# Metricbeat not loading in ES indices

**URL:** <https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 19, 2017, 7:53am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274 "2017-11-19T07:53:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 19, 2017, 7:53am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/1 "2017-11-19T07:53:53Z")

</div>

I end up here after several hours of pain.

I setup a Elasticsearch / Kibana (no Logstash) installation to monitor RAM/CPU/and so on on a ubuntu VM.

I installed metricbeat but I do not manage to have the MB indice loaded in elastic.

I setup the elastic user, thinking about a permission issue, but it did not changed a thing.

Here is the curl localhost:9200/\_cat/indices?v result:  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open .kibana MWFHgWW1QKqks2zGbaHEjg 1 1 1 0 3.1kb 3.1kb  
green open cowrie Jp1UO0StTkWO25YMKrXwPA 1 0 0 0 160b 160b  
yellow open test NIKJEtHIRUOEQPzSScKrjw 5 1 0 0 800b 800b

Here is the metricbeat.yml:  
###################### Metricbeat Configuration Example #######################

```
# This file is an example configuration file highlighting only the most common
# options. The metricbeat.full.yml file from the same directory contains all the
# supported options with more comments. You can use it as a reference.
#
# You can find the full configuration reference here:
# https://www.elastic.co/guide/en/beats/metricbeat/index.html

#========================== Modules configuration ============================
metricbeat.modules:

#------------------------------- System Module -------------------------------
- module: system
  metricsets:
# CPU stats
- cpu

# System Load stats
- load

# Per CPU core stats
- core

# IO stats
- diskio

# Per filesystem stats
- filesystem

# File system summary stats
- fsstat

# Memory stats
- memory

# Network stats
- network

# Per process stats
- process

# Sockets (linux only)
- socket
  enabled: true
  period: 10s
  processes: ['.*']

- module: apache
 metricsets: ["status"]
 enabled: true
 period: 1s
 hosts: ["http://127.0.0.1"]

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group
# all the transactions sent by a single shipper in the web interface.
#name:

# The tags of the shipper are included in their own field with each
# transaction published.
#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the
# output.
#fields:
# env: staging

#================================ Outputs =====================================

# Configure what outputs to use when sending the data collected by the beat.
# Multiple outputs may be used.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["127.0.0.1:9200"]
  enabled: true

setup.kibana:
  host: "localhost:5601"

  # Optional protocol and basic auth credentials.
  #protocol: "https"
  username: "elasticsearch"
  password: "test"

#----------------------------- Logstash output --------------------------------
#output.logstash:
  # The Logstash hosts
  #hosts: ["localhost:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: critical, error, warning, info, debug
#logging.level: debug

# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publish", "service".
#logging.selectors: ["*"]

setup.dashboards.enabled: true
```

---

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 19, 2017, 7:54am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/2 "2017-11-19T07:54:54Z")

</div>

The elasticsearch.yml:  
# ======================== Elasticsearch Configuration =========================  
#  
# NOTE: Elasticsearch comes with reasonable defaults for most settings.  
# Before you set out to tweak and tune the configuration, make sure you  
# understand what are you trying to accomplish and the consequences.  
#  
# The primary way of configuring a node is via this file. This template lists  
# the most important settings you may want to configure for a production cluster.  
#  
# Please consult the documentation for further information on configuration options:  
# [https://www.elastic.co/guide/en/elasticsearch/reference/index.html](https://www.elastic.co/guide/en/elasticsearch/reference/index.html)  
#  
# ---------------------------------- Cluster -----------------------------------  
#  
# Use a descriptive name for your cluster:  
#  
[cluster.name](http://cluster.name): honeymap  
#  
# ------------------------------------ Node ------------------------------------  
#  
# Use a descriptive name for the node:  
#  
[node.name](http://node.name): honeynode  
#note.master: false  
#  
# Add custom attributes to the node:  
#  
#node.attr.rack: r1  
#  
# ----------------------------------- Paths ------------------------------------  
#  
# Path to directory where to store the data (separate multiple locations by comma):  
#  
#path.data: /path/to/data  
#  
# Path to log files:  
#  
#path.logs: /path/to/logs  
#  
# ----------------------------------- Memory -----------------------------------  
#  
# Lock the memory on startup:  
#  
#bootstrap.memory\_lock: true  
#  
# Make sure that the heap size is set to about half the memory available  
# on the system and that the owner of the process is allowed to use this  
# limit.  
#  
# Elasticsearch performs poorly when the system is swapping the memory.  
#  
# ---------------------------------- Network -----------------------------------  
#  
# Set the bind address to a specific IP (IPv4 or IPv6):  
#  
network.host: 127.0.0.1  
#  
# Set a custom port for HTTP:  
#  
http.port: 9200  
#  
# For more information, consult the network module documentation.  
#  
# --------------------------------- Discovery ----------------------------------  
#  
# Pass an initial list of hosts to perform discovery when new node is started:  
# The default list of hosts is ["127.0.0.1", "[::1]"]  
#  
#discovery.zen.ping.unicast.hosts: ["host1", "host2"]  
#  
# Prevent the "split brain" by configuring the majority of nodes (total number of master-eligible nodes / 2 + 1):  
#  
#discovery.zen.minimum\_master\_nodes: 3  
#  
# For more information, consult the zen discovery module documentation.  
#  
# ---------------------------------- Gateway -----------------------------------  
#  
# Block initial recovery after a full cluster restart until N nodes are started:  
#  
#gateway.recover\_after\_nodes: 3  
#  
# For more information, consult the gateway module documentation.  
#  
# ---------------------------------- Various -----------------------------------  
#  
# Require explicit names when deleting indices:  
#  
#action.destructive\_requires\_name: true

If anybody has an idea...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 19, 2017, 11:00pm UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/3 "2017-11-19T23:00:09Z")

</div>

What do the metricbeat logs show?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2017, 5:16am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/4 "2017-11-20T05:16:50Z")

</div>

Yaml is indentation sensitive and it looks to me like your Metricbeat modules section may not be correct.

---

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 20, 2017, 6:28am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/5 "2017-11-20T06:28:08Z")

</div>

There is no logs... ☹  
I did not find any in /etc/metricbeat, /usr/share/metricbeat or /var/log

---

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 20, 2017, 6:29am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/6 "2017-11-20T06:29:31Z")

</div>

I hope it is so simple.  
I will try with a new file.  
By the way, any issue with the host being localhost or 127.0.0.1?

---

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 20, 2017, 6:47am UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/7 "2017-11-20T06:47:21Z")

</div>

I removed metricbeat, rebooted and installed metricbeat again.  
When I list the indices in elasticsearch, nothing.  
I tried to stop/restart each service, but nothing.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 20, 2017, 3:51pm UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/8 "2017-11-20T15:51:17Z")

</div>

Have you [tested your config file](https://www.elastic.co/guide/en/beats/metricbeat/6.0/yaml-tips.html#_test_your_config_file)? If so, what is the result?

---

<div class="post-metadata">

**Author:** ![Alaric](https://avatars.discourse-cdn.com/v4/letter/a/f475e1/32.png) [@Alaric](https://discuss.elastic.co/u/Alaric)\
**Post date:** [November 20, 2017, 7:05pm UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/9 "2017-11-20T19:05:25Z")

</div>

Perfect!  
The error was in the metricbeat.yml file.  
I must have had an extra space.  
I removed the apache part and it works for the system module.  
Now, I will try the apache module!  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2017, 7:06pm UTC](https://discuss.elastic.co/t/metricbeat-not-loading-in-es-indices/108274/10 "2017-12-18T19:06:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
