# MetricBeat Setup

**URL:** <https://discuss.elastic.co/t/metricbeat-setup/351432>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 19, 2024, 10:42am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432 "2024-01-19T10:42:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [January 19, 2024, 10:42am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/1 "2024-01-19T10:42:17Z")

</div>

I am trying to configure my metricbeat on my elasticsearch but I am getting the following error message.

"/metricbeat-7.17.16-linux-x86\_64] Data path: [/root/metricbeat-7.17.16-linux-x86\_64/data] Logs path: [/root/metricbeat-7.17.16-linux-x86\_64/logs] Hostfs Path: [/]  
2024-01-19T16:23:54.587+0545 INFO instance/beat.go:706 Beat ID: f3d85e71-e92f-4302-a199-c9f0cf6aac66  
2024-01-19T16:23:57.590+0545 WARN [add\_cloud\_metadata] add\_cloud\_metadata/provider\_aws\_ec2.go:79 read token request for getting IMDSv2 token returns empty: Put "[http://169.254.169.254/latest/api/token](http://169.254.169.254/latest/api/token)": context deadline exceeded (Client.Timeout exceeded while awaiting headers). No token in the metadata request will be used.  
2024-01-19T16:23:57.591+0545 INFO [beat] instance/beat.go:1052 Beat info {"system\_info": {"beat": {"path": {"config": "/root/metricbeat-7.17.16-linux-x86\_64", "data": "/root/metricbeat-7.17.16-linux-x86\_64/data", "home": "/root/metricbeat-7.17.16-linux-x86\_64", "logs": "/root/metricbeat-7.17.16-linux-x86\_64/logs"}, "type": "metricbeat", "uuid": "f3d85e71-e92f-4302-a199-c9f0cf6aac66"}}}  
2024-01-19T16:23:57.591+0545 INFO [beat] instance/beat.go:1061 Build info {"system\_info": {"build": {"commit": "1490a760f9443652fbb7ce25ea8487be8acd03d9", "libbeat": "7.17.16", "time": "2023-12-07T19:05:58.000Z", "version": "7.17.16"}}}  
2024-01-19T16:23:57.591+0545 INFO [beat] instance/beat.go:1064 Go runtime info {"system\_info": {"go": {"os":"linux","arch":"amd64","max\_procs":4,"version":"go1.20.11"}}}  
2024-01-19T16:23:57.591+0545 INFO [beat] instance/beat.go:1070 Host info {"system\_info": {"host": {"architecture":"x86\_64","boot\_time":"2024-01-18T13:03:00+05:45","containerized":false,"name":"wazuh","ip":["127.0.0.1","::1","192.168.88.248","fe80::c851:f5ff:fe21:618c"],"kernel\_version":"5.4.0-169-generic","mac":["ca:51:f5:21:61:8c"],"os":{"type":"linux","family":"debian","platform":"ubuntu","name":"Ubuntu","version":"20.04.6 LTS (Focal Fossa)","major":20,"minor":4,"patch":6,"codename":"focal"},"timezone":"+0545","timezone\_offset\_sec":20700,"id":"c8ee876c7bc04cf59bbed51f95caf911"}}}  
2024-01-19T16:23:57.592+0545 INFO [beat] instance/beat.go:1099 Process info {"system\_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"effective":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"bounding":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"ambient":null}, "cwd": "/root/metricbeat-7.17.16-linux-x86\_64", "exe": "/root/metricbeat-7.17.16-linux-x86\_64/metricbeat", "name": "metricbeat", "pid": 87393, "ppid": 87184, "seccomp": {"mode":"disabled","no\_new\_privs":false}, "start\_time": "2024-01-19T16:23:53.570+0545"}}}  
2024-01-19T16:23:57.592+0545 INFO instance/beat.go:292 Setup Beat: metricbeat; Version: 7.17.16  
2024-01-19T16:23:57.592+0545 INFO [index-management] idxmgmt/std.go:184 Set output.elasticsearch.index to 'metricbeat-7.17.16' as ILM is enabled.  
2024-01-19T16:23:57.592+0545 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: [https://192.168.88.248:9200](https://192.168.88.248:9200)  
2024-01-19T16:23:57.593+0545 INFO [publisher] pipeline/module.go:113 Beat name: wazuh  
2024-01-19T16:23:57.611+0545 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: [https://192.168.88.248:9200](https://192.168.88.248:9200)  
2024-01-19T16:23:57.627+0545 ERROR [esclientleg] transport/logging.go:37 Error dialing x509: certificate signed by unknown authority {"network": "tcp", "address": "192.168.88.248:9200"}  
2024-01-19T16:23:57.628+0545 ERROR [esclientleg] eslegclient/connection.go:232 error connecting to Elasticsearch at [https://192.168.88.248:9200](https://192.168.88.248:9200): Get "[https://192.168.88.248:9200](https://192.168.88.248:9200)": x509: certificate signed by unknown authority  
2024-01-19T16:23:57.628+0545 ERROR instance/beat.go:1027 Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at [https://192.168.88.248:9200](https://192.168.88.248:9200): Get "[https://192.168.88.248:9200](https://192.168.88.248:9200)": x509: certificate signed by unknown authority]  
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at [https://192.168.88.248:9200](https://192.168.88.248:9200): Get "[https://192.168.88.248:9200](https://192.168.88.248:9200)": x509: certificate signed by unknown authority]"

