- Metricbeat Reference: other versions:
- Metricbeat overview
- Quick start: installation and configuration
- Set up and run
- Upgrade Metricbeat
- How Metricbeat works
- Configure
- Modules
- General settings
- Project paths
- Config file loading
- Output
- Kerberos
- SSL
- Index lifecycle management (ILM)
- Elasticsearch index template
- Kibana endpoint
- Kibana dashboards
- Processors
- Define processors
- add_cloud_metadata
- add_cloudfoundry_metadata
- add_docker_metadata
- add_fields
- add_host_metadata
- add_id
- add_kubernetes_metadata
- add_labels
- add_locale
- add_network_direction
- add_nomad_metadata
- add_observer_metadata
- add_process_metadata
- add_tags
- append
- community_id
- convert
- copy_fields
- decode_base64_field
- decode_duration
- decode_json_fields
- decode_xml
- decode_xml_wineventlog
- decompress_gzip_field
- detect_mime_type
- dissect
- dns
- drop_event
- drop_fields
- extract_array
- fingerprint
- include_fields
- move_fields
- rate_limit
- registered_domain
- rename
- replace
- script
- syslog
- translate_ldap_attribute
- translate_sid
- truncate_fields
- urldecode
- Autodiscover
- Internal queue
- Logging
- HTTP endpoint
- Regular expression support
- Instrumentation
- Feature flags
- metricbeat.reference.yml
- How to guides
- Modules
- ActiveMQ module
- Aerospike module
- Airflow module
- Apache module
- AWS module
- AWS awshealth metricset
- AWS billing metricset
- AWS cloudwatch metricset
- AWS dynamodb metricset
- AWS ebs metricset
- AWS ec2 metricset
- AWS elb metricset
- AWS kinesis metricset
- AWS lambda metricset
- AWS natgateway metricset
- AWS rds metricset
- AWS s3_daily_storage metricset
- AWS s3_request metricset
- AWS sns metricset
- AWS sqs metricset
- AWS transitgateway metricset
- AWS usage metricset
- AWS vpn metricset
- AWS Fargate module
- Azure module
- Azure app_insights metricset
- Azure app_state metricset
- Azure billing metricset
- Azure compute_vm metricset
- Azure compute_vm_scaleset metricset
- Azure container_instance metricset
- Azure container_registry metricset
- Azure container_service metricset
- Azure database_account metricset
- Azure monitor metricset
- Azure storage metricset
- Beat module
- Ceph module
- Ceph cluster_disk metricset
- Ceph cluster_health metricset
- Ceph cluster_status metricset
- Ceph mgr_cluster_disk metricset
- Ceph mgr_cluster_health metricset
- Ceph mgr_osd_perf metricset
- Ceph mgr_osd_pool_stats metricset
- Ceph mgr_osd_tree metricset
- Ceph mgr_pool_disk metricset
- Ceph monitor_health metricset
- Ceph osd_df metricset
- Ceph osd_tree metricset
- Ceph pool_disk metricset
- Cloudfoundry module
- CockroachDB module
- Consul module
- Containerd module
- Coredns module
- Couchbase module
- CouchDB module
- Docker module
- Dropwizard module
- Elasticsearch module
- Elasticsearch ccr metricset
- Elasticsearch cluster_stats metricset
- Elasticsearch enrich metricset
- Elasticsearch index metricset
- Elasticsearch index_recovery metricset
- Elasticsearch index_summary metricset
- Elasticsearch ingest_pipeline metricset
- Elasticsearch ml_job metricset
- Elasticsearch node metricset
- Elasticsearch node_stats metricset
- Elasticsearch pending_tasks metricset
- Elasticsearch shard metricset
- Enterprise Search module
- Envoyproxy module
- Etcd module
- Google Cloud Platform module
- Google Cloud Platform billing metricset
- Google Cloud Platform carbon metricset
- Google Cloud Platform compute metricset
- Google Cloud Platform dataproc metricset
- Google Cloud Platform firestore metricset
- Google Cloud Platform gke metricset
- Google Cloud Platform loadbalancing metricset
- Google Cloud Platform metrics metricset
- Google Cloud Platform pubsub metricset
- Google Cloud Platform storage metricset
- Golang module
- Graphite module
- HAProxy module
- HTTP module
- IBM MQ module
- IIS module
- Istio module
- Jolokia module
- Kafka module
- Kibana module
- Kubernetes module
- Kubernetes apiserver metricset
- Kubernetes container metricset
- Kubernetes controllermanager metricset
