# Ecs metrics

**URL:** <https://discuss.elastic.co/t/ecs-metrics/371727>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 9, 2024, 9:31pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727 "2024-12-09T21:31:29Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 9, 2024, 9:31pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/1 "2024-12-09T21:31:29Z")

</div>

I have a metricbeat running on one place which is generating following metrics  
**`host.network.ingress.bytes`**

but at different place (same version metricbeat) but different elastic cluster is not producting this metric. How do I enable this.

I read that it is ECS metrics

> **[ECS fields | Metricbeat Reference \[8.16\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-ecs.html)**

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 10, 2024, 1:24am UTC](https://discuss.elastic.co/t/ecs-metrics/371727/2 "2024-12-10T01:24:21Z")

</div>

`system` module  
`network` metircset

> **[System network metricset | Metricbeat Reference \[8.16\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-metricset-system-network.html)**

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 10, 2024, 9:19pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/3 "2024-12-10T21:19:16Z")

</div>

hmm, I already have that enable. I will try getting one container for testing to see what is happening.

```auto
- module: system
  period: 1m
  metricsets:
    - cpu
    - load
    - memory
    - network
    - process_summary
    - process

```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 10, 2024, 9:36pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/4 "2024-12-10T21:36:30Z")

</div>

does this matric works only for container?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 11, 2024, 1:43am UTC](https://discuss.elastic.co/t/ecs-metrics/371727/5 "2024-12-11T01:43:59Z")

</div>

I would say opposite I would expect to when metricbeat is run directly on a host or full vm... But perhaps not in a thin container

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 11, 2024, 3:02am UTC](https://discuss.elastic.co/t/ecs-metrics/371727/6 "2024-12-11T03:02:43Z")

</div>

This might not be related to your issue but just as a heads up -- I took a brief look at the code and it might be the case that the very first network metric emitted from the system network metrics excludes the `host.network.*` fields. When a minute passes and the second network metricset is emitted it should contain the `host.network.*` fields.

The Operating System reports these values as counters that always increase but the host metricset reports deltas so we have to wait to see 2 values before we can calculate and report a delta.

Can you share the metricbeat config as well as example network documents from each cluster?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 11, 2024, 8:55pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/7 "2024-12-11T20:55:07Z")

</div>

in my test, I am receiving host.disk.write.bytes and host.disk.read.bytes. but not getting network. (using v8.5.3 for testing)

both config are identical. most probably the way both container has deploy or how they running metricbeat. I have contacted our local system admin guys to find out what are the difference between two deployment. where I get data from one but not from other.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 11, 2024, 9:31pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/8 "2024-12-11T21:31:02Z")

</div>

@elasticforme

Corrected Below.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 11, 2024, 9:54pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/9 "2024-12-11T21:54:12Z")

</div>

I see the host.network.\* fields in a document on my Mac running macOS 14.6.1 (23G93)

Metricbeat.yml

```auto
metricbeat.config.modules:
  path: ${path.config}/modules.d/*.yml

  reload.enabled: false

output.console:
  pretty: true

```

System.yml:

```auto
- module: system
  period: 10s
  metricsets:
    - network

```

Will print a document for each interface and a summary document with the host.network.\* fields:

```auto
./metricbeat
....
{
  "@timestamp": "2024-12-11T21:52:33.659Z",
  "@metadata": {
    "beat": "metricbeat",
    "type": "_doc",
    "version": "8.16.1"
  },
  "event": {
    "module": "system",
    "duration": 17273208,
    "dataset": "system.network"
  },
  "metricset": {
    "period": 10000,
    "name": "network"
  },
  "service": {
    "type": "system"
  },
  "host": {
    "name": "billeastons-MBP.ad.weaston.org",
    "network": {
      "ingress": {
        "bytes": 5479,
        "packets": 40
      },
      "egress": {
        "packets": 210,
        "bytes": 87902
      }
    }
  },
  "ecs": {
    "version": "8.0.0"
  },
  "agent": {
    "type": "metricbeat",
    "version": "8.16.1",
    "ephemeral_id": "cd61d6fb-25c6-4263-8130-78e3d7c750f1",
    "id": "368def15-35c4-4d4e-834e-7e9879a6b653",
    "name": "billeastons-MBP.ad.weaston.org"
  }
}

```

Metricbeat creates it so that the infrastructure UI in the observability solution can consistently show network data without having to rely on rate counters and without having to handle rollover of counters. I don't believe it's platform-specific.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 11, 2024, 10:05pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/10 "2024-12-11T22:05:42Z")

</div>

Yup I see it now on my normal linux host... and my mac.

