# \#elastic-stack-monitoring

**URL:** https://discuss.elastic.co/tag/elastic-stack-monitoring/7.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [System integration does not report filesystem metrics for network-mounted filesystem](https://discuss.elastic.co/t/system-integration-does-not-report-filesystem-metrics-for-network-mounted-filesystem/389722)

<div class="topic-metadata">

**Author:** [@Barbarossa](https://discuss.elastic.co/u/Barbarossa)\
**Replies:** 2\
**Last updated:** [September 3, 2026, 9:07pm UTC](https://discuss.elastic.co/t/system-integration-does-not-report-filesystem-metrics-for-network-mounted-filesystem/389722 "2026-09-03T21:07:15Z")

</div>

Hi, I’m collecting host metrics from my Elasticsearch nodes using the System integration. Filesystem metrics are collected correctly for all of my local mount points under /mnt/\*, for example /mnt/es\_data, but I’m not …

---

## [Indices Stack Monitoring - Cannot expand \`inner\_hits\` for collapse field \`index\_stats.index\`](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205)

<div class="topic-metadata">

**Author:** [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Replies:** 3\
**Last updated:** [August 12, 2026, 3:53pm UTC](https://discuss.elastic.co/t/indices-stack-monitoring-cannot-expand-inner-hits-for-collapse-field-index-stats-index/386205 "2026-08-12T15:53:42Z")

</div>

Hello, We have updated to Elasticsearch 9.4.0, Kibana 9.4.0, Elastic Agent 9.4.0 and Elasticsearch monitoring integration 1.20.2. Since then, the Stack Monitong Indices tab is broken and does not load the dashboard: …

---

## [Only One Scheduled Osquery Query Pack Runs in Agent Policy](https://discuss.elastic.co/t/only-one-scheduled-osquery-query-pack-runs-in-agent-policy/388792)

<div class="topic-metadata">

**Author:** [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Replies:** 0\
**Last updated:** [July 26, 2026, 12:33pm UTC](https://discuss.elastic.co/t/only-one-scheduled-osquery-query-pack-runs-in-agent-policy/388792 "2026-07-26T12:33:00Z")

</div>

Hello, I am using Elastic Agent 8.19.14 and collecting systemd unit information through the Osquery Manager integration. Recently, I have encountered an issue where, if I configure two query packs within the same Agent…

---

## [ML anomaly detection for log-volume drop detection and looking for real-world experiences (low\_count, high count)](https://discuss.elastic.co/t/ml-anomaly-detection-for-log-volume-drop-detection-and-looking-for-real-world-experiences-low-count-high-count/387299)

<div class="topic-metadata">

**Author:** [@battal](https://discuss.elastic.co/u/battal)\
**Replies:** 3\
**Last updated:** [July 22, 2026, 9:54am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-for-log-volume-drop-detection-and-looking-for-real-world-experiences-low-count-high-count/387299 "2026-07-22T09:54:50Z")

</div>

Hello dear Elastic Community, I am new here. I'm building out log-source health monitoring across a multi-tenant ECE deployment and would love to hear how others have approached this with ML anomaly detection, especiall…

---

## [Elastic stack \> Monitoring \> Indices Not Showing the indices](https://discuss.elastic.co/t/elastic-stack-monitoring-indices-not-showing-the-indices/387608)

<div class="topic-metadata">

**Author:** [@kkumar123](https://discuss.elastic.co/u/kkumar123)\
**Replies:** 3\
**Last updated:** [July 15, 2026, 8:39pm UTC](https://discuss.elastic.co/t/elastic-stack-monitoring-indices-not-showing-the-indices/387608 "2026-07-15T20:39:37Z")

</div>

Kibana Stack monitoring \> Indices not showing indices i have monitoring enabled via elastic agent and currently i see other monitoring stats but this one tab is not showing any indices stats Elastic Stack \> Kibana ela…

---

## [Fleet-managed APM Server monitoring metrics on a dedicated monitoring cluster](https://discuss.elastic.co/t/fleet-managed-apm-server-monitoring-metrics-on-a-dedicated-monitoring-cluster/387506)