- Kubernetes event metricset
- Kubernetes node metricset
- Kubernetes pod metricset
- Kubernetes proxy metricset
- Kubernetes scheduler metricset
- Kubernetes state_container metricset
- Kubernetes state_cronjob metricset
- Kubernetes state_daemonset metricset
- Kubernetes state_deployment metricset
- Kubernetes state_job metricset
- Kubernetes state_node metricset
- Kubernetes state_persistentvolumeclaim metricset
- Kubernetes state_pod metricset
- Kubernetes state_replicaset metricset
- Kubernetes state_resourcequota metricset
- Kubernetes state_service metricset
- Kubernetes state_statefulset metricset
- Kubernetes state_storageclass metricset
- Kubernetes system metricset
- Kubernetes volume metricset
- KVM module
- Linux module
- Logstash module
- Memcached module
- Cisco Meraki module
- MongoDB module
- MSSQL module
- Munin module
- MySQL module
- NATS module
- Nginx module
- Openmetrics module
- Oracle module
- Panw module
- PHP_FPM module
- PostgreSQL module
- Prometheus module
- RabbitMQ module
- Redis module
- Redis Enterprise module
- SQL module
- Stan module
- Statsd module
- SyncGateway module
- System module
- System core metricset
- System cpu metricset
- System diskio metricset
- System entropy metricset
- System filesystem metricset
- System fsstat metricset
- System load metricset
- System memory metricset
- System network metricset
- System network_summary metricset
- System process metricset
- System process_summary metricset
- System raid metricset
- System service metricset
- System socket metricset
- System socket_summary metricset
- System uptime metricset
- System users metricset
- Tomcat module
- Traefik module
- uWSGI module
- vSphere module
- Windows module
- ZooKeeper module
- Exported fields
- ActiveMQ fields
- Aerospike fields
- Airflow fields
- Apache fields
- AWS fields
- AWS Fargate fields
- Azure fields
- Beat fields
- Beat fields
- Ceph fields
- Cloud provider metadata fields
- Cloudfoundry fields
- CockroachDB fields
- Common fields
- Consul fields
- Containerd fields
- Coredns fields
- Couchbase fields
- CouchDB fields
- Docker fields
- Docker fields
- Dropwizard fields
- ECS fields
- Elasticsearch fields
- Enterprise Search fields
- Envoyproxy fields
- Etcd fields
- Google Cloud Platform fields
- Golang fields
- Graphite fields
- HAProxy fields
- Host fields
- HTTP fields
- IBM MQ fields
- IIS fields
- Istio fields
- Jolokia fields
- Jolokia Discovery autodiscover provider fields
- Kafka fields
- Kibana fields
- Kubernetes fields
- Kubernetes fields
- KVM fields
- Linux fields
- Logstash fields
- Memcached fields
- MongoDB fields
- MSSQL fields
- Munin fields
- MySQL fields
- NATS fields
- Nginx fields
- Openmetrics fields
- Oracle fields
- Panw fields
- PHP_FPM fields
- PostgreSQL fields
- Process fields
- Prometheus fields
- Prometheus typed metrics fields
- RabbitMQ fields
- Redis fields
- Redis Enterprise fields
- SQL fields
- Stan fields
- Statsd fields
- SyncGateway fields
- System fields
- Tomcat fields
- Traefik fields
- uWSGI fields
- vSphere fields
- Windows fields
- ZooKeeper fields
- Monitor
- Secure
- Troubleshoot
- Get help
- Debug
- Understand logged metrics
- Common problems
- "open /compat/linux/proc: no such file or directory" error on FreeBSD
- Metricbeat collects system metrics for interfaces you didn’t configure
- Metricbeat uses too much bandwidth
- Error loading config file
- Found unexpected or unknown characters
- Logstash connection doesn’t work
- Publishing to Logstash fails with "connection reset by peer" message
- @metadata is missing in Logstash
- Not sure whether to use Logstash or Beats
- SSL client fails to connect to Logstash
- Monitoring UI shows fewer Beats than expected
- Dashboard could not locate the index-pattern
- High RSS memory usage due to MADV settings
- Contribute to Beats
Enterprise Search module
enterprisesearch
contains metrics and health information for Enterprise Search
-
enterprisesearch.cluster_uuid
-
Cluster UUID for the Elasticsearch cluster used as the data store for Enterprise Search.
