# View metrics shows no data for selected host

**URL:** <https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183>\
**Category:** Metrics\
**Created:** [February 6, 2020, 1:31pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183 "2020-02-06T13:31:30Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 6, 2020, 1:31pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/1 "2020-02-06T13:31:31Z")

</div>

Hi,  
I struggle with the "View Metrics" display, which shows no data for a limited user, but for the elastic superuser. The user can see the inventory of the hosts, when opening the Metrics app, he can change to Logs and get results, also changing to Uptime works fine. But the "View Metrics" action only gives the header with the host information, but no further metrics. There are data available, as the elastic user gets metrics for the same hosts. I've checked both users out of the same space. I've also checked with Discover, and the results for both users are the same.

Is there a role that needs to be added to the user to get results there ? I'm on 7.5.2 running in Elastic Cloud.

Thanks in advance for any advice.

Best regards,  
Norbert

---

<div class="post-metadata">

**Author:** ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)\
**Post date:** [February 7, 2020, 12:56pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/2 "2020-02-07T12:56:24Z")

</div>

Hi @norgro2601,

Sorry to hear you're having problems with the Metrics app.

First, please could you clarify what you mean by "Limited user" - if you could post the role / user / privilege combination you're using for this user that would help us.

Thanks!

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 7, 2020, 1:36pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/3 "2020-02-07T13:36:16Z")

</div>

Hi Kerry,

here it is, hope this helps.

Regards,  
Norbert

![Bild 1](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f463e14434a591b959392d74daf5de3dd8a70f18.png)

 ![Bild 2](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3a66d2920cbb8767ae8bcf555b4dafdc6f4b0ab0.png)

---

<div class="post-metadata">

**Author:** ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)\
**Post date:** [February 10, 2020, 10:13am UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/4 "2020-02-10T10:13:28Z")

</div>

Thank you.

I think what's happening here is your role isn't providing the privileges to allow access to [TSVB](https://www.elastic.co/guide/en/kibana/current/TSVB.html). The metrics page you're having problems with issues TSVB requests behind the scenes.

Your screenshot shows the Elasticsearch privileges, but not the Kibana privileges, so I can't be sure you have the correct Kibana privileges. [There's some relevant documentation here](https://www.elastic.co/guide/en/kibana/current/kibana-privileges.html#_assigning_feature_privileges) on assigning feature privileges - the feature in question here would be "Visualize".

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 10, 2020, 10:51am UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/5 "2020-02-10T10:51:17Z")

</div>

I've added Screenshots from Kibana privileges and what I get on the inventory panel and then in the details panel, nothing displayed, although there are data to display.

 ![Discover CPU events](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0bcf29dafc85b40e356a2a62e241a5ed7bccf78.png) ![Discover](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf25dfeab44cc4cc7b504bf7bf127eaf3285632b.png) ![Metrics details](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d86a9c55009ea04d1683a0b4d9050c4424cb733e.png) ![Metrics Inventory](https://us1.discourse-cdn.com/elastic/original/3X/0/4/04856660c1e62a107570ee8e4f473674ea3059d2.png) ![Space privileges](https://us1.discourse-cdn.com/elastic/original/3X/1/7/1733f9e58db2a33fc9412ae4704b2161aabd4fee.png)

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 10, 2020, 3:06pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/6 "2020-02-10T15:06:36Z")

</div>

Can you check to see if Metrics Explorer is working? Use `system.cpu.user.pct` as the metric and `host.name` as the grouping field. Can you post a JSON sample of an event with `system.cpu.user.pct`? Just expand on of the rows from Discover and then click the JSON tab. And finally, can you post the mappings from one of the indices?