<div class="topic-metadata">

**Author:** [@javierE](https://discuss.elastic.co/u/javierE)\
**Replies:** 3\
**Last updated:** [July 6, 2026, 6:39pm UTC](https://discuss.elastic.co/t/fleet-managed-apm-server-monitoring-metrics-on-a-dedicated-monitoring-cluster/387506 "2026-07-06T18:39:14Z")

</div>

Hi everyone, I'm testing a fleet-managed apmserver and trying to understand the correct way to monitor the APM Server itself. My current setup is: A Fleet-managed APM Server. (stack version 9.4.1) The policy default…

---

## [Instrumentation failure with Java Agent 1.56](https://discuss.elastic.co/t/instrumentation-failure-with-java-agent-1-56/387319)

<div class="topic-metadata">

**Author:** [@igorlovich](https://discuss.elastic.co/u/igorlovich)\
**Replies:** 5\
**Last updated:** [June 26, 2026, 12:26pm UTC](https://discuss.elastic.co/t/instrumentation-failure-with-java-agent-1-56/387319 "2026-06-26T12:26:03Z")

</div>

Hello, After upgrading to Java Agent 1.56 Instrumentation stopped working. It works fine with 1.55.6. Java version: 26.0.1+8-FR (Amazon.com Inc.) Linux 6.12.88-119.157.amzn2023.x86\_64 Tomcat version: 10.1.55 Linux: A…

---

## [Count of record drops on the hour](https://discuss.elastic.co/t/count-of-record-drops-on-the-hour/386676)

<div class="topic-metadata">

**Author:** [@HuwT](https://discuss.elastic.co/u/HuwT)\
**Replies:** 3\
**Last updated:** [June 5, 2026, 5:01pm UTC](https://discuss.elastic.co/t/count-of-record-drops-on-the-hour/386676 "2026-06-05T17:01:39Z")

</div>

Hello, I am running a single node ELK cluster including filebeat. My main pipeline involves Filebeat \> Logstash \> Elastic and I'm running no log mutations or alterations in logstash. I am seeing periodic drops, approxim…

---

## [Kaspersky Logs for SOC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695)

<div class="topic-metadata">

**Author:** [@breno.bazaga](https://discuss.elastic.co/u/breno.bazaga)\
**Replies:** 0\
**Last updated:** [June 3, 2026, 1:49pm UTC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695 "2026-06-03T13:49:51Z")

</div>

Hello everyone, I currently work in a SOC environment and I am working on a use case involving monitoring and ingestion of Kaspersky logs into Elastic for managed security services. During the integration process, I no…

---

## [Kibana Showing Only 5xx Errors for API Logs Despite of receving 200 Responses too in Analytics](https://discuss.elastic.co/t/kibana-showing-only-5xx-errors-for-api-logs-despite-of-receving-200-responses-too-in-analytics/386525)

<div class="topic-metadata">

**Author:** [@devapi](https://discuss.elastic.co/u/devapi)\
**Replies:** 1\
**Last updated:** [May 27, 2026, 6:46pm UTC](https://discuss.elastic.co/t/kibana-showing-only-5xx-errors-for-api-logs-despite-of-receving-200-responses-too-in-analytics/386525 "2026-05-27T18:46:40Z")

</div>

We have successfully set up and integrated Elasticsearch with the IBM Analytics subsystem to offload API logs into ELK. However, while applying a filter on the API-Name field in the Kibana UI for a specific valid timesta…

---

## [Free Elasticsearch MCP Server with a Semantic-to-Lexical layer for Business rules](https://discuss.elastic.co/t/free-elasticsearch-mcp-server-with-a-semantic-to-lexical-layer-for-business-rules/386456)

<div class="topic-metadata">

**Author:** [@rbeg](https://discuss.elastic.co/u/rbeg)\
**Replies:** 0\
**Last updated:** [May 22, 2026, 12:45pm UTC](https://discuss.elastic.co/t/free-elasticsearch-mcp-server-with-a-semantic-to-lexical-layer-for-business-rules/386456 "2026-05-22T12:45:44Z")

