# Logstash filter "metrics" is not working!

**URL:** <https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482>\
**Category:** Logstash\
**Created:** [November 18, 2016, 6:32am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482 "2016-11-18T06:32:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ritesh\_Sharma](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Ritesh\_Sharma](https://discuss.elastic.co/u/Ritesh_Sharma)\
**Post date:** [November 18, 2016, 6:32am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/1 "2016-11-18T06:32:07Z")

</div>

Hey Guys ,

I am trying to get response per second for some of my APIs from NGINX Access logs and after some googling i came across "metrics" filter of logstash which claims to provide per duration (/sec , /minute etc ) occurrence information for any term present in log event hence i followed the specified conf on elastic and other web sources but it doesn't seem working either .

mentioning some details below ,

NGINX Log Event :

Some\_Private\_IP - - [18/Nov/2016:11:34:47 +0530] "GET /Some/API/URI/ HTTP/1.1" 499 0 rt=2.686 "-" "tsung" "-"

logstash conf :

filter {

if [type] == "nginx79\_transit\_logdata"  
{  
grok {  
pattern =\> ["%{SYSLOGTIMESTAMP:filebeat\_timestamp}%{SPACE}%{SYSLOGHOST:client\_hostname}%{SPACE}%{NOTSPACE:server\_file\_name}%{SPACE}%{IP:remote\_addr}%{SPACE}-%{SPACE}-%{SPACE}[%{HTTPDATE:rqst\_time}]%{SPACE}"%{WORD:rqst\_type}%{SPACE}%{NOTSPACE:api\_called}%{SPACE}%{NOTSPACE:httpversion}%{SPACE}%{NUMBER:status\_code:int}%{SPACE}%{NUMBER:page\_size:double}%{SPACE}rt=%{NUMBER:resp\_time:float}%{SPACE}%{GREEDYDATA:left\_msg}" ]

```
            add_tag => "got_syslog_timestamp"
            add_field => ["received_at", "%{@timestamp}"]
        }

    metrics{
            meter => "status_code" # token getting from above pattern matching and tokenization ; 
            add_tag => "metric"
            }

    date {
            match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
         }

```

}  
}

output {

if [type] == "nginx79\_transit\_logdata" {

```
                    stdout {codec => rubydebug}

```

}  
}

In output json document i can clearly see "got\_syslog\_timestamp" in tags[] which is added in grok filter but unable to see tag "metric" which is added in metrics filter .

Kindly , suggest whether my way of configuring is correct or not or is there any other way of achieving my goal .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 18, 2016, 6:49am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/2 "2016-11-18T06:49:18Z")

</div>

The metrics will be emitted as new events, but the only kind of event you're doing anything about are nginx79\_transit\_logdata ones. Comment out that conditional in your output block and you'll see what happens.

---

<div class="post-metadata">

**Author:** ![Ritesh\_Sharma](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Ritesh\_Sharma](https://discuss.elastic.co/u/Ritesh_Sharma)\
**Post date:** [November 18, 2016, 8:13am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/3 "2016-11-18T08:13:04Z")

</div>

Hey Magnus ,

Yes , you are correct now its throwing some metrics details as json but i am not getting what sort of metrics these are could you kindly explain , i am expecting some per sec occurrence value for each type of Status code (HTTP) present in inp log file.

Kindly help .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 18, 2016, 8:20am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/4 "2016-11-18T08:20:26Z")

</div>

Unless you show what you're getting I can't explain what you're getting.

---

<div class="post-metadata">

**Author:** ![Ritesh\_Sharma](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@Ritesh\_Sharma](https://discuss.elastic.co/u/Ritesh_Sharma)\
**Post date:** [November 18, 2016, 10:02am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/5 "2016-11-18T10:02:56Z")

</div>

Sorry , here it is .

{  
"@timestamp" =\> "2016-11-18T08:00:10.802Z",  
"beat" =\> {  
"hostname" =\> "ip-10-0-0-9",  
"name" =\> "ip-10-0-0-9",  
"version" =\> "5.0.0"  
},  
"input\_type" =\> "log",  
"message" =\> "Nov 18 13:30:09 ip-10-0-0-23 nginxTrial-571 Some\_Private\_IP - - [18/Nov/2016:13:30:01 +0530] "POST /coupons/v1/coupons/10/user-action HTTP/1.1" 200 27 rt=0.010 "-" "tsung" "-"",  
"offset" =\> 14220285,  
"source" =\> "/rescue\_109/dataLogging/Some\_Private\_IP/nginxTrial-571/2016-11-18.log",  
"type" =\> "nginx79\_transit\_logdata",  
"@version" =\> "1",  
"filebeat\_timestamp" =\> "Nov 18 13:30:09",  
"client\_hostname" =\> "ip-10-0-0-23",  
"server\_file\_name" =\> "nginxTrial-571",  
"remote\_addr" =\> "Some\_Private\_IP",  
"rqst\_time" =\> "18/Nov/2016:13:30:01 +0530",  
"rqst\_type" =\> "POST",  
"api\_called" =\> "/coupons/v1/coupons/10/user-action",  
"httpversion" =\> "HTTP/1.1"",  
"status\_code" =\> 200,  
"page\_size" =\> "27",  
"resp\_time" =\> 0.01,  
"left\_msg" =\> ""-" "tsung" "-"",  
"received\_at" =\> "2016-11-18T08:00:10.802Z",  
"tags" =\> [  
[0] "got\_syslog\_timestamp"  
]  
}

{  
"@version" =\> "1",  
"@timestamp" =\> "2016-11-18T08:01:54.500Z",  
"message" =\> "ip-10-0-0-6",  
"status\_code" =\> {  
"count" =\> 8000,  
"rate\_1m" =\> 171.96722134759196,  
"rate\_5m" =\> 513.7988399847355,  
"rate\_15m" =\> 617.8121727163245  
},  
"tags" =\> [  
[0] "metric"  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 18, 2016, 10:21am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/6 "2016-11-18T10:21:42Z")

</div>

> Yes , you are correct now its throwing some metrics details as json but i am not getting what sort of metrics these are could you kindly explain , i am expecting some per sec occurrence value for each type of Status code (HTTP) present in inp log file.

Then you need to configure the metrics filter accordingly. With your current configuration,

```plaintext
metrics{
  meter => "status_code"
  add_tag => "metric"
}

```

you're sending all events into the same bucket. To shard them per status code follow the example in the documentation, e.g. by doing this:

```plaintext
metrics{
  meter => "status_code_%{status_code}"
  add_tag => "metric"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2016, 10:22am UTC](https://discuss.elastic.co/t/logstash-filter-metrics-is-not-working/66482/7 "2016-12-16T10:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
