# Sending ganglia metric to logstash and the displaying them on kibana

**URL:** <https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567>\
**Category:** Logstash\
**Created:** [January 30, 2016, 9:06pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567 "2016-01-30T21:06:01Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [January 30, 2016, 9:06pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/1 "2016-01-30T21:06:01Z")

</div>

Hi All,

I was able to send some metrics of ganglia to logstash. Here is my input configuration  
input {  
lumberjack {  
port =\> 5043  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
udp {  
port =\> 8649  
codec =\> json\_lines  
}  
}  
This configuration is working and I able to visaulized my ganglia metric the awesome kibana dashbroad. But, logstash is unable to understand the message of the metric. That is the message look like  
"message" =\> "\u0000\u0000\u0000\x86\u0000\u0000\u0000\u0010ip-172-31-37-235\u0000\u0000\u0000\fload\_fifteen\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0004%.2f=L\xCC\xCD\u0000\u0000\u0000\x84\u0000\u0000\u0000\u0010ip-172-31-37-235\u0000\u0000\u0000\theartbeat\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002%u\u0000\u0000V\xAC\xDFF\u0000\u0000\u0000\x84\u0000\u0000\u0000\u0010ip-172-31-37-235\u0000\u0000\u0000\theartbeat\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002%u\u0000\u0000V\xAC\xDFF\u0000\u0000\u0000\x86\u0000\u0000\u0000\u0010ip-172-31-37-235\u0000\u0000\u0000\bmem\_free\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0004%.0fH\xEBK\u0000\u0000\u0000\u0000\x86\u0000\u0000\u0000\u0010ip-172-31-37-235\u0000\u0000\u0000"  
I have attach a screenshot.  
Now my question is how can I configure logstash to understand the messages sent by ganglia.  
Thanks for the concern.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/9bd9fa742949e86606fed9707522f536f07abf93.PNG)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 30, 2016, 9:36pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/2 "2016-01-30T21:36:04Z")

</div>

Have you tried using the [Ganglia input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-ganglia.html)?

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [January 31, 2016, 5:31pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/3 "2016-01-31T17:31:07Z")

</div>

Hi @Christian-Dahlqvist

Thanks for the quick respond. Yes I have tried Ganglia input plugin. When I used ganglia input as follows, I have nothing been displayed by kibana.  
input {  
lumberjack {  
port =\> 5043  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
ganglia {  
port =\> 8649  
codec =\> json\_lines  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 31, 2016, 6:06pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/4 "2016-01-31T18:06:40Z")

</div>

When debugging input plugins and filters, it is generally recommended to send data to the stdout plugin with a ruby debug codec, as this allows you to quickly look at the events coming in and being processed. I would start trying to receive messages on UDP using the ganglia plugin and the default settings (no son\_lines codec) and see what events look like. If you are not receiving anything, enable verbose mode to see if any errors are reported.

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [January 31, 2016, 8:48pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/5 "2016-01-31T20:48:18Z")

</div>

I have just used the ganglia plugin with the default settings. I had no events been displayed and when I enable verbose, I have this error.  
{:timestamp=\>"2016-01-31T20:44:47.899000+0000", :message=\>"An error occurred. Closing connection", :client=\>"41.205.24.27:34479", :exception=\>#\<NoMeth  
odError: undefined method `[]' for nil:NilClass>, :backtrace=>["/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.0.0-java/lib/logstash/event .rb:73:in`initialize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-json\_lines-2.0.2/lib/logstash/codecs/json\_lines.rb:52:in `guard'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-codec-json_lines-2.0.2/lib/logstash/codecs/json_lines.rb:38:in`decode'", "/opt/logstash/vendor/  
bundle/jruby/1.9/gems/logstash-codec-line-2.0.2/lib/logstash/codecs/line.rb:36:in `decode'", "org/jruby/RubyArray.java:1613:in`each'", "/opt/logstash  
/vendor/bundle/jruby/1.9/gems/logstash-codec-line-2.0.2/lib/logstash/codecs/line.rb:35:in `decode'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logst ash-codec-json_lines-2.0.2/lib/logstash/codecs/json_lines.rb:37:in`decode'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-tcp-2.0.4/lib  
/logstash/inputs/tcp.rb:149:in `handle_socket'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-tcp-2.0.4/lib/logstash/inputs/tcp.rb:140:i n`server\_connection\_thread'"], :level=\>:error}

Thanks for the concern.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 31, 2016, 9:25pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/6 "2016-01-31T21:25:11Z")

</div>

It seems to be complaining about the son\_lines codec. Can you show the exact configuration you used when you got this error?

