# Multiple hosts monitoring

**URL:** https://discuss.elastic.co/t/multiple-hosts-monitoring/57225
**Category:** Beats
**Created:** [August 4, 2016, 2:16pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225 "2016-08-04T14:16:45Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 4, 2016, 2:16pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/1 "2016-08-04T14:16:45Z")

</div>

Hi i have 2 hosts with topbeat configured to send to another host (third)  
the problem is i can't disting 2 hosts on kibana dashboard, furthermore it takes all "-" in name as a new machine so i have 2 hosts to monitor, but i have 5 lines on dashboard =

name

test-int-name-01  
test-int-name-02

i see

test  
int  
name  
01  
02

it is a big issue how i can do ?

thanks !

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [August 4, 2016, 3:16pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/2 "2016-08-04T15:16:18Z")

</div>

This is caused by not loading the provided index template. Please see the documentation on [how to load the index template](https://www.elastic.co/guide/en/beats/topbeat/current/topbeat-template.html). You will have to delete the data you already indexed in order to correct the issue (there's a note about that in the docs).

---

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 4, 2016, 3:32pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/3 "2016-08-04T15:32:23Z")

</div>

thank you very much you're right i will try it with the windows command there is no CURL in windows

---

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 5, 2016, 7:31am UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/4 "2016-08-05T07:31:22Z")

</div>

I am sorry but i did the command via postman but it doesn't work, i use topbeat on only one computer, i delete the old data but i still see like it was several hosts monitored, see the pictures

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/413aba1aff1354dbdc8ed4744c4f92f435804bb9.png)

as you can see i monitor only one host , its name is "rs-tst-aof-01", indeed i can't use monitoring due to duplicate data

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/565048ad7f7fde3443a52b51d78ae8a13cb072c8.png)

---

<div class="post-metadata">

### Author: ![MarkGavalda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markgavalda/32/4764_2.png) [@MarkGavalda](https://discuss.elastic.co/u/MarkGavalda)
#### Post date: [August 6, 2016, 9:49pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/5 "2016-08-06T21:49:54Z")

</div>

The problem is Beats splits the hostnames into multiple ones at the dashes. I came to the forum to report the exact same thing :-/ I even set the:  
_shipper:_  
_name: "my-shipper"_  
configuration option, but it results in the same.

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [August 7, 2016, 2:57pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/6 "2016-08-07T14:57:06Z")

</div>

Please provide the output of the following Elasticsearch queries. You'll probably need to use something like [http://pastebin.com](http://pastebin.com) in order to share the results due to post size limits.

`http://<elasticsearch>:9200/_template/topbeat?pretty`

`http://<elasticsearch>:9200/topbeat-2016.08.07/_mapping?pretty` \<- substitute in today's date

---

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 9, 2016, 12:38pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/8 "2016-08-09T12:38:36Z")

</div>

> [@andrewkroh](#):
>
> topbeat-2016.08.07/\_mapping?pretty

this is the mapping in attchment, thanks

{  
"topbeat-2016.08.09": {  
"mappings": {  
"filesystem": {  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
},  
"beat": {  
"properties": {  
"hostname": {  
"type": "string"  
},  
"name": {  
"type": "string"  
}  
}  
},  
"count": {  
"type": "long"  
},  
"fs": {  
"properties": {  
"avail": {  
"type": "long"  
},  
"device\_name": {  
"type": "string"  
},  
"files": {  
"type": "long"  
},  
"free": {  
"type": "long"  
},  
"free\_files": {  
"type": "long"  
},  
"mount\_point": {  
"type": "string"  
},  
"total": {  
"type": "long"  
},  
"used": {  
"type": "long"  
},  
"used\_p": {  
"type": "double"  
}  
}  
},  
"type": {  
"type": "string"  
}  
}  
},  
"system": {  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
},  
"beat": {  
"properties": {  
"hostname": {  
"type": "string"  
},  
"name": {  
"type": "string"  
}  
}  
},  
"count": {  
"type": "long"  
},  
"cpu": {  
"properties": {  
"idle": {  
"type": "long"  
},  
"iowait": {  
"type": "long"  
},  
"irq": {  
"type": "long"  
},  
"nice": {  
"type": "long"  
},  
"softirq": {  
"type": "long"  
},  
"steal": {  
"type": "long"  
},  
"system": {  
"type": "long"  
},  
"system\_p": {  
"type": "double"  
},  
"user": {  
"type": "long"  
},  
"user\_p": {  
"type": "double"  
}  
}  
},  
"load": {  
"properties": {  
"load1": {  
"type": "long"  
},  
"load15": {  
"type": "long"  
},  
"load5": {  
"type": "long"  
}  
}  
},  
"mem": {  
"properties": {  
"actual\_free": {  
"type": "long"  
},  
"actual\_used": {  
"type": "long"  
},  
"actual\_used\_p": {  
"type": "double"  
},  
"free": {  
"type": "long"  
},  
"total": {  
"type": "long"  
},  
"used": {  
"type": "long"  
},  
"used\_p": {  
"type": "double"  
}  
}  
},

