# Kibana throwing 404 when trying to view Logstash Node

**URL:** <https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402>\
**Category:** Kibana\
**Created:** [August 1, 2017, 7:07pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402 "2017-08-01T19:07:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jathin](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@Jathin](https://discuss.elastic.co/u/Jathin)\
**Post date:** [August 1, 2017, 7:07pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/1 "2017-08-01T19:07:07Z")

</div>

I have monitoring configured in logstash and Kibana and i get the overview of Logstash all good.  
But as soon as i hit Logstash nodes link on Monitoring tab. I get a 404. I have the kibana log that error for me. But need help understanding this error.

```
{
	"type": "request",
	"@timestamp": "2017-08-01T19:00:18Z",
	"tags": ["monitoring-ui",
	"error"],
	"pid": 12430,
	"level": "error",
	"message": "Not Found",
	"error": {
		"message": "Not Found",
		"name": "Error",
		"stack": "Not Found :: {\"path\":\"/.monitoring-data-2/logstash/ef34eee7-270b-4633-a27b-db79bd7f21ce\",\"query\":{\"_source\":\"timestamp,logstash.process.cpu.percent,logstash.jvm.mem.heap_used_percent,logstash.jvm.uptime_in_millis,logstash.events.out,logstash.logstash.http_address,logstash.logstash.name,logstash.logstash.host,logstash.logstash.uuid,logstash.logstash.status,logstash.logstash.version,logstash.logstash.pipeline,logstash.reloads\"},\"statusCode\":404,\"response\":\"{\\\"_index\\\":\\\".monitoring-data-2\\\",\\\"_type\\\":\\\"logstash\\\",\\\"_id\\\":\\\"ef34eee7-270b-4633-a27b-db79bd7f21ce\\\",\\\"found\\\":false}\"}\n at respond (/usr/share/kibana/node_modules/elasticsearch/src/lib/transport.js:295:15)\n at checkRespForFailure (/usr/share/kibana/node_modules/elasticsearch/src/lib/transport.js:254:7)\n at HttpConnector.<anonymous> (/usr/share/kibana/node_modules/elasticsearch/src/lib/connectors/http.js:157:7)\n at IncomingMessage.bound (/usr/share/kibana/node_modules/elasticsearch/node_modules/lodash/dist/lodash.js:729:21)\n at emitNone (events.js:91:20)\n at IncomingMessage.emit (events.js:185:7)\n at endReadableNT (_stream_readable.js:974:12)\n at _combinedTickCallback (internal/process/next_tick.js:80:11)\n at process._tickDomainCallback (internal/process/next_tick.js:128:9)"
	}
}
```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 4, 2017, 12:28pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/2 "2017-08-04T12:28:16Z")

</div>

Is this happening for any Logstash node or just a specific one?

What version of the Elastic stack are you using?

---

<div class="post-metadata">

**Author:** ![Jathin](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@Jathin](https://discuss.elastic.co/u/Jathin)\
**Post date:** [August 4, 2017, 1:15pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/3 "2017-08-04T13:15:50Z")

</div>

Using Logstash 5.5.0 and Elastic & Kibana at 5.4.2.

So monitoring data from logstash is on .monitoring-logstash-2-\* index and Kibana is generating query for .monitoring-data-2-\* index. All other links on Monitoring Tab for Kibana is working fine.

So is this because of version mismatch. Is there a way i can change the where the monitoring info for logstash is getting indexed to.. or is there a way to tell kibana to look at .monitoring-logstash index rather than .monitoring-data index.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 4, 2017, 4:21pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/4 "2017-08-04T16:21:59Z")

</div>

Running differing versions of the product isn't recommended because it can cause issues like the one you are seeing. I would suggest upgrading Kibana (and any other parts of your Elastic stack) to 5.5.0 as well.

Shaunak

---

<div class="post-metadata">

**Author:** ![Jathin](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@Jathin](https://discuss.elastic.co/u/Jathin)\
**Post date:** [August 4, 2017, 5:17pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/5 "2017-08-04T17:17:18Z")

</div>

> **[Support Matrix](https://www.elastic.co/support/matrix#show_compatibility)**

above page says ES/Kibana 5.4x with Logstash 5.5x. am i reading it wrong?

there is a note too..

> - We recommend running the latest version of Beats, Logstash, and ES-Hadoop; earlier versions will work with reduced functionality.

and hence logstash was updated to latest, our infra team requires additional effort to update ES and Kibana and xpack and custom realms and maybe other breaking changes.

Upgrading logstash is very easy, hence i was thinking if there is a hack in Kibana, it would be really helpful. I am ready to add extra configurations in logstash to make this happen.

Thanks

---

<div class="post-metadata">

**Author:** ![pickypg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pickypg/32/62409_2.png) [@pickypg](https://discuss.elastic.co/u/pickypg)\
**Post date:** [August 4, 2017, 6:20pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/6 "2017-08-04T18:20:38Z")

</div>

@Jathin

You are reading that correctly. However, we had to make a breaking change (it is documented in the breaking changes list for X-Pack monitoring 5.5) to the monitoring schema prior to 6.0 because we are removing support for multiple `_type`s. The new schema is ready for 6.x _and_ it's far more efficient.

A good general rule of thumb is that, even ignoring breaking changes (which should be rare), it is always better to have the Monitoring cluster be the same or newer version of Elasticsearch than the monitored stack. Getting ahead of it is _generally_ going to be okay, but there's always the risk of pitfalls like this in doing so.

This change went into X-Pack Monitoring 5.5+ and Elasticsearch nor Kibana recognize the `.monitoring-data-2` index in 5.5+. In Logstash 5.5+, we no longer send the data that used to be routed to that index because it expects the monitoring cluster to be the same or newer version.

You could hack together a document so that the page can be displayed, if that's your motivation.

```auto
GET /.monitoring-logstash-*/_search
{
  "query": {
    "bool": {
      "must": [
         { "term": { "logstash_stats.logstash.uuid": "ef34eee7-270b-4633-a27b-db79bd7f21ce" } }
      ]
    }
  },
  "sort": {
    "timestamp": { "order": "desc" }
  }
}

```

Then, from the document that it returns, copy the `_source` and replace `logstash_stats` with `logstash`.

```auto
PUT /.monitoring-data-2/logstash/ef34eee7-270b-4633-a27b-db79bd7f21ce
{
  ...
}

```

This will provide a _stale_ view of the summary bar for that instance of Logstash, but it will have live charts that are relevant.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 6:20pm UTC](https://discuss.elastic.co/t/kibana-throwing-404-when-trying-to-view-logstash-node/95402/7 "2017-09-01T18:20:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