</div>

Hello guys, this is A generic Model Context Protocol (MCP) server that connects LLMs to Elasticsearch, with a Semantic-to-Lexical (S2L) layer that translates technical field names into business knowledge — without har…

---

## [Help in selecting the right Stack Monitoring Mode - Node vs Cluster?](https://discuss.elastic.co/t/help-in-selecting-the-right-stack-monitoring-mode-node-vs-cluster/386238)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 1\
**Last updated:** [May 11, 2026, 1:23pm UTC](https://discuss.elastic.co/t/help-in-selecting-the-right-stack-monitoring-mode-node-vs-cluster/386238 "2026-05-11T13:23:32Z")

</div>

Hey everyone, we are still on version 8.x, since we still have selfmonitoring enabled, but we want to move to version 9 as soon as possible. For now we want to switch to agent based monitoring (AutoOps is a possibility…

---

## [Logstash monitoring is not enabled despite Helm values](https://discuss.elastic.co/t/logstash-monitoring-is-not-enabled-despite-helm-values/385998)

<div class="topic-metadata">

**Author:** [@CitizenSteak](https://discuss.elastic.co/u/CitizenSteak)\
**Replies:** 2\
**Last updated:** [April 23, 2026, 10:09am UTC](https://discuss.elastic.co/t/logstash-monitoring-is-not-enabled-despite-helm-values/385998 "2026-04-23T10:09:51Z")

</div>

Hello, In my current ECK deployment (using the eck-stack chart), Logstash monitoring is not enabled, while Elasticsearch and Kibana monitoring are working as expected. Current Logstash Configuration (Excerpt) eck-logst…

---

## [Crowdstrike Integration Degraded](https://discuss.elastic.co/t/crowdstrike-integration-degraded/385987)

<div class="topic-metadata">

**Author:** [@4l13v](https://discuss.elastic.co/u/4l13v)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 1:23pm UTC](https://discuss.elastic.co/t/crowdstrike-integration-degraded/385987 "2026-04-22T13:23:18Z")

</div>

The problem is 3 months ago, I have integrated Crowdstrike via API. It okay, and I am getting alerts from Falcon without problems. But Fleet server came unhealthy in these days. {failed to decode discover body: EOF} . …

---

## [Sythetics icmp down alert received but host and agent had been unenrolled!](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [April 13, 2026, 9:20am UTC](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866 "2026-04-13T09:20:44Z")

</div>

host had been decommissioned. agent had been unrolled weeks back BUT still getting sythetics icmp down alert today. Kindly assist!

---

## [GUI \>\> Cluster \>\> Logstash \>\> Nodes (no nodes displayed)](https://discuss.elastic.co/t/gui-cluster-logstash-nodes-no-nodes-displayed/385739)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [April 9, 2026, 5:50am UTC](https://discuss.elastic.co/t/gui-cluster-logstash-nodes-no-nodes-displayed/385739 "2026-04-09T05:50:33Z")

</div>

When we click on Nodes under the Logstash section. Nothing is displayed!!

---

## [Cluster logs for errors in GUI (via filter) if not whatst the specific index to search](https://discuss.elastic.co/t/cluster-logs-for-errors-in-gui-via-filter-if-not-whatst-the-specific-index-to-search/385738)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [April 7, 2026, 10:46am UTC](https://discuss.elastic.co/t/cluster-logs-for-errors-in-gui-via-filter-if-not-whatst-the-specific-index-to-search/385738 "2026-04-07T10:46:11Z")

</div>

This morning we were having slowness on our web console. From the cluster overview page. There were many high CPU for nodes. https://XXXXXXXXX.aws.found.io/app/monitoring#/overview? When we zoom it we found that they …

---

## [ELK - SAS drivers](https://discuss.elastic.co/t/elk-sas-drivers/385754)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 1\
**Last updated:** [April 4, 2026, 1:58pm UTC](https://discuss.elastic.co/t/elk-sas-drivers/385754 "2026-04-04T13:58:33Z")

