# 32-BIT Metricbeat (7.8.0) return abnormal value for system.network.in.bytes

**URL:** <https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 5, 2020, 8:17am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369 "2020-11-05T08:17:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Razby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/razby/32/127582_2.png) [@Razby](https://discuss.elastic.co/u/Razby)\
**Post date:** [November 5, 2020, 8:17am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/1 "2020-11-05T08:17:49Z")

</div>

Hi,

32-BIT Metricbeat (7.8.0) return abnormal high value for system.network.in.bytes such as "6,424,932,420,939,677,696". 😟  
With 64-BIT version I got acceptable value such as "3,652,142,427"

I really don’t know what is the reason for such a difference? 🤔

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c7af7b83263ff6d4f461eccd0d49177fa177e9c7.png)

Regards,  
Tadej

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 5, 2020, 7:05pm UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/2 "2020-11-05T19:05:54Z")

</div>

Hey @Razby,

Would it be possible that these machines have a lot of network traffic?  
These values are directly taken from the network counters available in `/proc/net/dev`, could you compare with the values there in your machines?

---

<div class="post-metadata">

**Author:** ![Razby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/razby/32/127582_2.png) [@Razby](https://discuss.elastic.co/u/Razby)\
**Post date:** [November 6, 2020, 7:49am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/3 "2020-11-06T07:49:37Z")

</div>

Hi @jsoriano,

This machine hasn't a lot network traffic.  
I checked the same counter directly in Performance Monitor but there are correct numbers.  
There seems to be something wrong with processing in the metricbeat.

metricbeat.log/Kibana

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/2/a27ac5381ec111e204b5e8a09325ed3c0db4551f.png)

Perf monitor

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55a2c9ad1a44ce5fcfd06d76d9d977e0b10230a8.png)

Regards,  
@Razby

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 6, 2020, 10:23am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/4 "2020-11-06T10:23:28Z")

</div>

Oh this is Windows, then don't look for `/proc` 🙂

In any case take into account that the value that metricbeat is reporting, is a cumulative counter of bytes since the machine started. The value you see in the Performance Monitor is probably in bytes/sec, i.e. a rate calculated from the original counter. You can get an equivalent metric using the derivative aggregation in a time series visual builder visualization.

There are more details about these aggregations, on this blogposts:

- How to visualize these metrics using Kibana: [https://www.elastic.co/blog/visualizing-observability-with-kibana-event-rates-and-rate-of-change-in-tsvb](https://www.elastic.co/blog/visualizing-observability-with-kibana-event-rates-and-rate-of-change-in-tsvb)
- How to query this data using the API: [https://www.elastic.co/blog/querying-and-aggregating-time-series-data-in-elasticsearch](https://www.elastic.co/blog/querying-and-aggregating-time-series-data-in-elasticsearch)

If the derivative values still don't make any sense, then this could be a bug. What version of Windows is this one?  
I see there is some code to handle 32-bit versions in the library used by Metricbeat to get these metrics: [https://github.com/shirou/gopsutil/blob/fc7e5e7af6052e36e83e5539148015ed2c09d8f9/net/net\_windows.go#L170](https://github.com/shirou/gopsutil/blob/fc7e5e7af6052e36e83e5539148015ed2c09d8f9/net/net_windows.go#L170)

---

<div class="post-metadata">

**Author:** ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)\
**Post date:** [November 16, 2020, 10:00am UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/5 "2020-11-16T10:00:35Z")

</div>

@Razby, from the lines @jsoriano referenced you can see we are calling a different win 32 api for the 32 bit machines, this returns `DWORD`(uint32) values instead of `ULONG64` (for 64 bit machines) but we are handling them in the same manner. This is most likely where the issue comes, can you open a github ticket in the beats repo ([https://github.com/elastic/beats](https://github.com/elastic/beats)) so we can follow up on that?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 12:00pm UTC](https://discuss.elastic.co/t/32-bit-metricbeat-7-8-0-return-abnormal-value-for-system-network-in-bytes/254369/6 "2020-12-14T12:00:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
