# Metricbeat inside docker provides correct Total CPU/RAM, but incorrect process top N

**URL:** <https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 20, 2019, 12:52pm UTC](https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939 "2019-01-20T12:52:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dmitriy\_Baskakov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitriy_baskakov/32/39982_2.png) [@Dmitriy\_Baskakov](https://discuss.elastic.co/u/Dmitriy_Baskakov)\
**Post date:** [January 20, 2019, 12:52pm UTC](https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939/1 "2019-01-20T12:52:30Z")

</div>

I run metricbeat 6.5.4 inside docker container using docker-compose.  
I use default configuration from docs:

```
  metricbeat:
    image: docker.elastic.co/beats/metricbeat:6.5.4
    network_mode: host
    user: root
    volumes:
      - /proc:/hostfs/proc:ro
      - /sys/fs/cgroup:/hostfs/sys/fs/cgroup:ro
      - /:/hostfs:ro
      - /var/run/docker.sock:/var/run/docker.sock:ro
    secrets:
      - source: metricbeat.yml
        target: /usr/share/metricbeat/metricbeat.yml
    command:
      - "-system.hostfs=/hostfs"
    restart: unless-stopped
secrets:
  metricbeat.yml:
    file: /etc/beats/metricbeat.yml

```

I use following metricbeat.yml configuration:

```
metricbeat.modules:
- module: system
  period: 10s
  metricsets:
    - cpu
    - load
    - memory
    - network
    - process
    - process_summary
  cpu.metrics: [percentages, normalized_percentages]
  process.include_top_n:
    by_cpu: 5 # include top 5 processes by CPU
    by_memory: 5 # include top 5 processes by memory

```

In Kibana dashboard, I get almost everything correct: total values for CPU/RAM, time histogram for CPU/RAM, network usage. But the only thing which is incorrect: top 5 processes by CPU/RAM.

For example: I have 86% RAM usage, total gauge, and time histogram gauge shows the same, when I SSH into server - I see this same correct values. But top 5 processes by RAM shows minimal usage 0-1% with "metricbeat" process at the top - which shows that metricbeat gets TOP process from inside the container, not from the host top.

Please, provide an advice how to solve this. I was not able to find it in existing topics. I appreciate your help.

![2019-01-20%2015_48_13-%5BMetricbeat%20System%5D%20Host%20overview%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1defc2ba1814c3a4bb27b79563a7576f5433e3fe.png)

 ![2019-01-20%2015_48_07-%5BMetricbeat%20System%5D%20Host%20overview%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4af40ace8dec6ec02e60bd4caaf58f88df1985f5.png) ![2019-01-20%2015_52_58-%5BMetricbeat%20System%5D%20Host%20overview%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/9/8/98009753384e575d0d4e01c74654be6040906a2d.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2019, 12:59pm UTC](https://discuss.elastic.co/t/metricbeat-inside-docker-provides-correct-total-cpu-ram-but-incorrect-process-top-n/164939/2 "2019-02-17T12:59:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
