# Configuration of Metricbeat

**URL:** <https://community.graylog.org/t/configuration-of-metricbeat/815>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, winlogbeat\
**Created:** [April 13, 2017, 1:14pm UTC](https://community.graylog.org/t/configuration-of-metricbeat/815 "2017-04-13T13:14:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tras2](https://avatars.discourse-cdn.com/v4/letter/t/71e660/32.png) [@Tras2](https://community.graylog.org/u/Tras2)\
**Post date:** [April 13, 2017, 1:14pm UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/1 "2017-04-13T13:14:10Z")

</div>

Hi everyone.

I have a question about Metricbeat

I’m using a Graylog 2.2.3 standalone virtual appliance (proof-of-concept environment). When I go to System-\>Collectors-\>Manage Configurations and create a new configuration, on the inputs I only see [FileBeat] and [WinLogBeat] as options (i.e. missing MetricBeat)

The node’s installed plugins show ‘Elastic Beats Input 2.2.3’ and according to [https://github.com/Graylog2/graylog-plugin-beats](https://github.com/Graylog2/graylog-plugin-beats), that version includes Metricbeat (along with Packetbeat which is also missing)

What am I doing wrong or missing?

Or does the Graylog UI currently not support collector-sidecar configuration of the Metricbeat?

Thanks

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 13, 2017, 1:45pm UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/2 "2017-04-13T13:45:36Z")

</div>

The Graylog Collector Sidecar currently only supports Filebeat, Winlogbeat, and nxlog.

You can use any other beat with the Graylog Beats input, though.

---

<div class="post-metadata">

**Author:** ![Tras2](https://avatars.discourse-cdn.com/v4/letter/t/71e660/32.png) [@Tras2](https://community.graylog.org/u/Tras2)\
**Post date:** [April 13, 2017, 2:29pm UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/3 "2017-04-13T14:29:56Z")

</div>

Thanks for the clarification - my searching couldn’t find an answer one way or another

While I was waiting for a reply I manually configured a metricbeat on a windows server and I have the data coming in. I’ll have to consider how to manage the Metricbeat configuration as it’s now separate to the management of the File/WinLog beat configuration (I’m liking the collector-sidecar)

For anyone who’s interested, (rightly or wrongly!) this is what I did:-

1. Goto System-\>Inputs. Add a ‘Beats’ input to a node (or add globally). Make a note of the port number

2. Install metricbeat on a server as per [https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-installation.html](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-installation.html)

3. Configure metricbeat.yml on the server as required. Make sure the logstash output is enabled and points to the Graylog Beats input (example below)

4. (re)start the Metricbeat service/process

---

<div class="post-metadata">

**Author:** ![drAlberT](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dralbert/32/1761_2.png) [@drAlberT](https://community.graylog.org/u/drAlberT)\
**Post date:** [June 30, 2018, 1:43pm UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/4 "2018-06-30T13:43:39Z")

</div>

Is there any plan to manage this in the sidecar itself? would be so nice

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [July 1, 2018, 8:51am UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/5 "2018-07-01T08:51:29Z")

</div>

[https://github.com/Graylog2/collector-sidecar/issues/103](https://github.com/Graylog2/collector-sidecar/issues/103)

---

<div class="post-metadata">

**Author:** ![Totally\_Not\_A\_Robot](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/totally_not_a_robot/32/3353_2.png) [@Totally\_Not\_A\_Robot](https://community.graylog.org/u/Totally_Not_A_Robot)\
**Post date:** [December 17, 2018, 8:52am UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/6 "2018-12-17T08:52:10Z")

</div>

I do believe this was shown in the Graylog 3.0 demo 🙂

@jan, could it be that the linked Github issue hasn’t been updated yet?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [December 17, 2018, 9:21am UTC](https://community.graylog.org/t/configuration-of-metricbeat/815/7 "2018-12-17T09:21:06Z")

</div>

> @jan, could it be that the linked Github issue hasn’t been updated yet?

yes - it is very likely. After the 3.0 we need to clean up all issues, check feature issues and similar. But currently we decide to actually work on the product and if all is finished, use the RC phase to clean up.