What makes it a bit odd... it is not in the exported field list for `system` module

> **[System fields | Metricbeat Reference \[8.16\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-system.html)**

It is only in the ECS fields.

> **[ECS fields | Metricbeat Reference \[8.16\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-ecs.html)**

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 17, 2024, 4:14pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/11 "2024-12-17T16:14:22Z")

</div>

this is so weird. I am running all kind of different test but I don't get host.network.ingress

I do get host.disk.read.bytes means metricbeat is sending ECS stuff. but not network related data.

I am testing this by running logstash from command line and putting out put on screen.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 17, 2024, 5:52pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/12 "2024-12-17T17:52:32Z")

</div>

I got my hand on metricbeat side, turn on debugging and got this

`{"log.level":"debug","@timestamp":"2024-12-17T10:57:19.768-0600","log.logger":"publisher","log.origin":{"file.name":"pipeline/client.go","file.line":226},"message":"Pipeline client receives callback 'onFilteredOut' for event: {Timestamp:2024-12-17 10:57:19.767232381 -0600 CST m=+60.264540632 Meta:null Fields:{\"event\":{\"dataset\":\"system.network\",\"duration\":305362,\"module\":\"system\"},\"host\":{\"network\":{\"egress\":{\"bytes\":1084701432,\"packets\":183003},\"ingress\":{\"bytes\":2304547302,\"packets\":216275}}},\"metricset\":{\"name\":\"network\",\"period\":60000},\"service\":{\"type\":\"system\"}} Private:<nil> TimeSeries:true}","service.name":"metricbeat","ecs.version":"1.6.0"}`

ecs.version:1.6.0. is this correct version?

I am still not getting this metric at logstash though

metricbeat is version 8.5.3

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 17, 2024, 7:55pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/13 "2024-12-17T19:55:57Z")

</div>

How have you determined that this metric is not available in Logstash

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 17, 2024, 8:59pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/14 "2024-12-17T20:59:13Z")

</div>

> [@elasticforme](#):
>
> receives callback 'onFilteredOut'

@strawgate

What causes that...

> <https://github.com/elastic/beats/pull/9016>
>
> To allow easier debugging when events are not sent by the output we
> have added …a few log statements at debug level for the onFilteredOut and
> the onDroppedOnPublish events.

> <https://github.com/elastic/beats/blob/d11501413d6353ecd9112a478b0b0e2fec4fcd6d/libbeat/publisher/pipeline/client.go#L108>

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 17, 2024, 9:18pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/15 "2024-12-17T21:18:11Z")

</div>

finally it is working. I have no access to container where metricbeat running hence it is hard to tell you what they did. But as I suspect they was using some old library and or configuration. I had to debug on logstash/elastic side and due to all these post I was confident on telling them that there is something not correct on metricbeat side.

Now I get all metric and ecs version is correct as well

```auto
 "ecs" => {
        "version" => "8.0.0"

```

```auto
"host" => {
           "name" => "host1",
        "network" => {
            "ingress" => {
                  "bytes" => 12066198482,
                "packets" => 862634
            },
             "egress" => {
                  "bytes" => 64507225,
                "packets" => 837701
            }
        }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 17, 2024, 9:20pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/16 "2024-12-17T21:20:03Z")

</div>

@elasticforme

What changed? What Config? Was it on the Metricbeat side?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 17, 2024, 9:22pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/17 "2024-12-17T21:22:08Z")

</div>

yes on metricbeat side they just said they was using old config.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 17, 2024, 10:41pm UTC](https://discuss.elastic.co/t/ecs-metrics/371727/18 "2024-12-17T22:41:39Z")

</div>

I ask for more specific. basically someone has started metricbeat on host system. they shut that down and kept only on VM. it was causing issue with it.
