# Need guidance on search for a list of servers that had software x installed from Kibana/Logstash/filebeat

**URL:** https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680
**Category:** Elasticsearch
**Created:** [March 4, 2019, 7:04am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680 "2019-03-04T07:04:49Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 4, 2019, 7:04am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/1 "2019-03-04T07:04:50Z")

</div>

Hi,

I'm not sure whether this should goes to Logstash, Elastic search or other forums.

My objective:  
To search for a list of servers that had software x installed, can someone please give me an advice on what's the best way to achieve the objective?

Thanks!  
Weng Sheng Lee

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 11, 2019, 12:33am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/2 "2019-03-11T00:33:05Z")

</div>

Can someone please give me an idea? It's been a week.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 11, 2019, 2:15am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/3 "2019-03-11T02:15:12Z")

</div>

You can use metricbeat, elasticsearch and Kibana.

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 11, 2019, 5:21am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/4 "2019-03-11T05:21:14Z")

</div>

Thanks for the response David.

What string should I be searching? I've have 3 nodes with Zabbix installed. If I want to get a list of servers that has Zabbix installed, what is the syntax should I use in search? Also what parameters should i add in the config file in order for Metrixbeat, Logstash, filebeat etc to be able to find the nodes that has Zabbix installed?

Thanks!  
Lee Weng Sheng

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 11, 2019, 5:21am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/5 "2019-03-11T05:21:45Z")

</div>

This is on Elasticsearch forum, hopefully someone can get back to me with the guidance.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 11, 2019, 5:36am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/6 "2019-03-11T05:36:56Z")

</div>

Read [this](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and specifically the "Also be patient" part.

It's fine to answer on your own thread after 2 or 3 days (not including weekends) if you don't have an answer.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 11, 2019, 5:40am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/7 "2019-03-11T05:40:16Z")

</div>

Just install metricbeat on every single server, configure it to send the data to your elasticsearch node, configure Kibana endpoint as well.

Then open the metricbeat system dashboard and you should see all processes running on all nodes.

Search for the one you want (I don't know what is the Linux name for zabbix, probably `zabbix`) and you will probably see where they are running.

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 11, 2019, 6:44am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/8 "2019-03-11T06:44:36Z")

</div>

Thank you David, I will give it a try, should be able to respond by tomorrow, at the same time. Thanks

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 20, 2019, 9:01pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/9 "2019-03-20T21:01:52Z")

</div>

Hi,

I've just added the following on the .yml file  
#------------------------------- System Module -------------------------------

- module: system  
metricsets:

- module: apache  
metricsets: ["status"]  
enabled: true  
period: 1s  
hosts: ["[http://127.0.0.1](http://127.0.0.1)"]

When i restarted the Metricbeat agent, it gives me:

[root@mhlinux151 ~]# service metricbeat restart  
Exiting: error loading config file: yaml: line 24: did not find expected key

Do you know the solution for this?

Thanks!

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 20, 2019, 9:52pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/10 "2019-03-20T21:52:48Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 27, 2019, 11:56pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/11 "2019-03-27T23:56:59Z")

</div>

```
indent preformatted text by 4 spaces

```

sorry for the late reply

Here's the error:  
[root@mhlinux151 metricbeat]# service metricbeat restart  
Exiting: error loading config file: yaml: line 118: did not find expected key

Here's the code:  
###################### Metricbeat Configuration Example #######################

# This file is an example configuration file highlighting only the most common

# options. The metricbeat.reference.yml file from the same directory contains all the

# supported options with more comments. You can use it as a reference.

# 

# You can find the full configuration reference here:

# [https://www.elastic.co/guide/en/beats/metricbeat/index.html](https://www.elastic.co/guide/en/beats/metricbeat/index.html)

#========================== Modules configuration ============================

metricbeat.config.modules:

# Glob pattern for configuration loading

path: /etc/metricbeat/modules.d/\*.yml

# path: ${path.config}/modules.d/\*.yml

metricbeat.modules:

# Set to true to enable config reloading

reload.enabled: false

# Period on which files under path should be checked for changes

#reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:  
index.number\_of\_shards: 1  
index.codec: best\_compression  
#\_source.enabled: false

#================================ General =====================================

# The name of the shipper that publishes the network data. It can be used to group

# all the transactions sent by a single shipper in the web interface.

#name:

# The tags of the shipper are included in their own field with each

# transaction published.

#tags: ["service-X", "web-tier"]

# Optional fields that you can specify to add additional information to the

# output.

#fields:

# env: staging

#============================== Dashboards =====================================

# These settings control loading the sample dashboards to the Kibana index. Loading

# the dashboards is disabled by default and can be enabled either by setting the

# options here, or by using the `-setup` CLI flag or the `setup` command.

#setup.dashboards.enabled: false

# The URL from where to download the dashboards archive. By default this URL

# has a value which is computed based on the Beat name and version. For released

# versions, this URL points to the dashboard archive on the [artifacts.elastic.co](http://artifacts.elastic.co)

# website.

#setup.dashboards.url:

#============================== Kibana =====================================

# Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.

