# Metricbeat elasticsearch module not showing index fields

**URL:** <https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, metricbeat\
**Created:** [March 4, 2019, 7:16pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780 "2019-03-04T19:16:27Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 4, 2019, 7:16pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/1 "2019-03-04T19:16:27Z")

</div>

node and node\_stats are working but not seeing index fileds coming into metricbeat.

- module: elasticsearch  
metricsets:
  - node

# - node\_stats

  - index
  - index\_summary

# - shard
period: 10s  
hosts: ["http://_._._._:9200"]

---

<div class="post-metadata">

**Author:** ![cachedout](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cachedout/32/38707_2.png) [@cachedout](https://discuss.elastic.co/u/cachedout)\
**Post date:** [March 5, 2019, 9:32pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/2 "2019-03-05T21:32:23Z")

</div>

Hi Frank,

I'm unable to replicate this. What version of Metricbeat are you on? Do you see any errors in the logs either from Metricbeat or from Elasticsearch? If you run Metricbeat with `-d -e '*'` do you see the fields present in the JSON data being sent? Finally, could you please repost your Elasticsearch module configuration and preserve the formatting so that we can make certain is is valid? Thanks.

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 6, 2019, 1:29pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/3 "2019-03-06T13:29:20Z")

</div>

metricbeat version 6.6.0 (amd64)  
Elasticsearch is 6.4.3.

Not sure how to preserve the formatting though.

I was abe to get index fields from another cluster that is Elasticsearch 6.6.0. Not sure if that is the issue or not.

I am attaching the config and log output

 ![metricbeat_ana_201903061111](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d15aa60399b64e5ddef0bbb1ef29480a80a4ebd.png)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 12, 2019, 8:23am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/4 "2019-03-12T08:23:44Z")

</div>

Could you try to enabled only `index` metricset and run metricbeat with `-e -d "*"` option and paste the output here? (it's going to be quite a lot).

To format the output best use 3 ticks before and after the code.

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 12, 2019, 3:10pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/5 "2019-03-12T15:10:49Z")

</div>

```auto
sudo cat /etc/metricbeat/modules.d/elasticsearch.yml
- module: elasticsearch
  metricsets:
  # - node
  # - node_stats
  - index
  # - index_summary
  # - shard
  period: 10s
  hosts: ["http://*.*.*.*:9200"]

```

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 12, 2019, 3:26pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/6 "2019-03-12T15:26:40Z")

</div>

Output is too large

```auto
2019-03-12T14:59:59.032Z WARN [cfgwarn] index/index.go:49 BETA: the elasticsearch/index metricset is beta

```

---

<div class="post-metadata">

**Author:** ![Mike\_Place](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_place/32/39555_2.png) [@Mike\_Place](https://discuss.elastic.co/u/Mike_Place)\
**Post date:** [March 13, 2019, 6:25pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/7 "2019-03-13T18:25:09Z")

</div>

Is there another place you could post the output where we can see it? Perhaps using a [GitHub gist](http://gist.github.com)?

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 13, 2019, 6:41pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/8 "2019-03-13T18:41:29Z")

</div>

> <https://gist.github.com/frankfoti/a436adf9dcc149b1b750e8d4ccb843b0>

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 14, 2019, 7:38am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/9 "2019-03-14T07:38:23Z")

</div>

Thanks for the ouptut. Based on [https://gist.github.com/frankfoti/a436adf9dcc149b1b750e8d4ccb843b0#file-gistfile1-txt-L565](https://gist.github.com/frankfoti/a436adf9dcc149b1b750e8d4ccb843b0#file-gistfile1-txt-L565) we see that it is started. Any chance you could disable the system module so we have less noise in the log.

Unfortunately the log you posted does not contain enough info to do a first fetch of the index metricset. You have to run it at least 19.9s with your settings above.

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 14, 2019, 1:05pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/10 "2019-03-14T13:05:33Z")

</div>

Output updated on gist

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 15, 2019, 11:47am UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/11 "2019-03-15T11:47:49Z")

</div>

Ok, I just found a very good hint:

```auto
2019-03-14T12:46:52.853Z DEBUG [elasticsearch] index/index.go:71 trying to fetch index stats from a non-master node

```

The index stats can only be fetched from the master node. This is to make sure the same index stats are only reported ones as they are same across all nodes. I assume the node you are talking to here is not he master?

---

<div class="post-metadata">

**Author:** ![frankfoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankfoti/32/26965_2.png) [@frankfoti](https://discuss.elastic.co/u/frankfoti)\
**Post date:** [March 15, 2019, 12:01pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/12 "2019-03-15T12:01:43Z")

</div>

That was the issue. Answers some confusion I had why some were working and not others. Also, as the node switches from active master to master... it turns on and off. All set thank you. Gist snippet updated.

Thanks

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 15, 2019, 12:20pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/13 "2019-03-15T12:20:23Z")

</div>

Glad it's working

@shaunak I wonder if we should keep some state in the metricset and log a message on the Info every time the metricset switches from talking to master or not talking to master to have something for the user on the Info level. I expect master not to constantly move around 🤞

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 15, 2019, 1:09pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/14 "2019-03-15T13:09:28Z")

</div>

I'd rather not keep state. The message in the log that Metricbeat is not talking to a master seems good enough to me. Since that [check](https://github.com/elastic/beats/blob/master/metricbeat/module/elasticsearch/index/index.go#L60) happens in the metricset's `Fetch` method, it will run every time Metricbeat polls Elasticsearch.

So if a master switch happens, Metricbeat would suddenly start emitting the log message when it wasn't previously. I think this is good enough if we're looking at logs over a long enough period of time?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 15, 2019, 1:26pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/15 "2019-03-15T13:26:46Z")

</div>

The log messages I had in mind:

As soon as the Metricset starts talking to a master (once):

`Start collecting elasticsearch.index metricset data as talking to a master node`.

As soon as not talking anymore to master, logging once:

`Stop collecting elasticsearch.index metricset data as not talking to a master node`

Both log messages happen only once when the switch happens.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2019, 3:26pm UTC](https://discuss.elastic.co/t/metricbeat-elasticsearch-module-not-showing-index-fields/170780/16 "2019-04-12T15:26:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
