# Monitoring pipeline fails x-pack for logstash

**URL:** <https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098>\
**Category:** Logstash\
**Created:** [February 22, 2018, 5:23pm UTC](https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098 "2018-02-22T17:23:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ecamero2](https://avatars.discourse-cdn.com/v4/letter/e/258eb7/32.png) [@ecamero2](https://discuss.elastic.co/u/ecamero2)\
**Post date:** [February 22, 2018, 5:23pm UTC](https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098/1 "2018-02-22T17:23:04Z")

</div>

logstash monitoring never shows up. I see the below over and over again in the log file:

[2018-02-22T12:15:59,993][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>".monitoring-logstash", "pipeline.workers"=\>1, "pipeline.batch.size"=\>2, "pipeline.batch.delay"=\>50}  
[2018-02-22T12:16:00,302][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/)]}}  
[2018-02-22T12:16:00,305][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/), :path=\>"/"}  
[2018-02-22T12:16:00,470][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/)"}  
[2018-02-22T12:16:00,515][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>nil}  
[2018-02-22T12:16:00,515][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-02-22T12:16:00,516][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://caprlog101:9200](http://caprlog101:9200)"]}  
[2018-02-22T12:16:00,565][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/)]}}  
[2018-02-22T12:16:00,566][INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/), :path=\>"/"}  
[2018-02-22T12:16:00,574][WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=\>"[http://logstash\_system:xxxxxx@caprlog101:9200/](http://logstash_system:xxxxxx@caprlog101:9200/)"}  
[2018-02-22T12:16:00,580][INFO][logstash.licensechecker.licensereader] ES Output version determined {:es\_version=\>nil}  
[2018-02-22T12:16:00,580][WARN][logstash.licensechecker.licensereader] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-02-22T12:16:00,616][INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x30a9500b@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 sleep\>"}  
[2018-02-22T12:16:00,636][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>[".monitoring-logstash"]}  
[2018-02-22T12:16:00,637][INFO][logstash.inputs.metrics] Monitoring License OK  
[2018-02-22T12:16:02,520][INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x30a9500b@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 run\>"}

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 22, 2018, 8:43pm UTC](https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098/2 "2018-02-22T20:43:18Z")

</div>

Is this a new install that you're just getting set up?

One thing to keep in mind is that there can be different users for writing logstash data to Elasticsearch and for writing monitoring data to Elasticsearch.

In my logstash.yml file I have my `xpack.monitoring.elasticsearch.username: logstash_system` and password.  
And in my logstash.conf file in my output, elasticsearch section I have a different user and password.

As a troubleshooting step, you could use a superuser in both of those places. If that works, change one user, and if that works, change the other user.

My `logstash_writer` role (used in my logstash.conf for writing to logstash-\*) looks like this;

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/430f63b0d9789f6685f0dce11cd5c9360915bc82.png)

---

<div class="post-metadata">

**Author:** ![ecamero2](https://avatars.discourse-cdn.com/v4/letter/e/258eb7/32.png) [@ecamero2](https://discuss.elastic.co/u/ecamero2)\
**Post date:** [February 22, 2018, 9:02pm UTC](https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098/3 "2018-02-22T21:02:13Z")

</div>

Thank you for your response! I ended up figuring it out, I only had the monitoring pipeline running because it was a new install. It appears it will not start if another pipeline is not running as well

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 9:02pm UTC](https://discuss.elastic.co/t/monitoring-pipeline-fails-x-pack-for-logstash/121098/4 "2018-03-22T21:02:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
