# DSL Query For CPU Load (MetricBeat Data)

**URL:** <https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917>\
**Category:** Elasticsearch\
**Created:** [January 9, 2017, 5:49am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917 "2017-01-09T05:49:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 9, 2017, 5:49am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/1 "2017-01-09T05:49:18Z")

</div>

Hi-  
Am trying to create a DSL query to fetch the CPU load of a server from my Elastic search engine.  
Could someone please help me in creating a query for this.

PS: I will execute this query using the Elasticsearch gem in the API level (with out logging to the Kibana).

Thanks in advance for your help.

Regards,  
Prakash

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 9, 2017, 6:35am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/2 "2017-01-09T06:35:03Z")

</div>

What do you have so far?

---

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 9, 2017, 6:40am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/3 "2017-01-09T06:40:09Z")

</div>

Thanks for your reply, @warkolm.

This is what I could write it so far:

> GET metricbeat-2017.01.09/metricsets/\_search?q=cpu  
> {  
> "size":1  
> }

This is the response, I've got:

> {  
> "took": 1,  
> "timed\_out": false,  
> "\_shards": {  
> "total": 5,  
> "successful": 5,  
> "failed": 0  
> },  
> "hits": {  
> "total": 184,  
> "max\_score": 5.304149,  
> "hits": [  
> {  
> "\_index": "metricbeat-2017.01.09",  
> "\_type": "metricsets",  
> "\_id": "AVmBoCrbVRlweE2aySFN",  
> "\_score": 5.304149,  
> "\_source": {  
> "@timestamp": "2017-01-09T05:07:54.525Z",  
> "beat": {  
> "hostname": "AAEINBLR03199L",  
> "name": "AAEINBLR03199L",  
> "version": "5.1.1"  
> },  
> "metricset": {  
> "module": "system",  
> "name": "cpu",  
> "rtt": 0  
> },  
> "system": {  
> "cpu": {  
> "idle": {  
> **"pct": 0.9062**  
> },  
> "iowait": {  
> "pct": 0  
> },  
> "irq": {  
> "pct": 0  
> },  
> "nice": {  
> "pct": 0  
> },  
> "softirq": {  
> "pct": 0  
> },  
> "steal": {  
> "pct": 0  
> },  
> "system": {  
> **"pct": 0.0362**  
> },  
> "user": {  
> **"pct": 0.0576**  
> }  
> }  
> },  
> "type": "metricsets"  
> }  
> }  
> ]  
> }  
> }

I just have a couple of questions:

-\> Is my query got the latest record from Elastic Search engine?  
-\> How do I navigate it to the lower nodes like the highlighted above in the query itself.

Please correct me, if am wrong anywhere.

Thanks !

---

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 12, 2017, 4:42am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/4 "2017-01-12T04:42:52Z")

</div>

Hi @warkolm-  
Could you please help me out here. Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2017, 5:36am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/5 "2017-01-12T05:36:25Z")

</div>

> [@prakash1243](#):
>
> -\> Is my query got the latest record from Elastic Search engine?

I don't know, you'd have to query and compare? It might be easiest to just take something from the last 5 seconds and live with the delay.

> [@prakash1243](#):
>
> -\> How do I navigate it to the lower nodes like the highlighted above in the query itself.

Navigate? In the response?

---

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 12, 2017, 5:54am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/6 "2017-01-12T05:54:04Z")

</div>

Yes @warkolm , Navigate in the Response.

Could you please let me know, how do I execute this query in the Ruby Client.

GET metricbeat-2017.01.09/metricsets/\_search?q=cpu  
{  
"size":1  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2017, 6:36am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/7 "2017-01-12T06:36:15Z")

</div>

> [@prakash1243](#):
>
> Yes @warkolm , Navigate in the Response.

I don't know what that means.

---

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 18, 2017, 6:20am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/8 "2017-01-18T06:20:31Z")

</div>

Hi @warkolm:

I have this query :

GET /\_search  
{  
"query": {  
"dis\_max": {  
"queries": [  
{ "match": { "index": "metricbeat-2017.01.18" }},  
{ "match": { "type": "metricsets" }},  
{ "match": { "beat.hostname": "HPPP-140-01" }}  
]  
}

}  
}

When I execute this, I get the below output:

{  
"\_index": "metricbeat-2017.01.16",  
"\_type": "metricsets",  
"\_id": "AVmkYc7mU2H8SwTt6SMr",  
"\_score": 0.000011355958,  
"\_source": {  
"@timestamp": "2017-01-16T00:00:06.089Z",  
"beat": {  
"hostname": "HPPP-140-01",  
"name": "HPPP-140-01",  
"version": "5.1.1"  
},  
"metricset": {  
"module": "system",  
"name": "cpu",  
"rtt": 0  
},  
"system": {  
"cpu": {  
"idle": {  
"pct": 0.9547  
},  
"iowait": {  
"pct": 0  
},  
"irq": {  
"pct": 0  
},  
"nice": {  
"pct": 0  
},  
"softirq": {  
"pct": 0  
},  
"steal": {  
"pct": 0  
},  
"system": {  
"pct": 0.0101  
},  
"user": {  
"pct": 0.0352  
}  
}  
},

I'd like to how how do I get the system.cpu.idle.pct value from the above output. Please let me know if am unclear.

And how do I get the content in a field at the DSL level. Please let me know. Thanks !

---

<div class="post-metadata">

**Author:** ![prakash1243](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Post date:** [January 20, 2017, 5:35am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/9 "2017-01-20T05:35:36Z")

</div>

Hi @warkolm:

Could you please let me know, if am still unclear. Thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2017, 5:35am UTC](https://discuss.elastic.co/t/dsl-query-for-cpu-load-metricbeat-data/70917/10 "2017-02-17T05:35:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