type: keyword
Enterprise Search health
-
enterprisesearch.health.name
-
Host name for the Enterprise Search node
type: keyword
Enterprise Search version information
-
enterprisesearch.health.version.number
-
Enterprise Search version number using the semantic versioning format
type: keyword
-
enterprisesearch.health.version.build_hash
-
A unique build hash for the Enterprise Search package
type: keyword
Enterprise Search process information
-
enterprisesearch.health.process.pid
-
Process ID for the Enterprise Search instance
type: long
-
enterprisesearch.health.process.uptime.sec
-
Process uptime for the Enterprise Search instance
type: long
Health information for the embedded Filebeat instance
-
enterprisesearch.health.process.filebeat.pid
-
Process ID for the embedded Filebeat instance
type: long
-
enterprisesearch.health.process.filebeat.restart_count
-
Number of times embedded Filebeat instance had to be restarted due to some issues
type: long
-
enterprisesearch.health.process.filebeat.time_since_last_restart.sec
-
Time since the last embedded Filebeat instance restart (-1 if never restarted)
type: long
JVM health
-
enterprisesearch.health.jvm.version
-
JVM version used to run Enterprise Search
type: keyword
Java garbage collection metrics
-
enterprisesearch.health.jvm.gc.collection_count
-
Total number of Java garbage collector invocations since the start of the process
type: long
-
enterprisesearch.health.jvm.gc.collection_time.ms
-
Total time spent running Java garbage collector since the start of the process
type: long
Memory usage
-
enterprisesearch.health.jvm.memory_usage.heap_init.bytes
-
Heap init used by the JVM in bytes.
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.heap_used.bytes
-
Heap used by the JVM in bytes.
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.heap_committed.bytes
-
Committed heap to the JVM in bytes.
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.heap_max.bytes
-
Max heap used by the JVM in bytes
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.non_heap_init.bytes
-
Non-Heap initial memory used by the JVM in bytes.
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.non_heap_committed.bytes
-
Non-Heap committed memory used by the JVM in bytes.
type: long
format: bytes
-
enterprisesearch.health.jvm.memory_usage.object_pending_finalization_count
-
Displays the approximate number of objects for which finalization is pending.
type: long
Threads information
-
enterprisesearch.health.jvm.threads.current
-
Current number of live threads.
type: long
-
enterprisesearch.health.jvm.threads.daemon
-
Current number of live daemon threads.
type: long
-
enterprisesearch.health.jvm.threads.max
-
Peak live thread count since the JVM started or the peak was reset.
type: long
-
enterprisesearch.health.jvm.threads.total_started
-
Total number of threads created and/or started since the JVM started.
type: long
Crawler health
Crawler workers
-
enterprisesearch.health.crawler.workers.pool_size
-
Workers pool size.
type: long
-
enterprisesearch.health.crawler.workers.active
-
Number of active workers.
type: long
-
enterprisesearch.health.crawler.workers.available
-
Number of available workers.
type: long
Enterprise Search stats.
Workplace Search connectors subsystem stats.
Workplace Search connectors job store stats.
-
enterprisesearch.stats.connectors.job_store.waiting
-
Number of connectors jobs waiting to be processed.
type: long
-
enterprisesearch.stats.connectors.job_store.working
-
Number of connectors jobs currently being processed.
type: long
Breakdown of connectors jobs by types.
-
enterprisesearch.stats.connectors.job_store.job_types.delete
-
Number of delete jobs in the jobs store.
type: long
-
enterprisesearch.stats.connectors.job_store.job_types.full
-
Number of full sync jobs in the jobs store.
type: long
-
enterprisesearch.stats.connectors.job_store.job_types.incremental
-
Number of incremental sync jobs in the jobs store.
type: long
-
enterprisesearch.stats.connectors.job_store.job_types.permissions
-
Number of permissions sync jobs in the jobs store.
type: long
Workplace Search worker pools stats.
Status information for the extractor workers pool.
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.size
-
Worker pool size.
type: long
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.busy
-
Number of busy workers.
type: long
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.queue_depth
-
Number of items waiting to be processed.
type: long
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.idle
-
Number of idle workers.
type: long
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.total_completed
-
Number of jobs completed since the start.
type: long
-
enterprisesearch.stats.connectors.pool.extract_worker_pool.total_scheduled
-
Number of jobs scheduled since the start.
type: long
Status information for the sub-extractor workers pool.
