# Event parsing - perf\_data from cmkbeat

**URL:** <https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001>\
**Category:** Logstash\
**Created:** [February 19, 2020, 3:23pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001 "2020-02-19T15:23:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robo/32/38295_2.png) [@Robo](https://discuss.elastic.co/u/Robo)\
**Post date:** [February 19, 2020, 3:23pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/1 "2020-02-19T15:23:57Z")

</div>

Hello,  
We are collecting some server metric using cmkbeat agent.  
The output is available in following format:  
perf\_data: heap=8308.406693;15045.98125;15837.875;;15837.875 nonheap=582.264664;0;0;;0  
perf\_data: generic\_number=4;80;90;;  
perf\_data: sessions=6338;10000;20000;;

The goal is to have following fields extracted from "perf\_data" field:  
metrics.metric\_name: value (e.g. metrics.heap: 8308.406693)  
metrics.metric\_name.warn: warn\_value (e.g. metrics.heap.warn: 15045.98125)  
metrics.metric\_name.crit: crit\_value (e.g. metrics.heap.crit: 15837.875)  
metrics.metric\_name.min: min\_value  
metrics.metric\_name.max: max\_value

Case some value is missing, don't create field.

The main issue is that there are more than 40 different metric types, so my question is if there is any way how to extract field names and values from field "perf\_data" dynamically (simply not to create 40 different grok patterns...)?

Thanks!

---

<div class="post-metadata">

**Author:** ![Robo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robo/32/38295_2.png) [@Robo](https://discuss.elastic.co/u/Robo)\
**Post date:** [February 20, 2020, 8:53am UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/2 "2020-02-20T08:53:02Z")

</div>

another solution might be to use existing metrics field created by cmkbeat and remove the second level field from field name.  
Would that be possible?

data example in json:  
"metrics": {  
"ORA\_PTSNSBS.SYS\_USER\_1\_Tablespace": {  
"size": "104857600",  
"max\_size": "104857600",  
"size\_warn": "94371840",  
"size\_crit": "99614720",  
"used": "1114112"  
}

current state:  
metrics.ORA\_PTSNSBS.SYS\_USER\_1\_Tablespace.max\_size: 104,857,600  
desired state:  
metrics.max\_size: 104,857,600

in general it's possible to "rename" field [metrics][service][metric\_name] to [metrics][metric\_name] for all fields?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2020, 3:12pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/3 "2020-02-20T15:12:51Z")

</div>

> [@Robo](#):
>
> in general it's possible to "rename" field [metrics][service][metric\_name] to [metrics][metric\_name] for all fields?

You could do it in ruby. Something similar (but not the same) as [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2).

---

<div class="post-metadata">

**Author:** ![Robo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robo/32/38295_2.png) [@Robo](https://discuss.elastic.co/u/Robo)\
**Post date:** [February 21, 2020, 12:44pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/4 "2020-02-21T12:44:46Z")

</div>

hi Badger,  
thanks for the hint, I'm not so familiar with ruby 🙂  
I'll try to adapt it and update the topic here.

---

<div class="post-metadata">

**Author:** ![Robo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robo/32/38295_2.png) [@Robo](https://discuss.elastic.co/u/Robo)\
**Post date:** [February 21, 2020, 2:03pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/5 "2020-02-21T14:03:24Z")

</div>

this solved our issues.  
At the end we renamed the original field "metrics" to "cmk\_metrics", because of the fields removal.

```
ruby {
  code => '
    event.get("metrics").each { |k, v|
      event.set("cmk_beat",v)
    }
    event.remove("metrics")
    '
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 2:03pm UTC](https://discuss.elastic.co/t/event-parsing-perf-data-from-cmkbeat/220001/6 "2020-03-20T14:03:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
