# Logstash missing from monitoring after 5.6.2 upgrade

**URL:** https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030
**Category:** Logstash
**Created:** [September 27, 2017, 8:44pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030 "2017-09-27T20:44:41Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)
#### Post date: [September 27, 2017, 8:44pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/1 "2017-09-27T20:44:41Z")

</div>

After upgrading elasticsearch, kibana, logstash and corresponding x-pack plugins, Logstash monitoring is missing from Kibana.

When looking at the monitoring indexes it seems the .monitoring-logstash-6-2017.09.27 index is not beeing updated since the upgrade.

Found this [https://www.elastic.co/guide/en/x-pack/current/monitoring-troubleshooting.html](https://www.elastic.co/guide/en/x-pack/current/monitoring-troubleshooting.html) but dont have x-pack security enabled so does not work.

Any tips to what is wrong?

---

<div class="post-metadata">

### Author: ![cutch69](https://avatars.discourse-cdn.com/v4/letter/c/977dab/32.png) [@cutch69](https://discuss.elastic.co/u/cutch69)
#### Post date: [September 29, 2017, 7:38pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/2 "2017-09-29T19:38:21Z")

</div>

let me know what you find.

right now i am adding the remove xpack security on all my nodes and rebooting.

if that dosent work. i will roll back to a snapshot before i did the upgrade on the logstash servers.

---

<div class="post-metadata">

### Author: ![Sam\_Chen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sam_chen/32/67249_2.png) [@Sam\_Chen](https://discuss.elastic.co/u/Sam_Chen)
#### Post date: [October 2, 2017, 1:57am UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/3 "2017-10-02T01:57:19Z")

</div>

try to set below config in logstash.yaml if security disabled.

xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: "changeme"

---

<div class="post-metadata">

### Author: ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)
#### Post date: [October 2, 2017, 10:19am UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/4 "2017-10-02T10:19:56Z")

</div>

@Sam_Chen that worked like a charm!!! Thanks 😃

---

<div class="post-metadata">

### Author: ![cutch69](https://avatars.discourse-cdn.com/v4/letter/c/977dab/32.png) [@cutch69](https://discuss.elastic.co/u/cutch69)
#### Post date: [October 2, 2017, 12:00pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/5 "2017-10-02T12:00:17Z")

</div>

so i though by disabling secuirty in the es.yml and kibana.yml it would disable it in logstash. was this a new added feature of 5.6.2

---

<div class="post-metadata">

### Author: ![pickypg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pickypg/32/62409_2.png) [@pickypg](https://discuss.elastic.co/u/pickypg)
#### Post date: [October 9, 2017, 9:07pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/6 "2017-10-09T21:07:17Z")

</div>

Hi @Benjamin_Cuthbert/ @flalar

There was a bug in 5.6.2, which did not exist in 5.6.0 or 5.6.1, of X-Pack monitoring for _Logstash_ , which makes forces it to require a password even when you are not using authentication with Elasticsearch. There should be a subtly logged error message during the startup of Logstash to that effect.

> You must set the password using the xpack.monitoring.elasticsearch.password in logstash.yml

This has been fixed for the forthcoming release of 5.6.3.

Setting _any_ password is enough to satisfy this requirement. For example:

```yaml
# logstash.yml
xpack.monitoring.elasticsearch.password: anypassword

```

Until Elasticsearch 6.0, all passwords default to "`changeme`", so this is a solid default to use there as well, but do beware that Elasticsearch 6.0 is going to remove _all_ default passwords.

Hope that helps,  
Chris

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 6, 2017, 9:07pm UTC](https://discuss.elastic.co/t/logstash-missing-from-monitoring-after-5-6-2-upgrade/102030/7 "2017-11-06T21:07:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
