Se você concluiu a instalação da integração do Elasticsearch com OpenTelemetry ou a instalação no Kubernetes mas não vê dados no New Relic, encontre seu problema abaixo e siga as etapas de solução.
Implantações baseadas em host
Como verificar
$sudo systemctl status otelcol-contribResolução
- Se o serviço estiver inativo, inicie-o:
sudo systemctl start otelcol-contrib - Se o serviço falhou, corrija os erros de configuração e reinicie:
sudo systemctl restart otelcol-contrib
Como verificar
$sudo journalctl -u otelcol-contrib.service -fResolução
Analise a saída do log e resolva a causa raiz (por exemplo, problemas de conexão, falhas de autenticação ou problemas de permissão).
Amostra de erro:
dial tcp [::1]:9200: connect: connection refused
Resolução
- Certifique-se de que o
endpointemconfig.yamlcorresponda ao host e à porta do Elasticsearch. - Confirme se o Elasticsearch está em execução e acessível a partir do host do coletor.
Amostra de erro:
permanent error: 403 Forbidden
Resolução
Verifique
NEWRELIC_LICENSE_KEYem/etc/systemd/system/otelcol-contrib.service.d/environment.conf.Recarregue o systemd e reinicie o coletor:
bash$sudo systemctl daemon-reload$sudo systemctl restart otelcol-contrib
Amostra de erro:
permission denied
ou
cannot open file
Resolução
- Adicione o usuário do coletor ao grupo Elasticsearch:bash$sudo usermod -a -G elasticsearch otelcol-contrib
- Reinicie o coletor:
sudo systemctl restart otelcol-contrib
Como verificar
$# Unsecured cluster$curl -I http://localhost:9200$
$# With authentication$curl -u username:password -k https://localhost:9200Resolução
Verifique se o cluster está íntegro, se as credenciais são válidas e se as configurações de firewall ou segurança permitem o acesso.
Resolução
- Garanta que o processador
resourcedetectionesteja incluído em todos os pipelines de métricas. - Verifique se
elasticsearch.cluster.nameestá definido via processadorresource/cluster_name_override.
Resolução
- Confirme se os caminhos do receptor
filelogestão corretos e absolutos. - Verifique se o pipeline de logs inclui tanto o receptor
filelogquanto o exportadorotlphttp.
Implantações do Kubernetes
Como verificar
$# Verify your Elasticsearch pods have the required label$kubectl get pods -n <namespace> -l app=elasticsearch --show-labelsResolução
Se nenhum pod for retornado, seus pods do Elasticsearch não possuem o rótulo
app=elasticsearch
obrigatório. O receiver_creator não consegue descobrir pods sem rótulos correspondentes.
- Para StatefulSet/Implantação, adicione o rótulo no modelo do pod:spec:template:metadata:labels:app: elasticsearch
- Para pods existentes, adicione o rótulo e reinicie:bash$kubectl label pods -l <your-selector> app=elasticsearch -n <namespace>$kubectl rollout restart statefulset/elasticsearch -n <namespace>
- Se estiver usando rótulos personalizados, atualize a regra do receiver no values.yaml para corresponder aos seus rótulos:rule: type == "pod" && labels["app"] == "your-custom-label"
Como verificar
$kubectl get pods -n newrelic$kubectl describe pod <collector-pod-name> -n newrelicResolução
Verifique os eventos do pod para erros:
kubectl describe podRevise os logs do coletor:
bash$kubectl logs -n newrelic -l app.kubernetes.io/name=opentelemetry-collectorVerifique se o segredo existe:
bash$kubectl get secret newrelic-licenses -n newrelicVerifique se os limites de recursos não estão muito baixos
Como verificar
$# Check collector logs for discovery errors$kubectl logs -n newrelic -l app.kubernetes.io/name=opentelemetry-collector | grep "receiver_creator"Resolução
Verifique se as permissões RBAC estão definidas corretamente:
bash$kubectl get clusterrole | grep opentelemetry$kubectl describe clusterrole <role-name>Certifique-se de que o coletor tenha permissões para monitorar pods, nós e endpoints
Verifique se a extensão k8s_observer está ativada na configuração
Como verificar
$# Check network policies$kubectl get networkpolicies -n <namespace>$
$# Test connectivity from collector to Elasticsearch$kubectl exec -n newrelic <collector-pod> -- curl http://<es-pod-ip>:9200Resolução
- Verifique se as políticas de rede permitem o tráfego do namespace newrelic para o seu namespace Elasticsearch
- Verifique se os pods do Elasticsearch estão expondo a porta correta (padrão: 9200)
- Certifique-se de que nenhuma regra de firewall bloqueie a comunicação entre pods
Amostra de erro:
permanent error: 403 Forbidden
Resolução
Verifique se o segredo contém a chave de licença correta:
bash$kubectl get secret newrelic-licenses -n newrelic -o jsonpath='{.data.NEWRELIC_LICENSE_KEY}' | base64 -dCertifique-se de que o endpoint OTLP esteja correto para sua região
Verifique se o segredo está montado no pod do coletor:
bash$kubectl describe pod <collector-pod> -n newrelic | grep -A5 "Environment"
Resolução
Verifique se você está usando
mode: daemonset(o modo de implantação não pode acessar os logs do nó)Verifique se as montagens de volume estão configuradas corretamente:
bash$kubectl describe pod <collector-pod> -n newrelic | grep -A10 "Mounts"Verifique se o caminho do receptor filelog corresponde aos logs do seu pod do Elasticsearch:
bash$kubectl exec -n newrelic <collector-pod> -- ls /var/log/pods/*/elasticsearch*/*.logCertifique-se de que o coletor tenha permissões de leitura nos diretórios de log do host
Resolução
Verifique se a variável de ambiente
K8S_CLUSTER_NAMEestá definida no values.yamlVerifique se o processador
resource/clusterestá no pipeline de métricasConsulta para verificar:
FROM Metric SELECT * WHERE metricName LIKE 'elasticsearch.%' LIMIT 1Verifique se o atributo
k8s.cluster.nameestá presente
APM correlation and distributed tracing
These issues apply when you've set up APM correlation with distributed tracing.
