IP:9200"]  
index =\> "plblogs-%{+YYYY.MM.dd}"  
}  
file {  
path =\> "/var/log/logstash/plblogs.log"  
}  
}  
}

Kafka:

bin/kafka-topics.sh --describe --zookeeper localhost:2181 --topic sscplblogs  
Topic:sscplblogs PartitionCount:3 ReplicationFactor:1 Configs:  
Topic: sscplblogs Partition: 0 Leader: 0 Replicas: 0 Isr: 0  
Topic: sscplblogs Partition: 1 Leader: 0 Replicas: 0 Isr: 0  
Topic: sscplblogs Partition: 2 Leader: 0 Replicas: 0 Isr: 0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2020, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-non-zero-metrics-in-the-last-30s/241216/4 "2020-08-12T13:14:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
