I have installed metricbeat in some virtual machines and started sending data to elasticsearch. I have imported default dashboards also for the same.
The problem is, the dashboard is not visualizing all data, instead its showing only for 3 VM's. If i convert the timing to last 7 days its visualizing, but for 15 or 30 mins time category i'm not getting all the data.
Could you check the timestamps of the data points if they are all as they should be or if there are some offsets? What is the minimum duration to select where all data shows up?
If I understand it right, with 15 minutes you don't see all the data. What is the minimum you see all data ? For example 3 hours or 24 hours? Or only 7 days?
@ruflin when i reduce dthe time to 15mins i get only 2 servers, sometimes 1 server.
When i use 24 hours or 7 days i'm able to see all the hosts monitored.
That kind of indicates for me that there is something up with the timestamps / time difference.
I assume you always see the same 1-2 servers in the last 15 minutes? Could you share 1 event for each of this server and 1-2 events of servers that you only see when you set it to 24h?
So the event you shared under 7 days does not show up in the "last 30 minutes" when you searched for it? But later it shows up with the exact timestamp?
I would like to figure out what it is the minimal period you have to set to see all events. It seems not only with 7 days you see everything but also with 24 hours? What about 1h, 2h ?
Are all your VM's in the same time zone? Do they have different setup?
@ruflin Yeah you are rite it shows up with exact time stamp only wen i choose 7 days or more. I'm not getting any details even if i choose 24hr or 1hr or 2hr.
For all these hours 24hr or 1hr or 2hr : I'm getting only one VM.
If i choose 7 days or more : I'll get to see all other vm's.
Few Vm's are running on different time as well.
As a best practice i would like to set a minimal of 15 or 30mins, so that the NOC team can keep watching the server performance.
The part I'm struggling is that you mentioned in your first post that the data shows up in discovery.
What do you get when you click on a single host that is not shown when you only look at the last 5 minutes and then scroll down to see cpu usage for example? Do you see the CPU usage for all 7 days or is the last part of the visualisation empty? See here as an example.
Was just wondering in case the same issue arise again, where should i need to look or should i need to restart cluster everytime when such issue happens.
I really have a hard time to understand on what happened here. A cluster restart should definitively not be needed. As after your cluster restart it seems all the data showed up, not only since the restart so all the data was there all the time as you described in the beginning.
I'm happy it works now, in case it breaks again, lets investigate further.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.