# Stack Monitoring - Elasticsearch Nodes not displayed as monitored with Metricbeat

**URL:** <https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [June 23, 2022, 9:51am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979 "2022-06-23T09:51:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndreiRD](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Post date:** [June 23, 2022, 9:51am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/1 "2022-06-23T09:51:26Z")

</div>

Hi,

I'm trying to set up Stack Monitoring and I went through all the steps from here: [Collecting Elasticsearch monitoring data with Metricbeat | Elasticsearch Guide [8.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.2/configuring-metricbeat.html)

1. Enabled the collection of monitoring data. Check the current settings below:

```auto
    "xpack" : {
      "monitoring" : {
        "elasticsearch" : {
          "collection" : {
            "enabled" : "false"
          }
        },
        "collection" : {
          "enabled" : "true"
        }
      }
    }

```

1. Installed metricbeat on each node and enabled the elasticsearch-xpack module:

```auto
- module: elasticsearch
  xpack.enabled: true
  period: 10s
  scope: node
  hosts: ["https:/elasticsearch01:9200", "https:/elasticsearch02:9200", "https://elasticsearch03:9200"]
  username: "user"
  password: "password"
  ssl.certificate_authorities: ["/etc/metricbeat/cert.crt"]

```

1. Sent the monitoring data to the same cluster:

```auto
output.elasticsearch:
  hosts: ["https:/elasticsearch01:9200", "https:/elasticsearch02:9200", "https://elasticsearch03:9200"]
  protocol: "https"
  username: "user"
  password: "password"
  output.elasticsearch.ssl.certificate_authorities:
    - "/etc/metricbeat/cert.crt"

```

1. Started metricbeat.
2. Disabled the default collection of Elasticsearch monitoring metrics.
3. Disabled the system module.

However, this is the result from Stack Monitoring. Here "some" means all hot and warm nodes.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/8/089ec27b58455146db706516edb135812bca3209.png)

What am I missing here?  
Any ideas/suggestions would be much appreciated.

Other details:

- Elastic version: 8.2.0
- Metricbeat version: 8.2.0
- the cluster has 3 dedicated master nodes. The best practices in our case suggest to set `scope: cluster` in the `elasticsearch-xpack` module which will require a single cluster endpoint in the `hosts: []` that will not direct requests to dedicated master nodes. Basically a load-balancer for hot & warm nodes (...in my understanding)? However, at the moment considering this is still not clear for us, we decided to go with `scope: node` even if this means additional load on the elected master node.

---

<div class="post-metadata">

**Author:** ![AndreiRD](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Post date:** [July 1, 2022, 9:11am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/2 "2022-07-01T09:11:11Z")

</div>

If anyone comes across this again:

- I noticed the following error keep repeating in the Metricbeat logs:

```auto
{"type":"mapper_parsing_exception","reason":"failed to parse field [elasticsearch.node.stats.os.cgroup.memory.limit.bytes] of type [byte] in document with id 'redacted'. Preview of field's value: 'max'","caused_by":{"type":"number_format_exception","reason":"For input string: "max""}}, dropping event!

```

- So I went to `.monitoring-es-mb` Index Template and changed the type of `elasticsearch.node.stats.os.cgroup.memory.limit.bytes` from `Numeric/Long` to `Keyword`;
- I rolled over the `.monitoring-es-8-mb` data stream;
- Metricbeat was no longer erroring out and Node Information started to be displayed in Stack Monitoring.

---

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [July 4, 2022, 7:18am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/3 "2022-07-04T07:18:49Z")

</div>

Thanks Andrei! We have that issue captured in [[Stack Monitoring] Mapping for elasticsearch.node.stats.os.cgroup.memory.limit.bytes is incorrect · Issue #31765 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/31765) - feel free to comment with any other info you think might be helpful.

---

<div class="post-metadata">

**Author:** ![AndreiRD](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Post date:** [July 5, 2022, 6:52am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/4 "2022-07-05T06:52:09Z")

</div>

Great! Don't have any additional input at the moment. Since I changed the type to `keyword`, Stack Monitoring seems to be working properly.

However, thanks for this link. I didn't know this is where I should have checked the field type first:

> **[Nodes stats API | Elasticsearch Guide \[8.3\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-stats.html)**

---

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [July 6, 2022, 1:23am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/5 "2022-07-06T01:23:46Z")

</div>

Nice! Thanks for letting me know and glad you found a workaround.

Just note that your template change could get reverted.

The [template](https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/core/src/main/resources/monitoring-es-mb.json) ships with Elasticsearch and can get overwritten when nodes start up.

A permanent fix will be to upgrade to the next release after the [issue](https://github.com/elastic/beats/issues/31765) is closed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2022, 1:24am UTC](https://discuss.elastic.co/t/stack-monitoring-elasticsearch-nodes-not-displayed-as-monitored-with-metricbeat/307979/6 "2022-08-03T01:24:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
