# Modules reported as "no data" despite data being available

**URL:** <https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 16, 2018, 11:47am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046 "2018-11-16T11:47:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [November 16, 2018, 11:47am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/1 "2018-11-16T11:47:24Z")

</div>

Went into "kibana" / "add data" and checked for data from a few metrics. Some appear to be working (EG system, k8) while others (EG kafka, elastic) (despite having data in dashboards, etc) show here as "no data received".

EG: elasticsearch. I go to my elastic host and check:

```
[root@myhost ~]# metricbeat modules list
Enabled:

elasticsearch
kibana
logstash
system

```

Did I miss a step somewhere?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 16, 2018, 4:37pm UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/2 "2018-11-16T16:37:15Z")

</div>

Hi @ethrbunny,

Do you mean that you see data about elasticsearch, but the check for data couldn't find it? This checks just looks for data with `metricset.name: elasticsearch` in the `metricbeat-*` indexes.  
Could you do this search in the discovery view to see if you can find events?  
Or maybe, are you using custom index names?

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [November 16, 2018, 7:02pm UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/3 "2018-11-16T19:02:23Z")

</div>

Ah ok. It's an index naming thing.

Seems like that should be flagged as needing some work. We had to break everything out into separate indexes otherwise we hit the limit v quickly.

In any event - ty

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 19, 2018, 10:52am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/4 "2018-11-19T10:52:26Z")

</div>

> We had to break everything out into separate indexes otherwise we hit the limit v quickly.

What limit do you mean? What index name patterns are you using at the moment?

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [November 24, 2018, 11:33am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/5 "2018-11-24T11:33:03Z")

</div>

The max # of items per index.

We split out most everything into it's own index. EG kafka, kibana, cassandra, etc.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 24, 2018, 1:27pm UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/6 "2018-11-24T13:27:56Z")

</div>

@ethrbunny with what frequency do you hit this limit?

This is a limit per shard of about 2 billion documents, and with current defaults you should be able to store this quantity per day, as the default index template creates one index every day with one shard. These are the settings involved:

```auto
setup.template.settings:
  index.number_of_shards: 1

output.elasticsearch.index: "metricbeat-%{[beat.version]}-%{+yyyy.MM.dd}"

```

If you are modifying the index name check that you are still creating new indexes periodically. Other thing you can try depending in the volume of your data is to increase the number of shards.

---

<div class="post-metadata">

**Author:** ![ethrbunny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethrbunny/32/34603_2.png) [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Post date:** [November 25, 2018, 10:24pm UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/7 "2018-11-25T22:24:17Z")

</div>

It isn't a document limit - it's an "indexed field" (IIRC). 1k? Something like that.

Anyway - it was easier to just break up the various inputs to their own indices.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 26, 2018, 10:40am UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/8 "2018-11-26T10:40:38Z")

</div>

Oh, yes, there is also a [limit](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/mapping.html#mapping-limit-settings) in the number of fields in the index mapping, this is 1000 by default in elasticsearch, but it is set to 10000 by default on beats indexes. This is a limit on the different fields that there can be in all the documents of an index. In principle you shouldn't be hitting this limit with metricbeat.

In any case, of course, feel free to have any indexes configuration you like 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 12:40pm UTC](https://discuss.elastic.co/t/modules-reported-as-no-data-despite-data-being-available/157046/9 "2018-12-24T12:40:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
