# Filebeat Stats and Metrics

**URL:** <https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting, filebeat\
**Created:** [April 9, 2020, 9:34pm UTC](https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408 "2020-04-09T21:34:48Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 9, 2020, 11:16pm UTC](https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408/2 "2020-04-09T23:16:14Z")

</div>

Hello @Emily_Hontoria

I am not a Beat developer so the provided information might not be accurate.

> [@Emily\_Hontoria](#):
>
> What do the "dropped" metrics mean?

I think this post might explain the `dropped` meaning: [Safely publish an event using libbeat - #3 by steffens](https://discuss.elastic.co/t/safely-publish-an-event-using-libbeat/52395/3)

An example of an event dropped in `libbeat` `output` is a document which is malformed (e.g. bad encoding) when being sent to a final destination (e.g. Elasticsearch).  
An example of an event dropped in `libbeat` `pipeline` is a document which is excluded (e.g. [`exclude_lines`](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-log.html#filebeat-input-log-exclude-lines) in `log` input or [`drop_event`](https://www.elastic.co/guide/en/beats/filebeat/current/drop-event.html) processor.

We document those fields:

- In [GoDoc](https://godoc.org/github.com/elastic/beats/libbeat/outputs)
- The exported fields when monitoring Filebeat using Metricbeat Filebeat module ([doc](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-beat.html))

> [@Emily\_Hontoria](#):
>
> What do the "output" and the "pipeline" mean?

I think:

- the output stats are related to the declared output in the configuration (e.g. Beats are able to send to different destinations)
- the pipeline stats are related to the declared processors, filters, conditionals and the internal queue

We document those fields in [GoDoc](https://godoc.org/github.com/elastic/beats/libbeat/publisher/pipeline#Pipeline).

> [@Emily\_Hontoria](#):
>
> What is the difference between a filebeat "event" and a libbeat "event"?

I think the difference is the following:

- a `filebeat` event is an event with specific fields, respecting the `filebeat` definition of event (e.g. a `filebeat` event coming from `syslog tcp` input with its dedicated fields or from a `log` input), built on top of a `libbeat` event
- a `libbeat` event is the common event format shared by all beats. Every event must have a timestamp and provide encodable Fields in `Fields`

* * *

In any case, those metrics are meant to be digested by the Elastic Stack Monitoring tools (see [here](https://www.elastic.co/guide/en/beats/filebeat/current/monitoring.html)).

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-stats-and-metrics/227408)._
