# Metricbeat data not flowing into elasticsearch

**URL:** <https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 7, 2018, 12:50pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328 "2018-08-07T12:50:52Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 7, 2018, 12:50pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/1 "2018-08-07T12:50:53Z")

</div>

Hi All,

Got into a small trouble, have installed metric beat in few VM's which was sending data to elasticsearch and was able to view all the dashboards properly, and the VM firewall was turned off.

There was a vulnerability so i had to enable the windows firewall and post that metricbeat data from those machines are not flowing into elasticsearch, I have created an inbound and outbound rule to allow port 5601 and 9200 in the Vm, still not luck. Any advice on this please?

To confirm the port open i have done a telnet to elasticsearch and kibana with respective port and its working.

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 1:22pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/2 "2018-08-07T13:22:34Z")

</div>

Hi @Gauti,

In principle this doesn't look like a problem on metricbeat 🤔 Were the firewall rules added in the host or in the guests?  
Did you try to connect with telnet from the same guests where metricbeat is running?  
Can you see any error in metricbeat logs?

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 7, 2018, 1:33pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/3 "2018-08-07T13:33:32Z")

</div>

yeah @jsoriano You are rite there is no problem with metricbeat,but for this scenario i thought this is the best place to ask the question.  
firewall rules are added in guest, yes i tried telnet with both the ports 5601 and 9200, telnet is happening successfully.  
mericbeat log doesnot have any information it has only one line which contains the config file path and logfile path, nothing else there in the log file.

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 1:48pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/4 "2018-08-07T13:48:53Z")

</div>

This is weird, I guess you already tried to restart metricbeat after the change in the firewall rules?

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 7, 2018, 3:16pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/5 "2018-08-07T15:16:05Z")

</div>

yeah i did that too, i even restarted the guest OS, still no luck

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 7, 2018, 3:53pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/6 "2018-08-07T15:53:44Z")

</div>

Does `curl` from the guest to port 9200 in elasticsearch also work?

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 8, 2018, 6:17am UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/7 "2018-08-08T06:17:51Z")

</div>

@jsoriano should i need to just mention "curl \<'IP Address'\> 9200" ?

tried the same way its throwing connection refused error

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 8, 2018, 10:03am UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/8 "2018-08-08T10:03:54Z")

</div>

It'd be `curl <IP address>:9200` (notice the `:` between host and port)

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 8, 2018, 10:48am UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/9 "2018-08-08T10:48:54Z")

</div>

i'm getting the output @jsoriano

FYI..  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/7/979663e5ffb34d3f2048204f88e26900efd6f63e.png)

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 8, 2018, 11:13am UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/10 "2018-08-08T11:13:19Z")

</div>

Was this executed from the same guest where metricbeat is not working?  
Is metricbeat configured to use the ip address too, or a hostname?

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 8, 2018, 11:55am UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/11 "2018-08-08T11:55:12Z")

</div>

yeah it is from the same guest machine, beat is configured to use IP address only.

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 8, 2018, 12:04pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/12 "2018-08-08T12:04:43Z")

</div>

Umm, let's go back to the root of the question 🙂 How are you checking that there is no data in elasticsearch? I'm thinking now that maybe metricbeat is being able to send data, but is Kibana the one that has problems connecting to elasticsearch and this is why you cannot see anything...

If everything between kibana and elasticsearch is fine, to continue investigating the problem in metricbeat, could you [enable debug logging](https://www.elastic.co/guide/en/beats/metricbeat/6.3/configuration-logging.html#level) with `logging.level: debug` and check again the logs for any problem related with connectivity?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 8, 2018, 12:09pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/13 "2018-08-08T12:09:11Z")

</div>

By the way, you can also test the connectivity between metricbeat and its output with `metricbeat test output`.

---

<div class="post-metadata">

**Author:** ![Gauti](https://avatars.discourse-cdn.com/v4/letter/g/cdc98d/32.png) [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Post date:** [August 8, 2018, 1:01pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/14 "2018-08-08T13:01:52Z")

</div>

my bad ,my bad, my bad.......sorry for wasting your time @jsoriano all these time i was checking whether data is flowing in or not by just clicking the beat.hostname on the lefthand side and checking how many hosts are there.it was showing only one.

After your question only i have searched for beat.hostname in the query field and got the output, yeah i'm getting all the documents flowing into elasticsearch.  
Thank you very much for your patience and proper questions asked.

btw here is the screenshot of connection output  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/7/577b546c7d70d1c42495075398adcec3105c431e.png)

Thanks  
Gauti

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 8, 2018, 1:13pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/15 "2018-08-08T13:13:47Z")

</div>

No problem, happy to see that you found the issue 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2018, 1:13pm UTC](https://discuss.elastic.co/t/metricbeat-data-not-flowing-into-elasticsearch/143328/16 "2018-09-05T13:13:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
