Open zjk231851 opened 5 months ago
@michel-laterman I upgraded to 8.14.1 but the problem persists. Can you help me?
The data streams have data in them, what logs are you expecting to see that are missing, and where you are looking?
This is probably better suited to being a post in https://discuss.elastic.co/c/elastic-stack/elastic-agent
The data streams have data in them, what logs are you expecting to see that are missing, and where you are looking?
This is probably better suited to being a post in https://discuss.elastic.co/c/elastic-stack/elastic-agent
I want to see the fleet-server and agent logs in [Monitor Elastic Agents | Fleet and Elastic Agent Guide [8.14] | Elastic 3](https://www.elastic.co/guide/en/fleet/current/monitor-elastic-agent.html#change-logging-level) But now it's empty
I took a quick look at the diagnostics you provided, nothing in the configs stuck out to me. The filestream-monitoring is present, and the inputs shows the paths to the agent logs.
The logs also didn't have anything in the way of errors (nothing to indicate that it failed to connect to ES), the only thing i wound was a warning and inputs loading messages from filestream-monitoring, but i'm not sure if this is expected behaviour.
{"log.level":"warn","@timestamp":"2024-04-01T07:56:37.548Z","message":"Filebeat is unable to load the ingest pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the ingest pipelines or are using Logstash pipelines, you can ignore this warning.","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.origin":{"file.line":331,"file.name":"beater/filebeat.go"},"ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"creating new InputManager","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"input","log.origin":{"file.line":55,"file.name":"shipper/input.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"States Loaded from registrar: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"registrar","log.origin":{"file.line":107,"file.name":"registrar/registrar.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"Loading Inputs: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.logger":"crawler","log.origin":{"file.line":71,"file.name":"beater/crawler.go"},"ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"Loading and starting Inputs completed. Enabled inputs: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"crawler","log.origin":{"file.line":106,"file.name":"beater/crawler.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}
Do any logs show up in the discover view? Do the indcies/datastreams show up ion the management views?
I took a quick look at the diagnostics you provided, nothing in the configs stuck out to me. The filestream-monitoring is present, and the inputs shows the paths to the agent logs.
The logs also didn't have anything in the way of errors (nothing to indicate that it failed to connect to ES), the only thing i wound was a warning and inputs loading messages from filestream-monitoring, but i'm not sure if this is expected behaviour.
{"log.level":"warn","@timestamp":"2024-04-01T07:56:37.548Z","message":"Filebeat is unable to load the ingest pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the ingest pipelines or are using Logstash pipelines, you can ignore this warning.","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.origin":{"file.line":331,"file.name":"beater/filebeat.go"},"ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"creating new InputManager","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"input","log.origin":{"file.line":55,"file.name":"shipper/input.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"States Loaded from registrar: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"registrar","log.origin":{"file.line":107,"file.name":"registrar/registrar.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"Loading Inputs: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.logger":"crawler","log.origin":{"file.line":71,"file.name":"beater/crawler.go"},"ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2024-04-01T07:56:37.548Z","message":"Loading and starting Inputs completed. Enabled inputs: 0","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"crawler","log.origin":{"file.line":106,"file.name":"beater/crawler.go"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}
Do any logs show up in the discover view? Do the indcies/datastreams show up ion the management views?
discover view and management views It works
Hello, everyone. I set up a cluster with three Linux servers using elastic version 8.11.1. The information for each server is as follows: Server 1 ip-10.150.3.12 elasticsearch+kibana, server 2 ip-10.150.3.15 elasticsearch+elastic agent, and server 3 ip 10.150.3.17 elasticsearch+fleetserver. They are self-managed clusters and are configured with TSL, using self-generated certificates. When installing fleetserver and agent, I didn't do any configuration for Elasti-agent.yml, just tar and install. fleetserver and agent are up and running, but in kibana, don't see logs. May I ask where I need to troubleshoot the problem next? I uploaded my diagnostics log at the end, hoping to help with this problem. Thank you so much!
elastic-agent-diagnostics-2024-04-01T08-21-38Z-00.zip