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 19, 2024, 2:54pm UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/2 "2024-01-19T14:54:44Z")

</div>

Hi @Ted0011

1. how did you install elasticsearch and version?

2. Please share your filebeat.yml

Please format your code.

Your error is a common SSL error between metricbeat and Elasticsearch

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [January 22, 2024, 5:18am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/3 "2024-01-22T05:18:58Z")

</div>

I installed elasticsearch using wazuh documentation for all-in-one deployment...

I have encountered another error....

'''  
Loading dashboards (Kibana must be running and reachable)  
2024-01-22T10:59:54.300+0545 INFO kibana/client.go:180 Kibana url: [http://localhost:5601](http://localhost:5601)  
2024-01-22T10:59:54.302+0545 ERROR instance/beat.go:1027 Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [http://localhost:5601/api/status](http://localhost:5601/api/status) fails: fail to execute the HTTP GET request: Get "[http://localhost:5601/api/status](http://localhost:5601/api/status)": EOF. Response: .  
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [http://localhost:5601/api/status](http://localhost:5601/api/status) fails: fail to execute the HTTP GET request: Get "[http://localhost:5601/api/status](http://localhost:5601/api/status)": EOF. Response: .  
'''

I checked the kibana.yml but I have not specified localhost anywhere how can I solve this issue

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [January 22, 2024, 5:20am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/4 "2024-01-22T05:20:29Z")

</div>

Here is filebeat.yml file...

\</\># Wazuh - Filebeat configuration file

```auto
output.elasticsearch.hosts: ["192.168.88.248:9200"]
output.elasticsearch.password: Pr@kr1t1@098

filebeat.modules:
  - module: wazuh
    alerts:
      enabled: true
    archives:
      enabled: false

setup.template.json.enabled: true
setup.template.json.path: /etc/filebeat/wazuh-template.json
setup.template.json.name: wazuh
setup.template.overwrite: true
setup.ilm.enabled: false

output.elasticsearch.protocol: https
output.elasticsearch.ssl.certificate: /etc/elasticsearch/certs/elasticsearch.crt
output.elasticsearch.ssl.key: /etc/elasticsearch/certs/elasticsearch.key
output.elasticsearch.ssl.certificate_authorities: /etc/elasticsearch/certs/ca/ca.crt
output.elasticsearch.ssl.verification_mode: strict
output.elasticsearch.username: elastic

logging.metrics.enabled: false

seccomp:
  default_action: allow
  syscalls:
  - action: allow
    names:
    - rseq

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 22, 2024, 5:56am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/5 "2024-01-22T05:56:12Z")

</div>

It looks like you don't have params for Kibana. Check a similar [issue](https://discuss.elastic.co/t/cant-install-winlogbeat/351492/2).

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [January 22, 2024, 6:28am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/6 "2024-01-22T06:28:34Z")

</div>

Thanks for your help Rios I just figured it out and I have updated my metricbeat.yml file to accept the kibana setup and rerunning the metric beat fingers cross....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2024, 8:28am UTC](https://discuss.elastic.co/t/metricbeat-setup/351432/7 "2024-02-19T08:28:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