Start with a minimal configuration and build on that, e.g. something like this:

```
input {
  ganglia {
    port => 8649
  }
}

output {
  stdout {
    codec => rubydebug
  }
}
```

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [January 31, 2016, 9:33pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/7 "2016-01-31T21:33:21Z")

</div>

Here is my input configuration  
input {  
lumberjack {  
port =\> 5043  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
ganglia {  
port =\> 8649  
}  
tcp {  
port =\> 9000  
codec =\> json\_lines  
}  
}  
and as output, I have something like this  
output {  
stdout {  
codec =\> rubydebug  
}  
}

Note the configuration with tcp is because I was first all recieving some logs on the port 9000

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2016, 3:07am UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/8 "2016-02-01T03:07:36Z")

</div>

I would recommend troubleshooting one input at a time. The error you saw appears to be caused by the tcp input and its son\_lines codec, and not the ganglia plugin. Run the TCP plugin without the codec first to ensure that data is arriving in the correct son\_lines format.

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [February 1, 2016, 10:07am UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/9 "2016-02-01T10:07:19Z")

</div>

It works once I remove the tcp plugin.  
Thanks very much @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [February 1, 2016, 4:48pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/10 "2016-02-01T16:48:00Z")

</div>

Hi @Christian\_Dahlqist

Thanks again for the help.  
I now want to send ganglia metrics to logstash without starting the gmetad.conf daemon.  
I have given a try as follows.  
In the gmond.conf  
cluster {  
name = "unspecified"  
owner = "unspecified"  
latlong = "unspecified"  
url = "unspecified"  
}

udp\_send\_channel {  
#mcast\_join = 239.2.11.71  
host = address\_of\_logstash\_server  
port = 8649  
ttl = 1  
}

tcp\_accept\_channel {  
host = address\_of\_logstash\_server  
port = 8649  
}  
I then started ganglia with the following command and stopped the gmetad.conf daemon with the following command.  
sudo service ganglia-monitor restart && sudo service gmetad stop && sudo service apache2 restart  
But unfortanately, I had nothing been displayed on logstash.  
Where am I going wrong?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 1, 2016, 4:55pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/11 "2016-02-01T16:55:27Z")

</div>

I have very limited experience with Ganglia, so will unfortunately not going to be able to help you there.

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [February 1, 2016, 6:55pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/12 "2016-02-01T18:55:46Z")

</div>

Thanks anyway. But nevertheless I manage to get it work.  
The trick was to remove the host attribute in the tag tcp\_accept\_channel.  
ie  
tcp\_accept\_channel {  
port = 8649  
}  
Hope this helps somebody in the future!!!

---

<div class="post-metadata">

**Author:** ![jstar](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jstar](https://discuss.elastic.co/u/jstar)\
**Post date:** [February 2, 2016, 7:34pm UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/13 "2016-02-02T19:34:18Z")

</div>

Hi @Christian_Dahlqvist

Sorry for the disturbance, in the last configuration, I had two machines: one handling my elk and another one handling my ganglia. The gmond.conf was configured to send its metrics to the machine holding elk. By so doing and with you help, I was able to send metrics to elk.

Now I want to consolidate both service on the same machine, with same configuration of my logstash  
ie  
input {  
ganglia {  
port =\> 8649  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
}  
I had the following exception  
:timestamp=\>"2016-02-02T19:30:46.202000+0000", :message=\>"ganglia udp listener died", :address=\>"0.0.0.0:8649", :exception=\>#\<SocketError: bind: name or service not known\>, :backtrace=\>["org/jruby/ext/socket/RubyUDPSocket.java:160:in `bind'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-ganglia-2.0.4/lib/logstash/inputs/ganglia.rb:55:in`udp\_listener'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-ganglia-2.0.4/lib/logstash/inputs/ganglia.rb:36:in `run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.0.0-java/lib/logstash/pipeline.rb:180:in`inputworker'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.0.0-java/lib/logstash/pipeline.rb:174:in `start\_input'"], :level=\>:warn}

Please can you help me sort out what is going on?  
Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/sending-ganglia-metric-to-logstash-and-the-displaying-them-on-kibana/40567/14 "2017-07-06T05:13:23Z")

</div>