</div>

Colleagues, good afternoon! Please tell me about the following issue. We plan to consider the possibility of deploying Elastic in our infrastructure, however, at the moment the main available storage is SAS disks. The…

---

## [Query for top xx usage elasticsearch nodes](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 7\
**Last updated:** [March 29, 2026, 2:14pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581 "2026-03-29T14:14:30Z")

</div>

Trying to create a query for my cluster elasticsearch nodes. I want it to show nodes that is more than xx% of cpu or memory or JVM heap or free space left in % Not sure if I have selected the correct field for CPU , j…

---

## [After reindexing. what needs to be done for alerts and dashboard?](https://discuss.elastic.co/t/after-reindexing-what-needs-to-be-done-for-alerts-and-dashboard/385599)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 0\
**Last updated:** [March 25, 2026, 6:59am UTC](https://discuss.elastic.co/t/after-reindexing-what-needs-to-be-done-for-alerts-and-dashboard/385599 "2026-03-25T06:59:32Z")

</div>

We are re-indexing our indices and giving it a new name lets say "indicies\_name\_v2" I suppose this will have impact to our alerts and dashboard Correct me if i am wrong. For alerts i suppose this is what we need to do …

---

## [Setting up self managed ELK stack with TLS/HTTPS issue](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102)

<div class="topic-metadata">

**Author:** [@BenNCSU](https://discuss.elastic.co/u/BenNCSU)\
**Replies:** 11\
**Last updated:** [March 5, 2026, 2:16am UTC](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102 "2026-03-05T02:16:44Z")

</div>

I’m trying to set up an ELK stack for SIEM doing a standard install. I installed Elasticsearch and Kibana, which worked fine using HTTP, but when I tried to set up TLS using a self-signed certificate from our CA, I can’…

---

## [Elastic Agent + Security Onion](https://discuss.elastic.co/t/elastic-agent-security-onion/385187)

<div class="topic-metadata">

**Author:** [@harry22](https://discuss.elastic.co/u/harry22)\
**Replies:** 0\
**Last updated:** [February 24, 2026, 4:31pm UTC](https://discuss.elastic.co/t/elastic-agent-security-onion/385187 "2026-02-24T16:31:55Z")

</div>

Hi team, I recentely deployed Security onion lab on Vmware workstation Allowed allow hosts on Security Onion with my home private Subnet Checked and verified all services showing up on VM Checked and verified on Pow…

---

## [How do you calculate the average document size in streams?](https://discuss.elastic.co/t/how-do-you-calculate-the-average-document-size-in-streams/385117)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 1\
**Last updated:** [February 19, 2026, 4:08pm UTC](https://discuss.elastic.co/t/how-do-you-calculate-the-average-document-size-in-streams/385117 "2026-02-19T16:08:24Z")

</div>

Streams is a really great feature that you have added, which was really needed. Now for the question. As the title suggests. How does the daily average get calculated? I tried calculating the average document size by…

---

## [Cannot Edit Monitor](https://discuss.elastic.co/t/cannot-edit-monitor/384846)

<div class="topic-metadata">

**Author:** [@lomar](https://discuss.elastic.co/u/lomar)\
**Replies:** 4\
**Last updated:** [February 2, 2026, 11:51am UTC](https://discuss.elastic.co/t/cannot-edit-monitor/384846 "2026-02-02T11:51:06Z")

</div>

When I try to delete via the Elasticsearch API, I get the same error code. I would appreciate your help. ELK Stack version: 9.2.4 Cluster status: green

---

## [EDOT running in Gateway mode - "sending queue is full"](https://discuss.elastic.co/t/edot-running-in-gateway-mode-sending-queue-is-full/384639)

<div class="topic-metadata">

**Author:** [@kazagz](https://discuss.elastic.co/u/kazagz)\
**Replies:** 1\
**Last updated:** [January 27, 2026, 7:32am UTC](https://discuss.elastic.co/t/edot-running-in-gateway-mode-sending-queue-is-full/384639 "2026-01-27T07:32:43Z")

