# Metricbeat stops logstash monitoring

**URL:** <https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 13, 2020, 7:50am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146 "2020-02-13T07:50:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tennaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tennaen/32/87293_2.png) [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Post date:** [February 13, 2020, 7:50am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/1 "2020-02-13T07:50:30Z")

</div>

I have running metricbeat, to monitor my ELK. It works great for Kibana and Elasticsearch, but when it comes to Logstash, it stops showing status. Starts working only after metricbeat restart.  
Logstash version: 7.5.2  
Metricbeat version: 7.5.2  
Metricbeat logstash-xpack.yml

```
# Module: logstash
# Docs: https://www.elastic.co/guide/en/beats/metricbeat/7.5/metricbeat-module-logstash.html

- module: logstash
  metricsets:
    - node
    - node_stats
  period: 60s
  hosts: ["my_ip:9600"]
  username: "monitor"
  password: "${monitor.password}"
  xpack.enabled: true

```

logstash.yml

```
node.name: node_name
path.data: /u01/app/logstash/data
http.host: my_ip
http.port: 9600
log.level: info
path.logs: /u01/data/ls_logs
config.reload.automatic: true
xpack.monitoring.enabled: false

```

Metricbeat logs show this message:

`2020-02-13T08:39:36.801+0100 ERROR [logstash.node_stats] node_stats/node_stats.go:81 HTTP error 400 in : 400 Bad Request`

---

<div class="post-metadata">

**Author:** ![maxh1](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@maxh1](https://discuss.elastic.co/u/maxh1)\
**Post date:** [February 14, 2020, 2:18am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/2 "2020-02-14T02:18:17Z")

</div>

We have the exact same problem here, on the same version (7.5.2).

Everything works fine for a while (after restarting Metricbeat), but then the dataflow stops, and we see the same error as OP in the logs:

`2020-02-14T03:14:09.685+0100 ERROR [logstash.node_stats] node_stats/node_stats.go:81 HTTP error 400 in : 400 Bad Request`

No errors can be seen on the Logstash side, that would explain why the HTTP API server is throwing back a 400 Bad Request.

Any suggestions?

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [February 17, 2020, 4:28pm UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/3 "2020-02-17T16:28:03Z")

</div>

I have the same error , MB stops after node\_stats fails.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [February 18, 2020, 4:09pm UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/4 "2020-02-18T16:09:27Z")

</div>

I think you might be running into this bug: [https://github.com/elastic/beats/issues/15974](https://github.com/elastic/beats/issues/15974). It was fixed via [https://github.com/elastic/beats/pull/16044](https://github.com/elastic/beats/pull/16044) and the fix is released in version 7.6.0.

Hope that helps,

Shaunak

---

<div class="post-metadata">

**Author:** ![tennaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tennaen/32/87293_2.png) [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Post date:** [February 19, 2020, 10:25am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/5 "2020-02-19T10:25:03Z")

</div>

@shaunak metricbeat updated to 7.6. Now i can just wait.

---

<div class="post-metadata">

**Author:** ![tennaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tennaen/32/87293_2.png) [@tennaen](https://discuss.elastic.co/u/tennaen)\
**Post date:** [February 20, 2020, 8:47am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/6 "2020-02-20T08:47:49Z")

</div>

It's working now. Thanks!

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [February 23, 2020, 4:08am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/7 "2020-02-23T04:08:15Z")

</div>

Yes, its working now. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2020, 4:08am UTC](https://discuss.elastic.co/t/metricbeat-stops-logstash-monitoring/219146/8 "2020-03-22T04:08:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