# This requires a Kibana endpoint configuration.

setup.kibana:

# Kibana Host

# Scheme and port can be left out and will be set to the default (http and 5601)

# In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)

# IPv6 addresses should always be defined as: https://[2001:db8::1]:5601

#host: "localhost:5601"

# Kibana Space ID

# ID of the Kibana Space into which the dashboards should be loaded. By default,

# the Default Space will be used.

#space.id:

#============================= Elastic Cloud ==================================

# These settings simplify using metricbeat with the Elastic Cloud ([https://cloud.elastic.co/](https://cloud.elastic.co/)).

# The cloud.id setting overwrites the `output.elasticsearch.hosts` and

# `setup.kibana.host` options.

# You can find the `cloud.id` in the Elastic Cloud web UI.

#cloud.id:

# The cloud.auth setting overwrites the `output.elasticsearch.username` and

# `output.elasticsearch.password` settings. The format is `<user>:<pass>`.

#cloud.auth:

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

hosts: ["localhost:9200"]

# Enabled ilm (beta) to use index lifecycle management instead daily indices.

#ilm.enabled: false

# Optional protocol and basic auth credentials.

#protocol: "https"  
#username: "elastic"  
#password: "changeme"

#----------------------------- Logstash output --------------------------------  
#output.logstash:

# The Logstash hosts

hosts: ["10.139.16.43:5004"]

# Optional SSL. By default is off.

# List of root certificates for HTTPS server verifications

#ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]  
#ssl.certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]

# Certificate for SSL client authentication

#ssl.certificate: "/etc/pki/client/cert.pem"

# Client Certificate Key

# ssl.key: "/etc/pki/client/cert.key"

#================================ Processors =====================================

# Configure processors to enhance or manipulate events generated by the beat.

processors:

- add\_host\_metadata: ~
- add\_cloud\_metadata: ~

#================================ Logging =====================================

# Sets log level. The default log level is info.

# Available log levels are: error, warning, info, debug

#logging.level: debug

# At debug level, you can selectively enable logging only for some components.

# To enable all selectors use ["\*"]. Examples of other selectors are "beat",

# "publish", "service".

#logging.selectors: ["\*"]

#============================== Xpack Monitoring ===============================

# metricbeat can export internal metrics to a central Elasticsearch monitoring

# cluster. This requires xpack monitoring to be enabled in Elasticsearch. The

# reporting is disabled by default.

# Set to true to enable the monitoring reporter.

#xpack.monitoring.enabled: false

# Uncomment to send the metrics to Elasticsearch. Most settings from the

# Elasticsearch output are accepted here as well. Any setting that is not set is

# automatically inherited from the Elasticsearch output configuration, so if you

# have the Elasticsearch output configured, you can simply uncomment the

# following line.

#xpack.monitoring.elasticsearch:

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [March 28, 2019, 4:49am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/12 "2019-03-28T04:49:22Z")

</div>

By the way, here's line 118:

113 #----------------------------- Logstash output --------------------------------  
118  
119 hosts: ["10.139.16.43:5004"]  
120  
121 # Optional SSL. By default is off.  
122 # List of root certificates for HTTPS server verifications  
123 #ssl.certificate\_authorities: ["/etc/pki/root/ca.pem"]  
124 #ssl.certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]  
125  
126 # Certificate for SSL client authentication  
127 #ssl.certificate: "/etc/pki/client/cert.pem"  
128  
129 # Client Certificate Key  
130 # ssl.key: "/etc/pki/client/cert.key"  
131

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 2, 2019, 12:02am UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/13 "2019-04-02T00:02:07Z")

</div>

now I've fixed the "did not find expected key" error, but got a new error below:

2019-04-01T19:01:55.626-0500 INFO instance/beat.go:281 Setup Beat: metricbeat; Version: 6.6.2  
2019-04-01T19:01:58.628-0500 INFO add\_cloud\_metadata/add\_cloud\_metadata.go:319 add\_cloud\_metadata: hosting provider type not detected.  
2019-04-01T19:01:58.629-0500 ERROR instance/beat.go:911 Exiting: error initializing publisher: missing required field accessing 'output.elasticsearch.hosts'  
Exiting: error initializing publisher: missing required field accessing 'output.elasticsearch.hosts'

