# 👀 Host.network.ingress.bytes looks broken

**URL:** <https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696>\
**Category:** Beats\
**Tags:** docker, metricbeat\
**Created:** [October 15, 2022, 7:54pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696 "2022-10-15T19:54:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [October 15, 2022, 7:54pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/1 "2022-10-15T19:54:51Z")

</div>

Hi! I have a Docker Swarm cluster with 4 nodes and Metricbeat installed on every node as a global service.

According to docs:

> **`host.network.ingress.bytes`**  
> The number of bytes received (gauge) on all network interfaces by the host since the last metric collection.

But in my case, this field always has almost the same values as before even if I start downloading or uploading big files (5Gb) at a high speed in one of the containers of the cluster (traffic goes through the host to the global network).

I have created visualization for the network speed and it also near the same:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce491253457ec62fa297487f6379f35df0c9f3f7.jpeg)

Is this some misconfiguration? How can I show the real network in and out speed?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2022, 8:10pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/2 "2022-10-15T20:10:38Z")

</div>

Hi @Its_Anton I am thinking that field is a counter so perhaps try counter\_rate and then normalize by the units per minute or second.

Take a look at that. See if that makes sense.

Also, be careful what you're breaking that down by.

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [October 15, 2022, 8:31pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/3 "2022-10-15T20:31:30Z")

</div>

Hi, @stephenb!  
Thanks for the reply.

If it would be a counter, it would increase over time, especially when I start downloading big files. But that doesn't happen.

BTW other counter fields, like **`docker.network.inbound.bytes`** work as expected, they start increase over time when I start downloading/uploading.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2022, 8:43pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/4 "2022-10-15T20:43:38Z")

</div>

Try the network fields I know those work.

> **[System fields | Metricbeat Reference \[8.4\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-system.html#_network_10)**

`system.network.out.bytes`  
`system.network.in.bytes`

Be careful because that's also per network interface if I remember

If I get a chance I'll look at the host fields later.

Yeah it says it's a host fields are per period ... Interesting

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2022, 10:17pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/5 "2022-10-15T22:17:57Z")

</div>

Ok I checked and I see equal...

In Lens

`counter_rate(max(system.network.in.bytes), kql='')`  
normalized per second  
Format Bytes

and

`average(host.network.ingress.bytes)/median(metricset.period)*1000`  
not Normalized  
Format Bytes

Tracking / Same... very minor differences probably how they are collected.

 ![Screen Shot 2022-10-15 at 3.17.19 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b053bddf24cee5771de5edb1aabf5bf0d8a94a1.png)

 ![Screen Shot 2022-10-15 at 3.17.31 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72b282394f37942a4dfc80154e1ac9f6c3d1d5ce.png)

 ![Screen Shot 2022-10-15 at 3.15.33 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cfce93804d4ee7e7cf3d173952109c56c0be603f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2022, 12:18am UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696/6 "2022-11-13T00:18:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
