# How does Metricbeat define "Used Memory"?

**URL:** <https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 12, 2016, 10:38pm UTC](https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786 "2016-12-12T22:38:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![coder-98103](https://avatars.discourse-cdn.com/v4/letter/c/22d042/32.png) [@coder-98103](https://discuss.elastic.co/u/coder-98103)\
**Post date:** [December 12, 2016, 10:38pm UTC](https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786/1 "2016-12-12T22:38:49Z")

</div>

I am considering using Metricbeat to track my server capacity, but I'm confused by the memory reports.

My test server has this output:

```
root@sandbox:/etc/metricbeat# free -m
              total used free shared buff/cache available
Mem: 3947 1599 1508 6 840 2095
Swap: 765 0 765

```

Metricbeat shows my "Used Memory" as "2.364GB" I can't figure out where that number is coming from. It doesn't seem to correspond to anything reported by the "free" command.

What I'm interested in seeing is the amount of memory is _available_ for use by my application. As shown above that is 2095MB aka 2.044GB.

So my questions are:  
What is Metricbeat putting into the "system.memory.used.bytes" field?  
How can I get the _available_ memory, which should exclude memory used for Buffers and Cache?

See also [http://www.linuxatemyram.com/](http://www.linuxatemyram.com/)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 12, 2016, 11:18pm UTC](https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786/2 "2016-12-12T23:18:54Z")

</div>

> [@coder-98103](#):
>
> What is Metricbeat putting into the "system.memory.used.bytes" field?

`system.memory.used.bytes = MemTotal - MemFree` where MemTotal and MemFree parsed from `/proc/meminfo` on Linux.

> [@coder-98103](#):
>
> How can I get the available memory, which should exclude memory used for Buffers and Cache?

Metricbeat has `system.memory.actual.free.bytes = MemFree + Buffers + Cached` which is an estimation of the amount of available memory.

---

<div class="post-metadata">

**Author:** ![coder-98103](https://avatars.discourse-cdn.com/v4/letter/c/22d042/32.png) [@coder-98103](https://discuss.elastic.co/u/coder-98103)\
**Post date:** [December 13, 2016, 10:30pm UTC](https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786/3 "2016-12-13T22:30:36Z")

</div>

Okay thanks for the clairification. It seems like the differences are just small deltas due to methodology differences between metricbeat and /usr/bin/free. I expected the numbers to line up exactly, but it is fine if they are close enough.

The thing I mainly wanted to confirm is that "Available Memory" is the amount of memory which needs be used up before the system runs out of memory and invites that mean old "Out Of Memory Killer" to the party.

Or to put it another way:  
system.memory.free - system.memory.actual.free = memory used by cache & buffers which will be tossed overboard in a low memory scenario

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2017, 10:30pm UTC](https://discuss.elastic.co/t/how-does-metricbeat-define-used-memory/68786/4 "2017-01-10T22:30:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