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 2, 2019, 9:28pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/14 "2019-04-02T21:28:04Z")

</div>

I just resolved the error "Exiting: error initializing publisher: missing required field accessing 'output.elasticsearch.hosts'"

Restarted the services, and didn't give me an error. Service claims it's up:

["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read","38","39","40","41","42","43","44","45","46","47","48","49","50","51","52","53","54","55","56","57","58","59","60","61","62","63"],"ambient":null}, "cwd": "/", "exe": "/usr/share/metricbeat/bin/metricbeat", "name": "metricbeat", "pid": 6009, "ppid": 6008, "seccomp": {"mode":""}, "start\_time": "2019-04-02T16:12:28.440-0500"}}}  
2019-04-02T16:12:28.586-0500 INFO instance/beat.go:280 Setup Beat: metricbeat; Version: 6.7.0  
2019-04-02T16:12:28.589-0500 INFO elasticsearch/client.go:164 Elasticsearch url: [http://10.139.16](http://10.139.16).??:5044  
2019-04-02T16:12:28.592-0500 INFO [publisher] pipeline/module.go:110 Beat name: linux1  
Config OK  
[OK]

However, I still can't find the host in Metricbeat! Do you know the solution to troubleshoot this? Is my expectation correct? I expect to see mhlinux151 as the hostname in Kibana but can't find it, I can see other hostname only. i refreshed the browser atleast three times and still can't find the hostname.

![metricbeat](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a17e61276a92e7850471aff55b43e451962e2c0c.png)

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 2, 2019, 9:36pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/15 "2019-04-02T21:36:31Z")

</div>

I found this from Metricbeat log file:

2019-04-02T16:31:58.660-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":13240,"time":{"ms":308}},"total":{"ticks":33470,"time":{"ms":800},"value":33470},"user":{"ticks":20230,"time":{"ms":492}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":4},"info":{"ephemeral\_id":"da8b4377-3baf-420d-a16c-c4460e0e4e8c","uptime":{"ms":1170045}},"memstats":{"gc\_next":31056528,"memory\_alloc":22266128,"memory\_total":3445476984,"rss":196608}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":6,"events":{"active":2335,"published":67,"retry":34,"total":67}}},"metricbeat":{"system":{"cpu":{"events":3,"success":3},"filesystem":{"events":12,"success":12},"fsstat":{"events":1,"success":1},"load":{"events":3,"success":3},"memory":{"events":3,"success":3},"network":{"events":15,"success":15},"process":{"events":24,"success":24},"process\_summary":{"events":3,"success":3},"socket\_summary":{"events":3,"success":3}}},"system":{"load":{"1":0.34,"15":0.51,"5":0.34,"norm":{"1":0.0213,"15":0.0319,"5":0.0213}}}}}}  
2019-04-02T16:32:25.935-0500 ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://10.139.16.43:5044](http://10.139.16.43:5044))): Get [http://10.139.16](http://10.139.16).:5044: dial tcp 10.139.16.43:5044: connect: connection refused  
2019-04-02T16:32:25.935-0500 INFO pipeline/output.go:93 Attempting to reconnect to backoff(elasticsearch([http://10.139.16.43:5044](http://10.139.16.43:5044))) with 30 reconnect attempt(s)  
2019-04-02T16:32:25.935-0500 INFO [publish] pipeline/retry.go:189 retryer: send unwait-signal to consumer  
2019-04-02T16:32:25.935-0500 INFO [publish] pipeline/retry.go:191 done  
2019-04-02T16:32:25.935-0500 INFO [publish] pipeline/retry.go:166 retryer: send wait signal to consumer  
2019-04-02T16:32:25.935-0500 INFO [publish] pipeline/retry.go:168 done  
2019-04-02T16:32:28.660-0500 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":13550,"time":{"ms":318}},"total":{"ticks":34310,"time":{"ms":845},"value":34310},"user":{"ticks":20760,"time":{"ms":527}}},"handles":{"limit":{"hard":4096,"soft":1024},"open":4},"info":{"ephemeral\_id":"da8b4377-3baf-420d-a16c-c4460e0e4e8c","uptime":{"ms":1200044}},"memstats":{"gc\_next":31576496,"memory\_alloc":21224488,"memory\_total":3533775688,"rss":684032}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":6,"events":{"active":2389,"published":54,"retry":34,"total":54}}},"metricbeat":{"system":{"cpu":{"events":3,"success":3},"load":{"events":3,"success":3},"memory":{"events":3,"success":3},"network":{"events":15,"success":15},"process":{"events":24,"success":24},"process\_summary":{"events":3,"success":3},"socket\_summary":{"events":3,"success":3}}},"system":{"load":{"1":0.59,"15":0.53,"5":0.4,"norm":{"1":0.0369,"15":0.0331,"5":0.025}}}}}}

