# Metrics format recommendations?

**URL:** <https://discuss.elastic.co/t/metrics-format-recommendations/28882>\
**Category:** Beats\
**Created:** [September 9, 2015, 12:51am UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882 "2015-09-09T00:51:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![imre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imre/32/5044_2.png) [@imre](https://discuss.elastic.co/u/imre)\
**Post date:** [September 9, 2015, 12:51am UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/1 "2015-09-09T00:51:16Z")

</div>

Hi folks,

do you have a writeup on metrics formatting conventions?

I have looked at the topbeat and packetbeat entries in ES and it wasn't clear how it was decided that some information should have:

- their own fields "client\_port"
- some were concatenated "proc.state"
- some had an array ""http": {"code": 200}

There is also the source naming convention: Topbeat uses "shipper" as the source but Packetbeat has "server" and "shipper".

Do you have any guidance? Thanks!

Imre

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 9, 2015, 1:50am UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/2 "2015-09-09T01:50:52Z")

</div>

Packetbeat has [documentation](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields.html) on each of the exported fields and their meanings.

You might also find the [developer guide](https://www.elastic.co/guide/en/beats/packetbeat/current/_developer_guide_adding_a_new_protocol.html) helpful depending on what you are doing.

---

<div class="post-metadata">

**Author:** ![imre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imre/32/5044_2.png) [@imre](https://discuss.elastic.co/u/imre)\
**Post date:** [September 9, 2015, 2:31pm UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/3 "2015-09-09T14:31:46Z")

</div>

> [@andrewkroh](#):
>
> developer guide

Thank you, the Packetbeat Exported Fields document was very helpful.

It's interesting how Topbeat doesn't implement some of the fields Packetbeat defines as Required: "status" and "path".

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [September 10, 2015, 7:28am UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/4 "2015-09-10T07:28:23Z")

</div>

`status` and `path` are required in the context of Packetbeat. I don't think they should required for all Beats, I struggle to think what we should fill them for Topbeat.

---

<div class="post-metadata">

**Author:** ![imre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imre/32/5044_2.png) [@imre](https://discuss.elastic.co/u/imre)\
**Post date:** [September 28, 2015, 2:15pm UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/5 "2015-09-28T14:15:15Z")

</div>

Another thing about topbeat metric naming: ES2.0 doesn't accept field names with commas in it, so "proc.cpu" is an invalid format.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [September 29, 2015, 9:03am UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/6 "2015-09-29T09:03:11Z")

</div>

You are right, we've cleaned that in master and now there's field documentation as well. From [this](https://github.com/elastic/topbeat/blob/master/etc/fields.yml) we generate [this](https://github.com/elastic/topbeat/blob/master/docs/fields.asciidoc).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:58pm UTC](https://discuss.elastic.co/t/metrics-format-recommendations/28882/7 "2017-07-05T21:58:42Z")

</div>


