You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kibana Monitoring标签页无法查看全部Logstash节点问题咨询

Troubleshooting Only One Logstash Node Showing Up in Monitoring

First, let's look at your provided logstash.yml configuration (formatted for clarity):

xpack.management.enabled: true
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.username: logstash_system
xpack.monitoring.elasticsearch.password: pass
xpack.monitoring.elasticsearch.hosts: [" http://es1.:9200 "," http://es2.:9200 "," http://es3.:9200 "]
xpack.management.pipeline.id: ["Firewall", "HSM","NX","ESET"]
xpack.management.elasticsearch.hosts: [" http://es1:9200 "," http://es2.:9200 "," http://es3.:9200 "]
xpack.management.elasticsearch.username: logstash_admin
xpack.management.elasticsearch.password: pass

I can spot a few immediate issues that might be causing only one node to appear in Monitoring, plus actionable steps to diagnose the rest:

  • Fix syntax and formatting errors in your config:

    • The Elasticsearch host entries have leading/trailing spaces (like " http://es1.:9200 ") and extraneous dots after hostnames (like es1.:9200). These typos will break connection attempts from affected Logstash nodes to your ES cluster. Correct them to clean entries like "http://es1:9200".
    • You have duplicate xpack.management.elasticsearch.hosts entries. Logstash may prioritize the last entry or hit parsing confusion that breaks configuration on some nodes. Remove the duplicate and keep a single, correct entry for this setting.
  • Validate config and check logs on each node:

    • On every Logstash server, run bin/logstash --config.test_and_exit to verify the config file has no syntax errors. If any node fails this test, it can't start properly and won't show up in monitoring.
    • Check the Logstash logs (typically at logs/logstash-plain.log by default) for errors related to Elasticsearch connectivity, authentication failures, or pipeline registration. Look for lines like "Failed to connect to Elasticsearch" or "Authentication failed"—these will explain why a node isn't reporting metrics.
  • Verify Elasticsearch user permissions:

    • Ensure the logstash_system user has the built-in logstash_system role assigned. This role grants the necessary permissions for Logstash to send monitoring data to Elasticsearch; missing permissions will block nodes from registering.
    • Confirm the logstash_admin user has pipeline management permissions (via the logstash_admin role or custom settings). Misconfigured access here can also prevent nodes from communicating properly with the cluster.
  • Check network and firewall rules:

    • On each Logstash node, test connectivity to your Elasticsearch cluster using curl http://es1:9200 (replace with your actual ES host) to rule out network blocks. If the curl fails, fix firewall rules or routing between nodes.
    • Make sure port 9200 is open between all Logstash servers and every Elasticsearch node in the cluster.

After addressing these points, restart each Logstash node and check the Monitoring tab again—all three nodes should appear if the issues are resolved.

内容的提问来源于stack exchange,提问作者JustAGuy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:25:39