---

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 9, 2016, 12:38pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/9 "2016-08-09T12:38:53Z")

</div>

```
      "swap": {
        "properties": {
          "free": {
            "type": "long"
          },
          "total": {
            "type": "long"
          },
          "used": {
            "type": "long"
          },
          "used_p": {
            "type": "long"
          }
        }
      },
      "type": {
        "type": "string"
      }
    }
  },
  "process": {
    "properties": {
      "@timestamp": {
        "type": "date",
        "format": "strict_date_optional_time||epoch_millis"
      },
      "beat": {
        "properties": {
          "hostname": {
            "type": "string"
          },
          "name": {
            "type": "string"
          }
        }
      },
      "count": {
        "type": "long"
      },
      "proc": {
        "properties": {
          "cmdline": {
            "type": "string"
          },
          "cpu": {
            "properties": {
              "start_time": {
                "type": "string"
              },
              "system": {
                "type": "long"
              },
              "total": {
                "type": "long"
              },
              "user": {
                "type": "long"
              },
              "user_p": {
                "type": "double"
              }
            }
          },
          "mem": {
            "properties": {
              "rss": {
                "type": "long"
              },
              "rss_p": {
                "type": "long"
              },
              "share": {
                "type": "long"
              },
              "size": {
                "type": "long"
              }
            }
          },
          "name": {
            "type": "string"
          },
          "pid": {
            "type": "long"
          },
          "ppid": {
            "type": "long"
          },
          "state": {
            "type": "string"
          },
          "username": {
            "type": "string"
          }
        }
      },
      "type": {
        "type": "string"
      }
    }
  }
}

```

}  
}

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [August 10, 2016, 2:28pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/10 "2016-08-10T14:28:35Z")

</div>

@fdlprod, the mapping that you posted indicates that you do not have the provided index template installed.

1. Stop the Topbeat service.

`PS C:\Program Files\Topbeat> Stop-Service topbeat`

1. Install the template:

`PS C:\Program Files\Topbeat> Invoke-WebRequest -Method Put -InFile topbeat.template.json -Uri http://localhost:9200/_template/topbeat?pretty`

1. Delete the existing Topbeat data that has the wrong mappings.

`PS C:\Program Files\Topbeat> Invoke-WebRequest -Method Delete -Uri "http://localhost:9200/topbeat-*"`

1. Restart the Topbeat service:

`PS C:\Program Files\Topbeat> Start-Service topbeat`

---

<div class="post-metadata">

### Author: ![fdlprod](https://avatars.discourse-cdn.com/v4/letter/f/6f9a4e/32.png) [@fdlprod](https://discuss.elastic.co/u/fdlprod)
#### Post date: [August 11, 2016, 10:28am UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/11 "2016-08-11T10:28:11Z")

</div>

i am sorry bu t always same result i try also in filebeat.yml to set template and override : true same error strange because in discover it seems to be OK

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 25, 2016, 2:17pm UTC](https://discuss.elastic.co/t/multiple-hosts-monitoring/57225/12 "2016-08-25T14:17:09Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
