# Metricbeat and advanced Prometheus queries

**URL:** <https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 28, 2019, 6:51am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412 "2019-10-28T06:51:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [October 28, 2019, 6:51am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/1 "2019-10-28T06:51:06Z")

</div>

I'm trying to use the metricbeat prometheus module to run a query like :

```auto
query:
  'match[]' : 'sum(increase(unix_bytes[5m])) by (process)'

```

however I get an error "Unable to decode response from prometheus endpoint". Am I kidding myself that I'm gonna be able to execute this type of query?

Secondly in the prometheus module does the `period: 300s` directive tell metricbeat to query the last 5m or do I need to do that in the query? The module is pretty sparsely documented!

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [October 29, 2019, 10:40am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/2 "2019-10-29T10:40:21Z")

</div>

Hi @hilt86 🙂

Please, can you try wrapping that PromQL queries between `{}`? It seems like it might be a requirement of the Federation API of Prometheus:

```auto
query:
  'match[]' : '{sum(increase(unix_bytes[5m])) by (process)}'

```

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [November 8, 2019, 8:00am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/3 "2019-11-08T08:00:31Z")

</div>

yeah same error...what is the difference between the /metrics and /federate endpoints?

Any other pointers?

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [November 20, 2019, 10:35am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/4 "2019-11-20T10:35:26Z")

</div>

Should I expect this to work @Mario_Castro or could you provide further assistance please?

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [November 27, 2019, 9:02am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/5 "2019-11-27T09:02:44Z")

</div>

It should work, I'm just wondering if it's something related to the query syntax in Prometheus. Have you check the query.

About the metrics and federate endpoints, for something so especific maybe you should ask in a Prometheus forum. I have no clue, frankly 😅

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [December 2, 2019, 9:31pm UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/6 "2019-12-02T21:31:10Z")

</div>

yeah it works in the prometheus interface....I'll try other queries and see what I find

---

<div class="post-metadata">

**Author:** ![esther.k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esther.k/32/67343_2.png) [@esther.k](https://discuss.elastic.co/u/esther.k)\
**Post date:** [December 13, 2019, 4:54am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/7 "2019-12-13T04:54:15Z")

</div>

Hi,  
Is there any progress in this issue?  
I am also trying to fetch the result from prometheus query. But `/federate` API in Prometheus doesn't seem to support "sum" query. This API works to scrape Prometheus' metrics.  
So I added some code into Metricbeat and it works.  
I am wondering if it's right way to work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 4:54am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/8 "2020-01-10T04:54:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [April 28, 2020, 9:12am UTC](https://discuss.elastic.co/t/metricbeat-and-advanced-prometheus-queries/205412/9 "2020-04-28T09:12:37Z")

</div>

Hey! This is expected to be solved by [https://github.com/elastic/beats/pull/15177](https://github.com/elastic/beats/pull/15177) where Metricbeat collects from Prometheus Query API directly. It is expected to be available in `7.7`.
