# No cluster events in index

**URL:** <https://discuss.elastic.co/t/no-cluster-events-in-index/49987>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [May 13, 2016, 9:55am UTC](https://discuss.elastic.co/t/no-cluster-events-in-index/49987 "2016-05-13T09:55:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lennylinux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lennylinux/32/9727_2.png) [@lennylinux](https://discuss.elastic.co/u/lennylinux)\
**Post date:** [May 13, 2016, 9:55am UTC](https://discuss.elastic.co/t/no-cluster-events-in-index/49987/1 "2016-05-13T09:55:05Z")

</div>

Hi!

I´ve tried the Watcher example to monitor the cluster join/left events.  
[https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-nodes](https://www.elastic.co/guide/en/watcher/current/watching-marvel-data.html#watching-nodes)

But in my test cluster there isn't an event field. Does I´ve to activate something for this?

---

<div class="post-metadata">

**Author:** ![pickypg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pickypg/32/62409_2.png) [@pickypg](https://discuss.elastic.co/u/pickypg)\
**Post date:** [May 13, 2016, 9:06pm UTC](https://discuss.elastic.co/t/no-cluster-events-in-index/49987/2 "2016-05-13T21:06:57Z")

</div>

Hi Lenny,

No, unfortunately the Watcher documentation for monitoring Marvel indices are out of date. Those examples were all written for a Marvel 1.x index, but you are presumably using Marvel 2.x.

We're in the process of fixing a large amount of the docs, as well as [automating the testing of our scripts in the docs](https://github.com/elastic/elasticsearch/pull/18075), but it will take time unfortunately.

In the case of that specific watch, it's not going to be possible as it's written because we do not track cluster events like that in Marvel 2.x/5.x. What you could do is to monitor the `.marvel-es-1-*` (2.3.x) index and `cluster_stats` type for its `cluster_stats.nodes.count.total` value.

You can choose to get fancy with it or keep it simple to just detect losing nodes (if that value is lower than you expect, then follow the rest of the path).

Long term, I suspect events will make a comeback, but doing something "simpler" is likely the best approach for now.

---

<div class="post-metadata">

**Author:** ![lennylinux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lennylinux/32/9727_2.png) [@lennylinux](https://discuss.elastic.co/u/lennylinux)\
**Post date:** [May 15, 2016, 3:08pm UTC](https://discuss.elastic.co/t/no-cluster-events-in-index/49987/3 "2016-05-15T15:08:45Z")

</div>

Hi Pickypg,

thanks for your reply. It would be great if you can pick a note on the documentation for this 🙂

Kind regards,

Lenny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/no-cluster-events-in-index/49987/4 "2017-07-06T13:43:32Z")

</div>


