# Non-zero metrics in the last 30s

**URL:** <https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 11, 2017, 8:21pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255 "2017-03-11T20:21:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 11, 2017, 8:21pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/1 "2017-03-11T20:21:59Z")

</div>

> Non-zero metrics in the last 30s: libbeat.es.call\_count.PublishEvents=4 libbeat.es.published\_and\_acked\_events=61 libbeat.publisher.messages\_in\_worker\_queues=4 libbeat.es.publish.write\_bytes=37185 libbeat.es.publish.read\_bytes=1582 libbeat.publisher.published\_events=61

I can not configure the packetbeat to send elasticsearch.

I can not configure the packet transmission to send elasticsearch.Kibina shows DNS queries, the search by reference

> [http://localhost:9200/packetbeat-\*/\_search?pretty](http://localhost:9200/packetbeat-*/_search?pretty)  
> does not show the requests (more accurately it shows static 3 DNS requests although the traffic passes)  
> Maybe I'm using the wrong link

# /etc/packetbeat/packetbeat.yml

> packetbeat.interfaces.device: 0  
> packetbeat.protocols.dns:  
> ports: [53]  
> include\_authorities: true  
> include\_additionals: true

> output.elasticsearch:  
> hosts: ["localhost:9200"]

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 13, 2017, 7:16am UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/2 "2017-03-13T07:16:36Z")

</div>

The log output clearly states events being successfully published to Elasticsearch.

Can you clearify what you're trying to do? Please share more complete configuration and logs. Use the `</>` button for format logs/configs.

---

<div class="post-metadata">

**Author:** ![korsdecaying](https://avatars.discourse-cdn.com/v4/letter/k/dbc845/32.png) [@korsdecaying](https://discuss.elastic.co/u/korsdecaying)\
**Post date:** [March 17, 2017, 5:13pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/3 "2017-03-17T17:13:30Z")

</div>

I apologize. Indeed the data comes in elasticsearch, but I do not understand where. Where it is possible to look and what configuration and logs it is necessary to throw off? I try to understand as there is a data transmission in elasticsearch a file and in what format where it is transformed in json records and where in general it is stored

---

<div class="post-metadata">

**Author:** ![jnmoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jnmoore/32/16440_2.png) [@jnmoore](https://discuss.elastic.co/u/jnmoore)\
**Post date:** [March 17, 2017, 5:53pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/4 "2017-03-17T17:53:59Z")

</div>

I was also confounded by this "non-zero metrics in the last 30s" message and thought packetbeat was not able to read network traffic, because I did not see indices being created in kibana. However, after a night's sleep, I realized that Kibana's Index Patterns list does not auto-discover new indices! I run ES on AWS, AWS reported packetbeat indices.

TL;DR Kibana's management GUI is not a good tool for checking if your beats are creating new indices

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 27, 2017, 5:15pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/5 "2017-03-27T17:15:35Z")

</div>

check out the elasticsearch docs for API to query data and indices. The API commands can also be run from kibana.

Accessing `http://elasticsearch-host:9200/_cat/indices?pretty` should get you a list of available indices. Check for `packetbeat-*` indices being available. In kibana you will have to configure an index pattern `packetbeat-*`, to access these data from kibana UI.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2017, 5:15pm UTC](https://discuss.elastic.co/t/non-zero-metrics-in-the-last-30s/78255/6 "2017-04-24T17:15:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
