# Can metricbeat support run command?

**URL:** <https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 15, 2016, 2:20am UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103 "2016-12-15T02:20:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sitanxin](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@sitanxin](https://discuss.elastic.co/u/sitanxin)\
**Post date:** [December 15, 2016, 2:20am UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/1 "2016-12-15T02:20:49Z")

</div>

Hi all,

Is there any way to run small command in the metricbeat?

> fields:  
> os\_version: "`cat /etc/redhat-release`"

But in result, we can see this command did not run. Is there any way we can run it?  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f285dab2cfdc86bf252b60e6e6ba133b9d226463.png)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 15, 2016, 1:40pm UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/2 "2016-12-15T13:40:16Z")

</div>

metricbeat will not run external commands for you. One option is to pass environment variables to metricbeat. e.g.

```auto
    $ OS_VERSION=$(cat /etc/redhat-release) metricbeat ...

```

then you can configure:

```auto
  fields.os_version: ${OS_VERSION:unknown}

```

Optionally without environment variables start metricbeat with:

```auto
    metricbeat -E os.version=$(cat /etc/redhat-release) ... -E os.type=linux -E os.distro=redhat -E os.arch=...

```

then you can configure:

```auto
  fields.os: ${os}

```

This config will get you an event with

```auto
"fields": {
  "os": {
    "type": "linux",
    "distro": "redhat",
    "version": "...",
    "arch": "...",
  }
}

```

Just an idea 😉

---

<div class="post-metadata">

**Author:** ![sitanxin](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@sitanxin](https://discuss.elastic.co/u/sitanxin)\
**Post date:** [December 15, 2016, 4:03pm UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/3 "2016-12-15T16:03:20Z")

</div>

this is a great idea. will test it tomorrow and share result to u.  
but just be quereosity, why not support shell scripty or command? for security concern or performance?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 16, 2016, 7:47am UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/4 "2016-12-16T07:47:19Z")

</div>

One of the main concerns in security but also performance and complexity. If we would just execute any script in the config metricbeat would become a script execution engine...

---

<div class="post-metadata">

**Author:** ![sitanxin](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@sitanxin](https://discuss.elastic.co/u/sitanxin)\
**Post date:** [December 17, 2016, 2:44pm UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/5 "2016-12-17T14:44:52Z")

</div>

verified the 2nd way, it can work as expected. and we use ansible to combind this as well. thanks again for ur detail explains.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2017, 2:45pm UTC](https://discuss.elastic.co/t/can-metricbeat-support-run-command/69103/6 "2017-01-14T14:45:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
