# Metricbeat output stops appearing in Kibana after a few minutes

**URL:** <https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [April 24, 2018, 1:01pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309 "2018-04-24T13:01:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [April 24, 2018, 1:01pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309/1 "2018-04-24T13:01:27Z")

</div>

I've had Metricbeat -\> Elasticsearch -\> Kibana working fine on a number of deployments for some time. I'm now building a complete new stack, and what I'm seeing is that Metricbeat output looks normal until Metricbeat has been running for a few minutes, after which no further Metricbeat output appears in Kibana.

The Metricbeat logs appear to continue normally, with no obvious change between before and after the data stops appearing in Kibana. There is nothing obviously relevant in the Elasticsearch logs. Other indices appear correct in both Elasticsearch and Kibana.

There is stuff in the Elasticsearch logs which I don't understand, being sequences like this

> [2018-04-24T13:44:02,392][INFO][o.e.c.s.ClusterService] [live-monitor-1] removed {{live-monitor-3}{W0B2alNyQOqXerA94r-1PA}{O3IHPNZ2SoO-X6LRMPYDjw}{172.31.13.99}{172.31.13.99:9300},}, reason: zen-disco-receive(from master [master {live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300} committed version [21444]])  
> [2018-04-24T13:44:05,973][INFO][o.e.c.s.ClusterService] [live-monitor-1] added {{live-monitor-3}{W0B2alNyQOqXerA94r-1PA}{O3IHPNZ2SoO-X6LRMPYDjw}{172.31.13.99}{172.31.13.99:9300},}, reason: zen-disco-receive(from master [master {live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300} committed version [21446]])  
> [2018-04-24T13:48:34,838][INFO][o.e.d.z.ZenDiscovery] [live-monitor-1] master\_left [{live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300}], reason [transport disconnected]  
> [2018-04-24T13:48:34,838][WARN][o.e.d.z.ZenDiscovery] [live-monitor-1] master left (reason = transport disconnected), current nodes: nodes:  
> {live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300}, master  
> {live-monitor-1}{xE9eAhNXQ0uBQAaPlqfuFQ}{6D5AWlLJQuWHcJHhj727Iw}{172.31.11.96}{172.31.11.96:9300}, local  
> {live-monitor-3}{W0B2alNyQOqXerA94r-1PA}{O3IHPNZ2SoO-X6LRMPYDjw}{172.31.13.99}{172.31.13.99:9300}
> 
> [2018-04-24T13:48:37,849][INFO][o.e.c.s.ClusterService] [live-monitor-1] detected\_master {live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300}, reason: zen-disco-receive(from master [master {live-monitor-2}{49PcsRhMSUitVmH6PHbTCA}{\_bdlSndNSrSL7g2AFcXbhg}{172.31.12.89}{172.31.12.89:9300} committed version [21474]])

but I've no idea whether these are relevant or whether they matter.

If I restart Metricbeat its output appears in Kibana again, for a few minutes, until it stops again. This applies to all the hosts on which I'm running Metricbeat in this system deployment.

How can I diagnose and fix what is going on?

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [April 24, 2018, 1:55pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309/2 "2018-04-24T13:55:17Z")

</div>

OK, so the documents **are** coming through ... very very slowly. I've creating an "ingested" timestamp on each document as well as the @timestamp, and there's around 25 minutes between them. Where are 25 minutes' worth of Metricbeat input getting queued up, and why? None of the machines involved show any significant CPU usage.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [April 24, 2018, 3:46pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309/3 "2018-04-24T15:46:11Z")

</div>

I suggest you run metricbeat with publish debug logs enabled: `-d publish`.

This will help see when are the events published and if there is any error delivering them to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [April 24, 2018, 4:00pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309/4 "2018-04-24T16:00:07Z")

</div>

Will do, if the problem recurs (I've finished that test and deleted the bunch of VMs, but will be building a new set and doing it again shortly).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2018, 4:00pm UTC](https://discuss.elastic.co/t/metricbeat-output-stops-appearing-in-kibana-after-a-few-minutes/129309/5 "2018-05-22T16:00:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
