Container Fields

edit

Container fields are used for meta information about the specific container that is the source of information.

These fields help correlate data based containers from any runtime.

Container Field Details

edit
Field Description Level

container.cpu.usage

Percent CPU used which is normalized by the number of CPU cores and it ranges from 0 to 1. Scaling factor: 1000.

type: scaled_float

extended

container.disk.read.bytes

The total number of bytes (gauge) read successfully (aggregated from all disks) since the last metric collection.

type: long

extended

container.disk.write.bytes

The total number of bytes (gauge) written successfully (aggregated from all disks) since the last metric collection.

type: long

extended

container.id

Unique container id.

type: keyword

core

container.image.hash.all

An array of digests of the image the container was built on. Each digest consists of the hash algorithm and value in this format: algorithm:value. Algorithm names should align with the field names in the ECS hash field set.

type: keyword

Note: this field should contain an array of values.

example: [sha256:f8fefc80e3273dc756f288a63945820d6476ad64883892c771b5e2ece6bf1b26]

extended

container.image.name

Name of the image the container was built on.

type: keyword

extended

container.image.tag

Container image tags.

type: keyword

Note: this field should contain an array of values.

extended

container.labels

Image labels.

type: object

extended

container.memory.usage

Memory usage percentage and it ranges from 0 to 1. Scaling factor: 1000.

type: scaled_float

extended

container.name

Container name.

type: keyword

extended

container.network.egress.bytes

The number of bytes (gauge) sent out on all network interfaces by the container since the last metric collection.

type: long

extended

container.network.ingress.bytes

The number of bytes received (gauge) on all network interfaces by the container since the last metric collection.

type: long

extended

container.runtime

Runtime managing this container.

type: keyword

example: docker

extended