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 10, 2020, 3:53pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/7 "2020-02-10T15:53:04Z")

</div>

In the metrics expolrer I get a dashlet for each host with "Chart data missing" and "Unable to render chart" in it. Strange thing is, when I open one of the charts in Visualize, I can see the data. I will add the JSON and Mapping in a separate reply

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 10, 2020, 3:53pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/8 "2020-02-10T15:53:37Z")

</div>

JSON:

{  
"\_index": "metricbeat-vw-2020.02.07-000023",  
"\_type": "\_doc",  
"\_id": "8q-ML3AB193DzneVcvKd",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@timestamp": "2020-02-10T15:40:37.647Z",  
"fields": {  
"customer": "VW",  
"server": "[limeprod01.volkswagenstiftung.de](http://limeprod01.volkswagenstiftung.de)",  
"ip": "83.246.48.93"  
},  
"host": {  
"name": "VW Stiftung Survey",  
"os": {  
"family": "redhat",  
"name": "CentOS Linux",  
"kernel": "3.10.0-957.5.1.el7.x86\_64",  
"codename": "Core",  
"platform": "centos",  
"version": "7 (Core)"  
},  
"containerized": false,  
"ip": [  
"192.168.100.20",  
"fe80::250:56ff:fe01:b49"  
],  
"geo": {  
"region\_iso\_code": "DE-NI",  
"city\_name": "Hannover",  
"name": "Volkswagen Stiftung",  
"location": "52.3325984,9.7678178",  
"continent\_name": "Europe",  
"country\_iso\_code": "DE",  
"region\_name": "Niedersachsen"  
},  
"architecture": "x86\_64",  
"id": "9ebe8602e45946819a3fe5754aca0c8f",  
"mac": [  
"00:50:56:01:0b:49"  
],  
"hostname": "[limeprod01.volkswagenstiftung.de](http://limeprod01.volkswagenstiftung.de)"  
},  
"service": {  
"type": "system"  
},  
"system": {  
"cpu": {  
"system": {  
"pct": 0.01  
},  
"steal": {  
"pct": 0  
},  
"total": {  
"pct": 0.025  
},  
"idle": {  
"pct": 1.974  
},  
"iowait": {  
"pct": 0.001  
},  
"cores": 2,  
"user": {  
"pct": 0.015  
},  
"nice": {  
"pct": 0  
},  
"softirq": {  
"pct": 0  
},  
"irq": {  
"pct": 0  
}  
}  
},  
"event": {  
"module": "system",  
"duration": 355301,  
"dataset": "system.cpu"  
},  
"metricset": {  
"name": "cpu",  
"period": 10000  
},  
"tags": [  
"VW Stiftung"  
],  
"ecs": {  
"version": "1.1.0"  
},  
"agent": {  
"type": "metricbeat",  
"ephemeral\_id": "582c6f47-553a-48d3-ae1c-38dc4dd3e576",  
"hostname": "[limeprod01.volkswagenstiftung.de](http://limeprod01.volkswagenstiftung.de)",  
"id": "216d6278-be95-4e18-8011-cef62acae8af",  
"version": "7.4.1",  
"name": "VW Stiftung Survey"  
}  
},  
"fields": {  
"@timestamp": [  
"2020-02-10T15:40:37.647Z"  
]  
},  
"sort": [  
1581349237647  
]  
}

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 10, 2020, 4:02pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/9 "2020-02-10T16:02:32Z")

</div>

Mapping cannot be posted completely, because it is too long, you'll find "system.cpu" here, is that OK?

```
      "cpu": {
        "properties": {
          "cores": {
            "type": "long"
          },
          "idle": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "iowait": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "irq": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "nice": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "softirq": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "steal": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "system": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          },
          "total": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              }
            }
          },
          "user": {
            "properties": {
              "norm": {
                "properties": {
                  "pct": {
                    "type": "scaled_float",
                    "scaling_factor": 1000
                  }
                }
              },
              "pct": {
                "type": "scaled_float",
                "scaling_factor": 1000
              },
              "ticks": {
                "type": "long"
              }
            }
          }
        }
      },
```

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 10, 2020, 4:41pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/10 "2020-02-10T16:41:07Z")

</div>

Can you just confirm that `host.name` and `event.dataset` are `keyword` fields.

