# Logstash metrics for different types?

**URL:** <https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299>\
**Category:** Logstash\
**Created:** [April 13, 2016, 6:31pm UTC](https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299 "2016-04-13T18:31:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [April 13, 2016, 6:31pm UTC](https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299/1 "2016-04-13T18:31:52Z")

</div>

I'd like to use the metrics filter to give me output of metrics for various `type` data that is coming in. How would I do that?

For example, if Logstash is reading in, and the `type` can be "http", "dns", or "dhcp", I'd like to be able to run the metrics plugin to get a count of each of those types of events.

How can I set up the meter so that I can get stats per type?

Something like

```
filter {
    if [type] == "generated" {
        metrics {
             meter => ["events", "type.%{log_type}"]
             add_tag => "metric"
        }
    }
}
output {
    if "metric" in [tags] {
        file {
            path => "/path/to/output.log"
            codec => line {
                format => "rate(event) - count:%{[events.http][count]} count:%{[events.dns][count]}"
            }
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 13, 2016, 10:50pm UTC](https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299/2 "2016-04-13T22:50:41Z")

</div>

That looks ok, have you tested it?

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [April 14, 2016, 3:37pm UTC](https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299/3 "2016-04-14T15:37:20Z")

</div>

No. It doesn't work. The output simply says `rate(event) - count:%{events.http][count] ...`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/logstash-metrics-for-different-types/47299/4 "2017-07-06T05:02:14Z")

</div>