Como verificar
FROM Span SELECT count(*) WHERE es.cluster.name = '<elasticsearch-cluster-name>' SINCE 30 minutes agoResolução
- Native OTLP trace export requires Elasticsearch 9.4 or later. Confirm your version with
curl http://localhost:9200. - Verify all three settings are present in
elasticsearch.yml:telemetry.tracing.enabled: true,telemetry.export.endpoint, andtelemetry.tracing.sample_rate. - Confirm the JVM system property
-Dtelemetry.otel.traces.enabled=trueis set (injvm.optionsorES_JAVA_OPTS), then restart Elasticsearch. - The default
telemetry.tracing.sample_rateis0.001(0.1%). Raise it while validating so spans appear quickly.
Resolução
- Confirm the collector has an
otlpreceiver with the gRPC protocol enabled on0.0.0.0:4317, and that the endpoint is reachable from the Elasticsearch nodes. - Confirm a
tracespipeline exists and includes theotlpreceiver and theotlphttpexporter. - Check the collector logs for OTLP receiver or export errors.
Causa
A self-loop appears when Elasticsearch spans reach New Relic that can't be attributed to a calling application. There are two common sources:
Parentless (root) Elasticsearch spans — spans with no parent application span, such as Kubernetes health probes or the Elasticsearch metrics receiver's own scrape calls (
_nodes/stats,_cluster/health, and similar). Because they aren't part of an application's trace, New Relic has no calling service and draws the relationship on the cluster itself.The node's own address — Elasticsearch server spans carry
http.request.headers.host(andserver.address), which New Relic resolves back to the cluster.Resolução
Add both processors to the
tracespipeline, then restart the collector.filter/drop_rootless_esdrops the parentless Elasticsearch spans (application-driven spans always have a parent, so they're kept), andtransform/strip_es_hostremoves the address attributes:processors:filter/drop_rootless_es:error_mode: ignoretraces:span:- 'instrumentation_scope.name == "elasticsearch" and IsRootSpan()'transform/strip_es_host:error_mode: ignoretrace_statements:- context: spanstatements:- delete_key(attributes, "http.request.headers.host") where instrumentation_scope.name == "elasticsearch"- delete_key(attributes, "server.address") where instrumentation_scope.name == "elasticsearch"# traces pipeline: processors: [filter/drop_rootless_es, transform/strip_es_host, batch]Existing self-loops clear on their own once the corrected spans arrive and the previous relationship expires (this can take up to about 75 minutes).
Resolução
- Make sure your applications are instrumented and propagate the W3C
traceparentheader on their Elasticsearch calls. Most modern Elasticsearch clients do this automatically when the application is instrumented with OpenTelemetry. - Open a distributed trace that includes an Elasticsearch call and confirm the application spans and Elasticsearch spans share the same trace.
- Give the relationship a few minutes to build. New Relic re-evaluates entity relationships periodically.
Resolução
- The traces path keys on
es.cluster.name(stamped by Elasticsearch on its spans) and the metrics path onelasticsearch.cluster.name. Theelasticsearchreceiverreportselasticsearch.cluster.nameautomatically from the value Elasticsearch returns, so both derive from the samecluster.nameand resolve to one entity — no extra collector configuration needed. - Don't force the metrics cluster name to a fixed value. If your collector config sets it with a
resourceprocessor (for example aresource/cluster_name_overridethat hardcodes the name), remove that override — otherwise metrics and traces resolve to two different entities and the correlated entity shows no metrics data. - Make sure your Elasticsearch
cluster.nameis unique within your New Relic account so it maps to a single, unambiguous entity.