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 10, 2020, 6:03pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/11 "2020-02-10T18:03:38Z")

</div>

Yes, both are keyword fields

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 10, 2020, 6:07pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/12 "2020-02-10T18:07:23Z")

</div>

I will try and recreate this issue locally to see if I can provide more insight.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 11, 2020, 3:42pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/13 "2020-02-11T15:42:04Z")

</div>

I setup a cloud account and created a user that is almost identical to the user you provided and everything seems to be working. Can you look at the `Elasticsearch > Logs` page in your cloud account and see if there are any errors?

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 11, 2020, 4:14pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/14 "2020-02-11T16:14:39Z")

</div>

No errors, just 2 warnings about deprecation came up, when I tried to view the metrics, but I'm not sure, if they are related to the function, because the instance 82 is a warm node.

 ![warn](https://us1.discourse-cdn.com/elastic/original/3X/6/9/6942cb4edbf0bcbf96cb14c1ce3aba350fd39219.png)

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 11, 2020, 4:29pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/15 "2020-02-11T16:29:03Z")

</div>

I've now tried another setup, I've added the kibana\_user role to the user, and immediately it works. So there must be something necessary missing in the vw\_user role.

---

<div class="post-metadata">

**Author:** ![norgro2601](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/norgro2601/32/33292_2.png) [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Post date:** [February 11, 2020, 4:33pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/16 "2020-02-11T16:33:06Z")

</div>

Here is the role setup from the API:

{  
"VW\_user" : {  
"cluster" : ,  
"indices" : [  
{  
"names" : [  
"filebeat-vw-_",  
"metricbeat-vw-_",  
"logstash-vw-_",  
"heartbeat-vw-_"  
],  
"privileges" : [  
"read"  
],  
"field\_security" : {  
"grant" : [  
"\*"  
],  
"except" :   
},  
"allow\_restricted\_indices" : false  
}  
],  
"applications" : [  
{  
"application" : "kibana-.kibana",  
"privileges" : [  
"feature\_discover.read",  
"feature\_dashboard.read",  
"feature\_infrastructure.read",  
"feature\_logs.read",  
"feature\_uptime.read",  
"feature\_siem.read",  
"feature\_visualize.read"  
],  
"resources" : [  
"space:volkswagen-stiftung"  
]  
}  
],  
"run\_as" : ,  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 11, 2020, 5:15pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/17 "2020-02-11T17:15:00Z")

</div>

Good News! I've recreated the issue on my cloud account. I'm going to dig into this and see if I can come up with a work around for you.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 11, 2020, 5:27pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/18 "2020-02-11T17:27:15Z")

</div>

Ok... Here is what I came up with. When I assigned my test user just the `VW_user` role I could see the Metrics UI but I couldn't see the charts in Metrics Explorer or the charts on the metric detail page. BUT if I also added the `kibana_user` role to my test user, everything started working as expected.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 11, 2020, 6:08pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/19 "2020-02-11T18:08:38Z")

</div>

Sorry... I wasn't happy with just applying the `kibana_user` role to the test user so I did some more poking around and found this combination works:

```auto
{
  "vw_test_role" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "metricbeat-*"
        ],
        "privileges" : [
          "read"
        ],
        "field_security" : {
          "grant" : [
            "*"
          ],
          "except" : []
        },
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [
      {
        "application" : "kibana-.kibana",
        "privileges" : [
          "feature_infrastructure.read"
        ],
        "resources" : [
          "space:vw-test-space"
        ]
      },
      {
        "application" : "kibana-.kibana",
        "privileges" : [
          "feature_infrastructure.read"
        ],
        "resources" : [
          "space:default"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

I'm gonna do some more digging on our end to see why the `default` space permission need to be there.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 11, 2020, 8:31pm UTC](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183/20 "2020-02-11T20:31:20Z")

</div>

@norgro2601 I've tracked down the root cause, there is an issue on our end where the call to TSVB's backend is being made under the `Default` space. We are looking into addressing this issue. For now, the work around is to add the Default space to your role with the same restrictions as your custom space.

Sorry for the inconvenience.

[Next page](https://discuss.elastic.co/t/view-metrics-shows-no-data-for-selected-host/218183.md?page=2)
