# Kibana monitoring shows only 1 Logstash instance

**URL:** <https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564>\
**Category:** Kibana\
**Created:** [June 27, 2018, 8:03am UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564 "2018-06-27T08:03:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [June 27, 2018, 8:03am UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/1 "2018-06-27T08:03:25Z")

</div>

Hi,

I am using ELK GA 6.3.0. I have enabled X-Pack monitoring to monitor my Logstash. I have 2 Logstash instances, which has same configuration, consuming from a Kafka topic having 11 partitions. The config is like below.

```
input {
	kafka{
		group_id => "group1"
		topics => ["topic1"]
		bootstrap_servers => "192.168.0.1:9092,192.168.0.2:9092,192.168.0.3:9092"
		consumer_threads => "6"
		codec => "json"
	}
}

```

I have enabled X-Pack monitoring in `logstash.yml` file, and it is like below;

**node 1**

```
node.name: logstash_0.10
config.reload.automatic: true
config.reload.interval: 30s
http.host: "192.168.0.10"
http.port: 9601
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.url: ["http://192.168.0.1:9210/","http://192.168.0.2:9210/","http://192.168.0.3:9210/"]
xpack.monitoring.collection.interval: 10s
xpack.monitoring.collection.pipeline.details.enabled: true
xpack.management.enabled: false
xpack.management.pipeline.id: ["main", "apache_logs"]
xpack.management.elasticsearch.url: ["http://192.168.0.1:9210/","http://192.168.0.2:9210/","http://192.168.0.3:9210/"]
xpack.management.logstash.poll_interval: 5s

```

**node 2**

```
node.name: logstash_0.11
config.reload.automatic: true
config.reload.interval: 30s
http.host: "192.168.0.11"
http.port: 9601
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.url: ["http://192.168.0.1:9210/","http://192.168.0.2:9210/","http://192.168.0.3:9210/"]
xpack.monitoring.collection.interval: 10s
xpack.monitoring.collection.pipeline.details.enabled: true
xpack.management.enabled: false
xpack.management.pipeline.id: ["main", "apache_logs"]
xpack.management.elasticsearch.url: ["http://192.168.0.1:9210/","http://192.168.0.2:9210/","http://192.168.0.3:9210/"]
xpack.management.logstash.poll_interval: 5s

```

As you can see, the only difference b/w these configs are in `node.name` and `http.host`. But when I open my Kibana monitoring page, it shows only one instance like below;

![upl](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bcca0afbaf28e8c760a3c31f48e097508bc6d118.PNG)

But I have confirmed both Logstash instances are running, and is visible in my Kafka Manager. In my Kafka manager, I can see that both consumers are consuming. In the **Nodes tab** of Logstash monitoring page of Kibana monitoring plugin page, sometimes the node name will be **logstash\_0.10** , and after some time, after reloading the page, it will change to **logstash\_0.11**

But why only one Logstash node name, at a time, in Monitoring UI?

Thanks.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [July 2, 2018, 2:29pm UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/2 "2018-07-02T14:29:04Z")

</div>

There is a `data/` folder in your Logstash install folder. In that folder there is a `uuid` file. Can you check the contents of this file for both your Logstash instances?

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [July 3, 2018, 7:55am UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/3 "2018-07-03T07:55:25Z")

</div>

@shaunak the uuid looks same for both instances `a0b34ad3-7d2b-4c59-8e8d-c4367bd61d91`

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [July 3, 2018, 2:08pm UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/4 "2018-07-03T14:08:40Z")

</div>

Okay, that would explain why you are seeing only one node in the Monitoring UI. The UUID uniquely identifies a node so two nodes with the same UUID will be seen as one.

The solution is to simply stop _one_ of your two Logstash nodes, delete the `data/uuid` file for that node and then restart the node. Logstash will recreate the `data/uuid` file automatically upon restart, and store a new, unique UUID in it. Then, if you look in the Monitoring UI, you should start seeing two Logstash instances.

---

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [July 4, 2018, 5:10am UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/5 "2018-07-04T05:10:48Z")

</div>

Alright. So Logstash will create the uuid file if its not present. Lemme ask you something. Is it ok, if I manually assign a uuid? For example, if i modify `a0b34ad3-7d2b-4c59-8e8d-c4367bd61d91` to `a0b34ad3-7d2b-4c59-8e8d-logstash1` , will it work? so that I can manually assign unique uuid across my cluster like `a0b34ad3-7d2b-4c59-8e8d-logstash1`, `a0b34ad3-7d2b-4c59-8e8d-logstash2` etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2018, 5:10am UTC](https://discuss.elastic.co/t/kibana-monitoring-shows-only-1-logstash-instance/137564/6 "2018-08-01T05:10:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
