# How to access filebeat HAProxy total response time?

**URL:** <https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 18, 2021, 4:22pm UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622 "2021-11-18T16:22:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mmcnl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmcnl/32/97235_2.png) [@mmcnl](https://discuss.elastic.co/u/mmcnl)\
**Post date:** [November 18, 2021, 4:22pm UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622/1 "2021-11-18T16:22:05Z")

</div>

I have the exact same question as was asked in [this topic](https://discuss.elastic.co/t/filebeat-haproxy-fields-mapping-not-clear-what-is-the-total-active-time-for-the-http-request/266088), which was closed due to no responses. Namely:

> Where do I find default HAProxy Timers `Tr` or `Ta` (which I assume include data/body) in Elastic Filebeat HAProxy fields?

Thank you for any input!

---

<div class="post-metadata">

**Author:** ![mmcnl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmcnl/32/97235_2.png) [@mmcnl](https://discuss.elastic.co/u/mmcnl)\
**Post date:** [December 8, 2021, 1:05am UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622/2 "2021-12-08T01:05:09Z")

</div>

@warkolm As you suggested in a PM, I opened a new topic with the same question. Is there anyone on the Elastic team who can respond? Thanks much for any input!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 8, 2021, 1:33am UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622/3 "2021-12-08T01:33:13Z")

</div>

The HAProxy module in filebeat uses this [ingest pipeline](https://github.com/elastic/beats/blob/master/filebeat/module/haproxy/log/ingest/pipeline.yml) to parse the log message.

The part that will parse the times is this one:

```auto
%{NUMBER:haproxy.http.request.time_wait_ms:long}/%{NUMBER:haproxy.total_waiting_time_ms:long}/%{NUMBER:haproxy.connection_wait_time_ms:long}/%{NUMBER:haproxy.http.request.time_wait_without_data_ms:long}/%{NUMBER:temp.duration:long}

```

Later in the pipeline the field `temp.duration` is renamed as `event.duration` using this processor:

```auto
- script:
    lang: painless
    source: ctx.event.duration = Math.round(ctx.temp.duration * params.scale)
    params:
      scale: 1000000
    if: ctx.temp?.duration != null

```

So, the 5 time fields from HAProxy HTTP requests, `TR`/`Tw`/`Tc`/`Tr`/`Ta`, will be parsed as:

```auto
haproxy.http.request.time_wait_ms
haproxy.total_waiting_time_ms
haproxy.connection_wait_time_ms
haproxy.http.request.time_wait_without_data_ms
event.duration

```

You then have:

- `TR`: `haproxy.http.request.time_wait_ms`
- `Tw`: `haproxy.total_waiting_time_ms`
- `Tc`: `haproxy.connection_wait_time_ms`
- `Tr`: `haproxy.http.request.time_wait_without_data_ms`
- `Ta`: `event.duration`

On a previous company I used to collect HAProxy logs, but I changed the ingest pipeline to store the fields as `haproxy.TR`, `haproxy.Ta` etc, I find that this is pretty easy for anyone who cames from a HAProxy background to understand what is the metric, the names used by elastic just added confusion to the analysts.

---

<div class="post-metadata">

**Author:** ![mmcnl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmcnl/32/97235_2.png) [@mmcnl](https://discuss.elastic.co/u/mmcnl)\
**Post date:** [December 8, 2021, 1:46am UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622/4 "2021-12-08T01:46:10Z")

</div>

Thank you very much @leandrojmp, much appreciated!! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2022, 3:46am UTC](https://discuss.elastic.co/t/how-to-access-filebeat-haproxy-total-response-time/289622/5 "2022-01-05T03:46:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
