After you collect monitoring data for one or more products in the Elastic Stack, you can configure Kibana to retrieve that information and display it in on the Monitoring page.
At a minimum, you must have monitoring data for the Elasticsearch production cluster. Once that data exists, Kibana can display monitoring data for other products in the cluster.
Identify where to retrieve monitoring data from.
The cluster that contains the monitoring data is referred to as the monitoring cluster.
If the monitoring data is stored on a dedicated monitoring cluster, it is accessible even when the cluster you’re monitoring is not. If you have at least a gold license, you can send data from multiple clusters to the same monitoring cluster and view them all through the same instance of Kibana.
By default, data is retrieved from the cluster specified in the
elasticsearch.urlvalue in the
kibana.ymlfile. If you want to retrieve it from a different cluster, set
To learn more about typical monitoring architectures, see How monitoring works and Monitoring in a production environment.
xpack.monitoring.ui.enabledis set to
true, which is the default value, in the
kibana.ymlfile. For more information, see Monitoring Settings.
If the Elastic security features are enabled on the monitoring cluster, you must provide a user ID and password so Kibana can retrieve the data.
Create a user that has the
monitoring_userbuilt-in role on the monitoring cluster.
xpack.monitoring.elasticsearch.passwordsettings in the
kibana.ymlfile. If these settings are omitted, Kibana uses the
elasticsearch.passwordsetting values. For more information, see Configuring security in Kibana.
- Create a user that has the
- (Optional) Configure Kibana to encrypt communications between the Kibana server and the monitoring cluster. See Encrypting communications.
If the Elastic security features are enabled on the Kibana server, only users that have the authority to access Kibana indices and to read the monitoring indices can use the monitoring dashboards.
These users must exist on the monitoring cluster. If you are accessing a remote monitoring cluster, you must use credentials that are valid on both the Kibana server and the monitoring cluster.
Create users that have the
- Create users that have the
Open Kibana in your web browser.
By default, if you are running Kibana locally, go to
If the Elastic security features are enabled, log in.
In the side navigation, click Monitoring.
If data collection is disabled, you are prompted to turn on data collection. If Elasticsearch security features are enabled, you must have
managecluster privileges to turn on data collection.
If you are using a separate monitoring cluster, you do not need to turn on data collection. The dashboards appear when there is data in the monitoring cluster.
You’ll see cluster alerts that require your attention and a summary of the available monitoring metrics for Elasticsearch, Logstash, Kibana, and Beats. To view additional information, click the Overview, Nodes, Indices, or Instances links. See Monitoring.
If you encounter problems, see Troubleshooting monitoring.
Intro to Kibana
ELK for Logs & Metrics