# No events/s for logstash events with basic license

**URL:** <https://discuss.elastic.co/t/no-events-s-for-logstash-events-with-basic-license/159054>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [December 2, 2018, 7:53pm UTC](https://discuss.elastic.co/t/no-events-s-for-logstash-events-with-basic-license/159054 "2018-12-02T19:53:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sarfaraz\_Ahmad](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@Sarfaraz\_Ahmad](https://discuss.elastic.co/u/Sarfaraz_Ahmad)\
**Post date:** [December 2, 2018, 7:53pm UTC](https://discuss.elastic.co/t/no-events-s-for-logstash-events-with-basic-license/159054/1 "2018-12-02T19:53:29Z")

</div>

Hi,

I just setup a very basic, minimal ELK cluster for learning purposes.  
I installed logstash/elasticsearch/kibana with basic xpack licenses where applicable.  
In Kibana's monitoring dashboard, I can see events per second for the default "main" pipeline, but,  
for individual input/filter/output plugins it still says 0 e/s.  
Does Kibana require logstash's monitoring API for this ?  
I can see logstash dumping health stats to elasticsearch undex .monitoring-logstash-6.

logstash\_stats.pipeline from a sample document in that index looks like this,

> {  
> "events": {  
> "out": 325,  
> "queue\_push\_duration\_in\_millis": 0,  
> "in": 325,  
> "duration\_in\_millis": 40958,  
> "filtered": 325  
> },  
> "queue": {  
> "events\_count": 0,  
> "max\_queue\_size\_in\_bytes": 0,  
> "type": "memory",  
> "queue\_size\_in\_bytes": 0  
> },  
> "reloads": {  
> "successes": 0,  
> "failures": 0  
> },  
> "id": "main",  
> "vertices": [  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_out": 325,  
> "queue\_push\_duration\_in\_millis": 0,  
> "id": "96b6b8f16363084f770033b4d0e5b98ca233dbce32314d166fef76935bda3600"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "long\_counters": [  
> {  
> "name": "matches",  
> "value": 325  
> },  
> {  
> "name": "failures",  
> "value": 0  
> }  
> ],  
> "duration\_in\_millis": 597,  
> "id": "squid-accesslog grok",  
> "events\_out": 325,  
> "events\_in": 325  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 325,  
> "events\_out": 325,  
> "duration\_in\_millis": 68,  
> "id": "squid-accesslog move tags to @metadata"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 0,  
> "events\_out": 0,  
> "duration\_in\_millis": 0,  
> "id": "squid-accesslog mutate on connect requests"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 0,  
> "events\_out": 0,  
> "duration\_in\_millis": 0,  
> "id": "2c3d83cfbca7d2e4a3eff90c7dbcd79cc30950bc7841a0a7f52c8d51404b31b0"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 0,  
> "events\_out": 0,  
> "duration\_in\_millis": 0,  
> "id": "squid source\_ip to localhost for cert retrievals"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 325,  
> "events\_out": 325,  
> "duration\_in\_millis": 98,  
> "id": "squid-accesslog rename host field to proxy"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 0,  
> "events\_out": 0,  
> "duration\_in\_millis": 0,  
> "id": "squid-accesslog mutate on error"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 0,  
> "events\_out": 0,  
> "duration\_in\_millis": 0,  
> "id": "squid-accesslog mutate category to safe"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "events\_in": 325,  
> "events\_out": 325,  
> "duration\_in\_millis": 19,  
> "id": "squid-accesslog remove unnecessary fields"  
> },  
> {  
> "pipeline\_ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "long\_counters": [  
> {  
> "name": "documents.successes",  
> "value": 325  
> },  
> {  
> "name": "bulk\_requests.successes",  
> "value": 305  
> },  
> {  
> "name": "bulk\_requests.responses.200",  
> "value": 305  
> }  
> ],  
> "duration\_in\_millis": 39320,  
> "id": "3776103e67c69576ce4006504000bb106754d95fa73bd90bfcd0b3560cb0c0ce",  
> "events\_out": 325,  
> "events\_in": 325  
> }  
> ],  
> "ephemeral\_id": "771a7f1f-7236-4ff8-94f7-7fb189aed44f",  
> "hash": "5abcc64a0a24428024e7a432f8cd46aae8f6519da0c0dcd779a387e6055647c1"  
> }

Any thoughts on what could be happening here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2018, 7:53pm UTC](https://discuss.elastic.co/t/no-events-s-for-logstash-events-with-basic-license/159054/2 "2018-12-30T19:53:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