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.size
-
Worker pool size.
type: long
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.busy
-
Number of busy workers.
type: long
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.queue_depth
-
Number of items waiting to be processed.
type: long
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.idle
-
Number of idle workers.
type: long
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.total_completed
-
Number of jobs completed since the start.
type: long
-
enterprisesearch.stats.connectors.pool.subextract_worker_pool.total_scheduled
-
Number of jobs scheduled since the start.
type: long
Status information for the publish workers pool.
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.size
-
Worker pool size.
type: long
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.busy
-
Number of busy workers.
type: long
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.queue_depth
-
Number of items waiting to be processed.
type: long
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.idle
-
Number of idle workers.
type: long
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.total_completed
-
Number of jobs completed since the start.
type: long
-
enterprisesearch.stats.connectors.pool.publish_worker_pool.total_scheduled
-
Number of jobs scheduled since the start.
type: long
Incoming HTTP request metrics.
Incoming HTTP connection statistics.
-
enterprisesearch.stats.http.connections.current
-
Current number of HTTP connections opened to the Enterprise Search instance.
type: long
-
enterprisesearch.stats.http.connections.max
-
Maximum number of concurrent HTTP connections open to the Enterprise Search instance since the start.
type: long
-
enterprisesearch.stats.http.connections.total
-
Total number of HTTP connections opened to the Enterprise Search instance since the start.
type: long
Network traffic metrics.
-
enterprisesearch.stats.http.network.received.bytes
-
Total number of bytes received by the Enterprise Search instance since the start.
type: long
format: bytes
-
enterprisesearch.stats.http.network.sent.bytes
-
Total number of bytes sent by the Enterprise Search instance since the start.
type: long
format: bytes
-
enterprisesearch.stats.http.network.received.bytes_per_sec
-
Average number of bytes received by the Enterprise Search instance per second since the start.
type: long
format: bytes
-
enterprisesearch.stats.http.network.sent.bytes_per_sec
-
Average number of bytes sent by the Enterprise Search instance per second since the start.
type: long
format: bytes
Aggregate HTTP request duration statistics.
-
enterprisesearch.stats.http.request_duration.max.ms
-
Longest HTTP connection duration since the start of the instance.
type: long
-
enterprisesearch.stats.http.request_duration.mean.ms
-
Average HTTP connection duration since the start of the instance.
type: long
-
enterprisesearch.stats.http.request_duration.std_dev.ms
-
Standard deviation for HTTP connection duration values since the start of the instance.
type: long
Aggregate HTTP response counts broken down by HTTP status type.
-
enterprisesearch.stats.http.responses.1xx
-
Total number of HTTP requests finished with a 1xx response code since the start of the instance.
type: long
-
enterprisesearch.stats.http.responses.2xx
-
Total number of HTTP requests finished with a 2xx response code since the start of the instance.
type: long
-
enterprisesearch.stats.http.responses.3xx
-
Total number of HTTP requests finished with a 3xx response code since the start of the instance.
type: long
-
enterprisesearch.stats.http.responses.4xx
-
Total number of HTTP requests finished with a 4xx response code since the start of the instance.
type: long
-
enterprisesearch.stats.http.responses.5xx
-
Total number of HTTP requests finished with a 5xx response code since the start of the instance.
type: long
Aggregate stats on the functioning of the background jobs processing pipeline within Enterprise Search.
-
enterprisesearch.stats.queues.engine_destroyer.count
-
Total number of jobs processed via the engine_destroyer queue since the start of the instance.
type: long
-
enterprisesearch.stats.queues.mailer.count
-
Total number of jobs processed via the mailer queue since the start of the instance.
type: long
-
enterprisesearch.stats.queues.process_crawl.count
-
Total number of jobs processed via the process_crawl queue since the start of the instance.
type: long
-
enterprisesearch.stats.queues.failed.count
-
Total number of jobs waiting in the failed queue.
type: long
Aggregate stats on the functioning of the crawler subsystem within Enterprise Search.
Global deployment-wide metrics for the crawler.
Crawl request summary for the deployment.
-
enterprisesearch.stats.crawler.global.crawl_requests.pending
-
Total number of crawl requests waiting to be processed.
type: long
-
enterprisesearch.stats.crawler.global.crawl_requests.active
-
Total number of crawl requests currently being processed (running crawls).
type: long
-
enterprisesearch.stats.crawler.global.crawl_requests.successful
-
Total number of crawl requests that have succeeded.
type: long
-
enterprisesearch.stats.crawler.global.crawl_requests.failed
-
Total number of failed crawl requests.
type: long
Node-level statistics for the crawler.
