# One Kibana for multiple server

**URL:** <https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044>\
**Category:** Kibana\
**Created:** [February 15, 2018, 5:41pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044 "2018-02-15T17:41:13Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [February 15, 2018, 5:41pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/1 "2018-02-15T17:41:14Z")

</div>

Hi,

I installed ELK on server1 and Elasticsearch/Logstash on server2.  
Now I want to visualise the data from server2 in Kibana on server1.

I edited elasticsearch.yml (server1):  
cluster.name: "elkcluster"  
node.master: false  
node.data: false

elasticsearch.yml (server2):  
cluster.name: "elkcluster"

But I don't get logs from server2.

Can you help me ?

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [February 15, 2018, 5:53pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/2 "2018-02-15T17:53:06Z")

</div>

I would suggest confirming that your ingest pipeline is working correctly by searching directly against the index on server2. If you can see the data, then try searching against server 1 ES.

---

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [March 7, 2018, 9:21pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/3 "2018-03-07T21:21:34Z")

</div>

First I got an error:  
not enough master nodes discovered during pinging (found [[]], but needed [-1]), pinging again

Second:  
I can't find other nodes in kibana or can't create an index pattern with the cluster or node name.

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 8, 2018, 1:24pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/4 "2018-03-08T13:24:17Z")

</div>

Can you share your elasticsearch.yml file (being sure to redact anything sensitive in it such as passwords)? It sounds like you have a cluster without a master node.

---

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [March 8, 2018, 1:39pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/5 "2018-03-08T13:39:44Z")

</div>

master elasticsearch.yml:

cluster.name: "elkcluster"  
node.name: "master"  
node.master: false  
node.data: false  
path:  
logs: /data/elk/log  
data: /data/elk/data  
http.host: 0.0.0.0  
http.cors.enabled: true  
http.cors.allow-origin: "\*"

node2 elasticsearch.yml:

cluster.name: "elkcluster"  
node.name: "node2"  
path:  
logs: /data/elk/log  
data: /data/elk/data  
http.host: 0.0.0.0  
http.cors.enabled: true  
http.cors.allow-origin: "\*"

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 8, 2018, 1:58pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/6 "2018-03-08T13:58:27Z")

</div>

I think the issue is missing discovery settings, so the two nodes do not wind up seeing each other. Look at these docs for details: [https://www.elastic.co/guide/en/elasticsearch/reference/current/discovery-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/discovery-settings.html)

---

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [March 8, 2018, 4:52pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/7 "2018-03-08T16:52:30Z")

</div>

Like this?

master elasticsearch.yml:

cluster.name: "elkcluster"  
node.name: "master"  
node.master: false  
node.data: false  
discovery.zen.ping.unicast.hosts:  
- node2.FQDN  
path:  
logs: /data/elk/log  
data: /data/elk/data  
http.host: 0.0.0.0  
http.cors.enabled: true  
http.cors.allow-origin: "\*"

node2 elasticsearch.yml:

cluster.name: "elkcluster"  
node.name: "node2"  
discovery.zen.ping.unicast.hosts:  
- master.FQDN  
path:  
logs: /data/elk/log  
data: /data/elk/data  
http.host: 0.0.0.0  
http.cors.enabled: true  
http.cors.allow-origin: "\*"

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 8, 2018, 5:14pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/8 "2018-03-08T17:14:03Z")

</div>

Yeah, that looks right to me. I might also verify that master and node2 can see each other on the network (try pinging the one from the other).

---

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [March 8, 2018, 5:46pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/9 "2018-03-08T17:46:39Z")

</div>

I can ping each other but it doesn't work.

master log:

publish\_address {127.0.0.1:9300}, bound\_addresses {[::1]:9300}, {127.0.0.1:9300}  
not enough master nodes discovered during pinging (found [[]], but needed [-1]), pinging again  
[...]

node2 log:

[2018-03-08T17:38:22,652][INFO][o.e.t.TransportService] [node2] publish\_address {127.0.0.1:9300}, bound\_addresses {[::1]:9300}, {127.0.0.1:9300}  
[2018-03-08T17:38:25,934][INFO][o.e.c.s.ClusterService] [node2] new\_master {node2}{CbKICAGjRmihWSYoSdQTgg}{NJVRju7ARN2n1VZCdPoH0w}{127.0.0.1}{127.0.0.1:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)  
[2018-03-08T17:38:26,120][INFO][o.e.h.n.Netty4HttpServerTransport] [node2] publish\_address {172.19.0.2:9200}, bound\_addresses {[::]:9200}  
[2018-03-08T17:38:26,121][INFO][o.e.n.Node] [node2] started  
[2018-03-08T17:38:27,678][INFO][o.e.g.GatewayService] [node2] recovered [3] indices into cluster\_state  
[2018-03-08T17:38:29,929][INFO][o.e.c.r.a.AllocationService] [node2] Cluster health status changed from [RED] to [GREEN] (reason: [shards started [[logstash-2018.03.08][0]] ...]).

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 8, 2018, 5:59pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/10 "2018-03-08T17:59:37Z")

</div>

I think I see what the issue is. If you do not specify a network.host, ES binds to localhost (127.0.0.1), which means that nothing outside the machine can connect to it. See this for explanation of how to configure that property: [https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html)

---

<div class="post-metadata">

**Author:** ![JaniJPK](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@JaniJPK](https://discuss.elastic.co/u/JaniJPK)\
**Post date:** [March 13, 2018, 7:49pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/11 "2018-03-13T19:49:56Z")

</div>

I installed a new master and I have other problems:

master elasticsearch.yml  
cluster.name: "elkcluster"  
node.name: "master"  
#need to uncomment because it cause error in kibana dashboard  
#node.master: false  
#node.data: false  
network.host: localhost  
http.port: 9200  
discovery.zen.ping.unicast.hosts:

- node2.FQDN

node2 elasticsearch.yml  
cluster.name: "elkcluster"  
node.name: "node2"  
#network.host: master.FQDN  
transport.tcp.port: 9200  
discovery.zen.ping.unicast.hosts:  
- master.FQDN

node2 logs:  
timed out after [5s] resolving host [master.FQDN]  
[2018-03-13T19:42:28,248][INFO][o.e.c.s.ClusterService] [node2] new\_master {node2}

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [March 13, 2018, 8:05pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/12 "2018-03-13T20:05:15Z")

</div>

your master configuration specifies network.host as localhost. This means no other machine can connect to that ES instance, as it binds to the loopback (127.0.0.1). Also, the timeout for resolving the hostname suggests that you are using a DNS name that does not exist in DNS. Are you literally using "master.FQDN" in node2's config ? That will not resolve. It should be something like "[master.yourdomain.com](http://master.yourdomain.com)".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 8:05pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-server/120044/13 "2018-04-10T20:05:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
