# Kibana Infrastructure data source

**URL:** <https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493>\
**Category:** Metrics\
**Created:** [May 10, 2019, 6:20am UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493 "2019-05-10T06:20:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jehutywong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehutywong/32/50527_2.png) [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Post date:** [May 10, 2019, 6:20am UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/1 "2019-05-10T06:20:27Z")

</div>

I'd wonder, if Kibana Infrastructure app can support data source other than metricbeat.

I am now collecting system metrics by Collectd. I assume Infrastructure app is looking for pre-defined field names. Can I modify field names in Collectd by Logstash, so that Infrastructure app can recognize those data.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 10, 2019, 1:50pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/2 "2019-05-10T13:50:01Z")

</div>

If you follow [ECS](https://www.elastic.co/guide/en/ecs/current/index.html) and the metric schema used in the system module of Metricbeat (here memory as an example: [https://github.com/elastic/beats/blob/master/metricbeat/module/system/memory/\_meta/fields.yml](https://github.com/elastic/beats/blob/master/metricbeat/module/system/memory/_meta/fields.yml)) the above should work.

---

<div class="post-metadata">

**Author:** ![Jehutywong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehutywong/32/50527_2.png) [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Post date:** [May 10, 2019, 2:39pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/3 "2019-05-10T14:39:00Z")

</div>

Will give it a try and feedback.

Many Thanks @ruflin for the confirmation.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [May 10, 2019, 2:44pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/4 "2019-05-10T14:44:45Z")

</div>

Here is a list of the fields that the Infrastructure UI uses: [https://www.elastic.co/guide/en/infrastructure/guide/current/install-infrastructure-monitoring.html#\_which\_fields\_are\_used\_for\_the\_metrics\_on\_the\_infrastructure\_home\_page](https://www.elastic.co/guide/en/infrastructure/guide/current/install-infrastructure-monitoring.html#_which_fields_are_used_for_the_metrics_on_the_infrastructure_home_page)

---

<div class="post-metadata">

**Author:** ![Jehutywong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehutywong/32/50527_2.png) [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Post date:** [May 14, 2019, 3:23am UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/5 "2019-05-14T03:23:40Z")

</div>

I have successfully enabled CPU, memory, load metrics in Infrastructure UI. But inbound and outbound traffic are always 0 bits.

I have both system.netowrk.in.bytes and system.netowrk.out.bytes in place, both of which are type number. However, these two metrics are not unique in a host, as there may have multiple NIC. Any advise?

BTW, according to the document, the UI will use max of `system.netowrk.in.bytes` and max of `system.netowrk.out.bytes`, here what's the max mean? max across NIC, or max across time interval?

---

<div class="post-metadata">

**Author:** ![Jehutywong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jehutywong/32/50527_2.png) [@Jehutywong](https://discuss.elastic.co/u/Jehutywong)\
**Post date:** [May 28, 2019, 6:53am UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/7 "2019-05-28T06:53:36Z")

</div>

i think its related to this issue

> <https://github.com/elastic/kibana/issues/36774>

My current data collection interval is 5 minutes

---

<div class="post-metadata">

**Author:** ![skh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skh/32/38637_2.png) [@skh](https://discuss.elastic.co/u/skh)\
**Post date:** [May 28, 2019, 1:50pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/8 "2019-05-28T13:50:08Z")

</div>

> [@Jehutywong](#):
>
> BTW, according to the document, the UI will use max of `system.netowrk.in.bytes` and max of `system.netowrk.out.bytes` , here what's the max mean? max across NIC, or max across time interval?

Well spotted, thank you! Currently it is `max` across all documents in the time interval, which does not look correct. We're tracking this in [[Infra UI] system.network.\* not displayed by interface name · Issue #37225 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/37225) .

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [June 3, 2019, 5:11pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/9 "2019-06-03T17:11:43Z")

</div>

@Jehutywong There is a [bug](https://github.com/elastic/kibana/issues/37225) with the metrics on the main "Inventory" view that is calculating the in/out traffic, it's not accounting for ALL the interfaces. The values on the "metrics page" view are correct and are sum total of all the interfaces.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2019, 5:13pm UTC](https://discuss.elastic.co/t/kibana-infrastructure-data-source/180493/10 "2019-07-01T17:13:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
