Kibana Monitoring标签页无法查看全部Logstash节点问题咨询
Troubleshooting Only One Logstash Node Showing Up in Monitoring
First, let's look at your provided logstash.yml configuration (formatted for clarity):
xpack.management.enabled: true xpack.monitoring.enabled: true xpack.monitoring.elasticsearch.username: logstash_system xpack.monitoring.elasticsearch.password: pass xpack.monitoring.elasticsearch.hosts: [" http://es1.:9200 "," http://es2.:9200 "," http://es3.:9200 "] xpack.management.pipeline.id: ["Firewall", "HSM","NX","ESET"] xpack.management.elasticsearch.hosts: [" http://es1:9200 "," http://es2.:9200 "," http://es3.:9200 "] xpack.management.elasticsearch.username: logstash_admin xpack.management.elasticsearch.password: pass
I can spot a few immediate issues that might be causing only one node to appear in Monitoring, plus actionable steps to diagnose the rest:
Fix syntax and formatting errors in your config:
- The Elasticsearch host entries have leading/trailing spaces (like
" http://es1.:9200 ") and extraneous dots after hostnames (likees1.:9200). These typos will break connection attempts from affected Logstash nodes to your ES cluster. Correct them to clean entries like"http://es1:9200". - You have duplicate
xpack.management.elasticsearch.hostsentries. Logstash may prioritize the last entry or hit parsing confusion that breaks configuration on some nodes. Remove the duplicate and keep a single, correct entry for this setting.
- The Elasticsearch host entries have leading/trailing spaces (like
Validate config and check logs on each node:
- On every Logstash server, run
bin/logstash --config.test_and_exitto verify the config file has no syntax errors. If any node fails this test, it can't start properly and won't show up in monitoring. - Check the Logstash logs (typically at
logs/logstash-plain.logby default) for errors related to Elasticsearch connectivity, authentication failures, or pipeline registration. Look for lines like "Failed to connect to Elasticsearch" or "Authentication failed"—these will explain why a node isn't reporting metrics.
- On every Logstash server, run
Verify Elasticsearch user permissions:
- Ensure the
logstash_systemuser has the built-inlogstash_systemrole assigned. This role grants the necessary permissions for Logstash to send monitoring data to Elasticsearch; missing permissions will block nodes from registering. - Confirm the
logstash_adminuser has pipeline management permissions (via thelogstash_adminrole or custom settings). Misconfigured access here can also prevent nodes from communicating properly with the cluster.
- Ensure the
Check network and firewall rules:
- On each Logstash node, test connectivity to your Elasticsearch cluster using
curl http://es1:9200(replace with your actual ES host) to rule out network blocks. If the curl fails, fix firewall rules or routing between nodes. - Make sure port 9200 is open between all Logstash servers and every Elasticsearch node in the cluster.
- On each Logstash node, test connectivity to your Elasticsearch cluster using
After addressing these points, restart each Logstash node and check the Monitoring tab again—all three nodes should appear if the issues are resolved.
内容的提问来源于stack exchange,提问作者JustAGuy
相关产品推荐
相关产品推荐