-
enterprisesearch.stats.crawler.node.pages_visited
-
Total number of pages visited by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.urls_allowed
-
Total number of URLs allowed by the crawler during discovery since the instance start.
type: long
Total number of URLs denied by the crawler during discovery since the instance start, broken down by deny reason.
-
enterprisesearch.stats.crawler.node.urls_denied.already_seen
-
Total number of URLs not followed because of URL de-duplication (each URL is visited only once).
type: long
-
enterprisesearch.stats.crawler.node.urls_denied.domain_filter_denied
-
Total number of URLs denied because of an unknown domain.
type: long
-
enterprisesearch.stats.crawler.node.urls_denied.incorrect_protocol
-
Total number of URLs with incorrect/invalid/unsupported protocols.
type: long
-
enterprisesearch.stats.crawler.node.urls_denied.link_too_deep
-
Total number of URLs not followed due to crawl depth limits.
type: long
-
enterprisesearch.stats.crawler.node.urls_denied.nofollow
-
Total number of URLs denied due to a nofollow meta tag or an HTML link attribute.
type: long
-
enterprisesearch.stats.crawler.node.urls_denied.unsupported_content_type
-
Total number of URLs denied due to an unsupported content type.
type: long
HTTP request result counts, by status code.
-
enterprisesearch.stats.crawler.node.status_codes.200
-
Total number of HTTP 200 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.301
-
Total number of HTTP 301 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.302
-
Total number of HTTP 302 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.400
-
Total number of HTTP 400 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.401
-
Total number of HTTP 401 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.402
-
Total number of HTTP 402 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.403
-
Total number of HTTP 403 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.404
-
Total number of HTTP 404 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.405
-
Total number of HTTP 405 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.410
-
Total number of HTTP 410 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.422
-
Total number of HTTP 422 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.429
-
Total number of HTTP 429 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.500
-
Total number of HTTP 500 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.501
-
Total number of HTTP 501 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.502
-
Total number of HTTP 502 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.503
-
Total number of HTTP 503 responses seen by the crawler since the instance start.
type: long
-
enterprisesearch.stats.crawler.node.status_codes.504
-
Total number of HTTP 504 responses seen by the crawler since the instance start.
type: long
Total current URL queue size for the instance.
-
enterprisesearch.stats.crawler.node.queue_size.primary
-
Total number of URLs waiting to be crawled by the instance.
type: long
-
enterprisesearch.stats.crawler.node.queue_size.purge
-
Total number of URLs waiting to be checked by the purge crawl phase.
type: long
-
enterprisesearch.stats.crawler.node.active_threads
-
Total number of crawler worker threads currently active on the instance.
type: long
Crawler workers information for the instance.
-
enterprisesearch.stats.crawler.node.workers.pool_size
-
Total size of the crawl workers pool (number of concurrent crawls possible) for the instance.
type: long
-
enterprisesearch.stats.crawler.node.workers.active
-
Total number of currently active crawl workers (running crawls) for the instance.
type: long
-
enterprisesearch.stats.crawler.node.workers.available
-
Total number of currently available (free) crawl workers for the instance.
type: long
Aggregate product usage statistics for the Enterprise Search deployment.
App Search product usage statistics.
-
enterprisesearch.stats.product_usage.app_search.total_engines
-
Current number of App Search engines within the deployment.
type: long
Workplace Search product usage statistics.
-
enterprisesearch.stats.product_usage.workplace_search.total_org_sources
-
Current number of Workplace Search org-wide content sources within the deployment.
type: long
-
enterprisesearch.stats.product_usage.workplace_search.total_private_sources
-
Current number of Workplace Search private content sources within the deployment.
type: long
On this page
- enterprisesearch
- health
- version
- process
- filebeat
- jvm
- gc
- memory_usage
- threads
- crawler
- workers
- stats
- connectors
- job_store
- job_types
- pool
- extract_worker_pool
- subextract_worker_pool
- publish_worker_pool
- http
- connections
- network
- request_duration
- responses
- queues
- crawler
- global
- crawl_requests
- node
- urls_denied
- status_codes
- queue_size
- workers
- product_usage
- app_search
- workplace_search