</div>

When using recommended elastic/elastic-agent image running in OTEL Gateway mode it shows errors when ingesting 10m and 60m aggregated data. Example setup Start Elastic server using elasticsearch/elasticsearch:9.2.3 D…

---

## [Error during agent enrollment](https://discuss.elastic.co/t/error-during-agent-enrollment/384246)

<div class="topic-metadata">

**Author:** [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Replies:** 2\
**Last updated:** [January 9, 2026, 3:15pm UTC](https://discuss.elastic.co/t/error-during-agent-enrollment/384246 "2026-01-09T15:15:32Z")

</div>

Hello everyone, I am trying to install Elastic Agent version 8.16.2 on Windows servers. On some servers the installation succeeds, but on others it fails with the error: failed to create new agent info: could not get …

---

## [Kibana “Managed API keys” can be hidden/misclassified by editing metadata.managed (UI + Dev Tools)](https://discuss.elastic.co/t/kibana-managed-api-keys-can-be-hidden-misclassified-by-editing-metadata-managed-ui-dev-tools/384407)

<div class="topic-metadata">

**Author:** [@Bolto](https://discuss.elastic.co/u/Bolto)\
**Replies:** 0\
**Last updated:** [January 7, 2026, 10:47am UTC](https://discuss.elastic.co/t/kibana-managed-api-keys-can-be-hidden-misclassified-by-editing-metadata-managed-ui-dev-tools/384407 "2026-01-07T10:47:20Z")

</div>

Hi Elastic team/community, While reviewing API Keys in Kibana, I noticed that the flag used to identify Managed API keys (created/used by Kibana background tasks) can be overwritten by a user by editing the API key meta…

---

## [Any Reason traces-apm@template is using Standard Index mode instead of timeseries or logsdb](https://discuss.elastic.co/t/any-reason-traces-apm-template-is-using-standard-index-mode-instead-of-timeseries-or-logsdb/383301)

<div class="topic-metadata">

**Author:** [@Serak\_Shiferaw](https://discuss.elastic.co/u/Serak_Shiferaw)\
**Replies:** 10\
**Last updated:** [December 22, 2025, 8:51am UTC](https://discuss.elastic.co/t/any-reason-traces-apm-template-is-using-standard-index-mode-instead-of-timeseries-or-logsdb/383301 "2025-12-22T08:51:09Z")

</div>

we are capturing enterprise java traces, and the trace is filling up all the spaces on my cluster, its generating 1.4TB daily and i cant keep up, then upon checking there is no compression on the created index and its ju…

---

## [Elastic cluster is getting down after 2 - 3 hours](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971)

<div class="topic-metadata">

**Author:** [@sathish12](https://discuss.elastic.co/u/sathish12)\
**Replies:** 55\
**Last updated:** [December 17, 2025, 10:50am UTC](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971 "2025-12-17T10:50:55Z")

</div>

Hi Everyone. I am using elastic 8.13.4 and I have 3 machines with 30 gb of RAM and 1tb of hard disk for each machine. I am creating 2 nodes per each machine through elastic portable download ealsticsearch-8.13.4.tar.gz.…

---

## [Configure High Availability setup for elastic stack](https://discuss.elastic.co/t/configure-high-availability-setup-for-elastic-stack/383819)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 3\
**Last updated:** [December 15, 2025, 7:35am UTC](https://discuss.elastic.co/t/configure-high-availability-setup-for-elastic-stack/383819 "2025-12-15T07:35:09Z")

</div>

Hi Elastic Experts, I would appreciate your inputs on the queries below. We have a requirement to configure high availability across two data centers (DC and DR) for Elasticsearch nodes, Logstash, and Kibana. The custo…

[Next page](https://discuss.elastic.co/tag/elastic-stack-monitoring/7.md?match_all_tags=true&page=1&tags%5B%5D=elastic-stack-monitoring)