Please advise, whether i need to start a service, because Metricbeat service is started, and I can ping the IP address:

[root@linux metricbeat]# ping 10.139.16.??  
PING 10.139.16.??(10.139.16.??) 56(84) bytes of data.  
64 bytes from 10.139.16.??: icmp\_seq=1 ttl=51 time=169 ms  
64 bytes from 10.139.16.??: icmp\_seq=2 ttl=51 time=169 ms

[root@linu151x metricbeat]# service metricbeat status  
metricbeat-god (pid 6039) is running...

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 2, 2019, 9:59pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/16 "2019-04-02T21:59:42Z")

</div>

2019-04-02T16:57:37.071-0500 ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://10.139.16.43:5044](http://10.139.16.43:5044))): Get [http://10.139.16](http://10.139.16).??:5044: dial tcp 10.139.16.??:5044: connect: connection refused  
2019-04-02T16:57:37.071-0500 INFO pipeline/output.go:93 Attempting to reconnect to backoff(elasticsearch([http://10.139.16](http://10.139.16).??:5044)) with 22 reconnect attempt(s)

[root@linux metricbeat]# lsof -i | grep 5044  
[root@linux metricbeat]#

Can you tell me what application do i need to open in order to listen to port 5044? or any configuration i have to do in order to achieve that objective? Thanks!

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 2, 2019, 11:52pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/17 "2019-04-02T23:52:04Z")

</div>

I managed to solve the error by altering the config file, now that error gone but i'm still not seeing the beatname mhlinux151 on Kibana

019-04-02T18:50:30.362-0500 INFO instance/beat.go:273 Setup Beat: metricbeat; Version: 6.4.2  
2019-04-02T18:50:30.363-0500 INFO pipeline/module.go:98 Beat name: mhlinux151  
2019-04-02T18:50:30.363-0500 INFO instance/beat.go:367 metricbeat start running.  
2019-04-02T18:50:30.363-0500 INFO [monitoring] log/log.go:114 Starting metrics logging every 30s  
2019-04-02T18:50:30.367-0500 INFO cfgfile/reload.go:196 Loading of config files completed.  
2019-04-02T18:50:31.366-0500 INFO pipeline/output.go:95 Connecting to backoff(async(tcp://10.139.16.??:5004))  
2019-04-02T18:50:31.981-0500 INFO pipeline/output.go:105 Connection to backoff(async(tcp://10.139.16.??:5004)) established

Please advise!

---

<div class="post-metadata">

### Author: ![Lee\_Weng\_Sheng](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)
#### Post date: [April 8, 2019, 8:42pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/18 "2019-04-08T20:42:11Z")

</div>

I'm still not seeing the hostname on Kibana, the log didn't throw any error out.

2019-04-08T15:39:00.365-0500 INFO [monitoring] log/log.go:141 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":5018840,"time":{"ms":298}},"total":{"ticks":13531990,"time":{"ms":785},"value":13531990},"user":{"ticks":8513150,"time":{"ms":487}}},"info":{"ephemeral\_id":"a08b8df5-0511-444a-9947-8ca1de712c72","uptime":{"ms":506910040}},"memstats":{"gc\_next":6951984,"memory\_alloc":6018320,"memory\_total":1357883042576}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":64,"batches":3,"total":64},"read":{"bytes":105},"write":{"bytes":9020}},"pipeline":{"clients":6,"events":{"active":0,"published":64,"total":64},"queue":{"acked":64}}},"metricbeat":{"system":{"cpu":{"events":3,"success":3},"filesystem":{"events":12,"success":12},"fsstat":{"events":1,"success":1},"load":{"events":3,"success":3},"memory":{"events":3,"success":3},"network":{"events":15,"success":15},"process":{"events":24,"success":24},"process\_summary":{"events":3,"success":3}}},"system":{"load":{"1":0.01,"15":0.08,"5":0.05,"norm":{"1":0.0006,"15":0.005,"5":0.0031}}}}}}

I expect to see mhlinux151 but i can't see it. It has other server name, just not mhlinux151  
 ![beatname](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c2d03292797a95b1361e6fd427d301c703223f01.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 6, 2019, 8:42pm UTC](https://discuss.elastic.co/t/need-guidance-on-search-for-a-list-of-servers-that-had-software-x-installed-from-kibana-logstash-filebeat/170680/19 "2019-05-06T20:42:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
