# New Plugin logstash-input-proc Linux /proc parser

**URL:** <https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098>\
**Category:** Community Ecosystem\
**Created:** [June 7, 2015, 7:23pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098 "2015-06-07T19:23:58Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 7, 2015, 7:23pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/1 "2015-06-07T19:23:59Z")

</div>

Hi everyone, I wanted to let you know about a new plugin. I wanted to start pulling statistics from the operating system and could not figure out how to get logstash/grock to parse some of the file formats. So, to avoid making Exec calls to ps, lsof, netstat, iostat and other tools. I wrote a plugin that would gather the raw data directly from the /proc directory

> **[eperry/logstash-input-proc](https://github.com/eperry/logstash-input-proc)**
>
> logstash-input-proc - A Logstash plugin to read the Linux Kernel /proc mount

Currently I am parsing - hoping to add more  
/proc/meminfo, vmstat, diskinfom, loadavg, mounts  
/proc/net/dev  
/proc//cmdline,exec,environ,stats,status  
/proc//fd/\*  
/proc//task/\*

I am right now considering:

- breaking this in to multiple plugins as some data does not change often while others do.
- changing the PID output to be multiple outputs rather then just 1 large doc
- adding more files
- Creating a sample Kibana dashboard to demo the data

I would love to hear some feed back about what you think of the plugin.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 8, 2015, 1:02am UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/2 "2015-06-08T01:02:15Z")

</div>

Very nice idea!

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 13, 2015, 1:25pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/3 "2015-06-13T13:25:29Z")

</div>

Thanks, I hope everyone likes it,

Now I am working on some Kibana Dashboards to display some of the data. It seems like it is starting to come together.

I think next week I will split it in to 2 or 3 different plugins.

- Process monitoring and statistics

- Static system information (Cpuinfo, PCI bus, and other information related to the hardware

- Highly Volatile data like MEMINFO,VMSTATS, NET/DEV, ....

I found that with all the files enabled it takes ~1 second to grab every file, not bad when sar collects by default once every 10 minutes.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 20, 2015, 7:03pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/4 "2015-06-20T19:03:08Z")

</div>

The plugin is now available via RubyGems

[https://rubygems.org/gems/logstash-input-proc](https://rubygems.org/gems/logstash-input-proc)  
[http://eperry.github.io/logstash-input-proc/](http://eperry.github.io/logstash-input-proc/)

##install  
${LS\_HOME}/bin/plugins install logstash-inputs-proc

## use

## Example Config all features enabled

```ruby
input {
    proc {
        interval=>60
        vmstats =>{ }
        loadavg =>{ }
        meminfo =>{ }
        pidstats =>{ 
            user => "root"
        }
        
    }
}

output { 
    stdout{ 
        codec=>"rubydebug"
    }
}

```

##Example Minimal

```ruby
input {
    proc {
        interval=>60
        meminfo =>{ }
    }
}

output { 
    stdout{ 
        codec=>"rubydebug"
    }
}

```

---

<div class="post-metadata">

**Author:** ![thehybridtech](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@thehybridtech](https://discuss.elastic.co/u/thehybridtech)\
**Post date:** [September 25, 2015, 2:59am UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/5 "2015-09-25T02:59:39Z")

</div>

Just saw this... Very cool...  
I process Sosreports and a couple other log bundles that do a basic proc dump. Mind if I fork and setup a config option to pull from a non standard path?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [October 11, 2015, 4:43pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/6 "2015-10-11T16:43:39Z")

</div>

Go a head that is the wonders of github feel free to fork it.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 11, 2015, 9:13pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/7 "2015-10-11T21:13:31Z")

</div>

We've also implemented a similar thing via Topbeat [https://www.elastic.co/guide/en/beats/topbeat/current/index.html](https://www.elastic.co/guide/en/beats/topbeat/current/index.html)

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [October 11, 2015, 11:25pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/8 "2015-10-11T23:25:20Z")

</div>

I might go look at how your collecting the stats. Though I like the idea of only having to run logstash on a server. One of the biggest issue I am starting to see is all the different agents I have to run on servers

Satellite runs gofred  
Nagios and Ganglia want an agent  
Puppet wants an agent (Or Salt)  
NewRelic wants an agent  
Oracle Monitoring or Websphere/Weblogic Node Agent  
Plus all the systems background processes

Then to add Logstash, packetbeat and topbeat on top of this. I seem to add up to 1 or 2 gigs just for monitoring and management.

Fortunately I run systems with +100GB memory so not that big of issue but this is starting to make me think about how much of what is running might be consolidated in to one or two tools.

Eh, guess this is the next hurdle to think about in IT management.

---

<div class="post-metadata">

**Author:** ![kaem2111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaem2111/32/24961_2.png) [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Post date:** [November 1, 2015, 10:49am UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/9 "2015-11-01T10:49:54Z")

</div>

Hi, I newly installed ES 2.0 with Logstash 2.0.0 and cannot download your plugin, maybe because of  
the Runtime dependency: logstash-core **\< 2.0.0** , \>= 1.4.0  
on [https://rubygems.org/gems/logstash-input-proc/versions/0.3.1](https://rubygems.org/gems/logstash-input-proc/versions/0.3.1).

May you change this or is there a hidden option to force download?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [November 1, 2015, 1:21pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/10 "2015-11-01T13:21:28Z")

</div>

Let me look at it, I have not tested it with LS 2.0 nor looked at the new API but lets see

---

<div class="post-metadata">

**Author:** ![kartman](https://avatars.discourse-cdn.com/v4/letter/k/898d66/32.png) [@kartman](https://discuss.elastic.co/u/kartman)\
**Post date:** [April 5, 2017, 5:44pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/12 "2017-04-05T17:44:41Z")

</div>

Sounds so cool. Is there any plans to upgrade this to work with the latest LS releases?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [April 6, 2017, 4:27pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/13 "2017-04-06T16:27:49Z")

</div>

you know I did not think about it, it might work as is. It is not doing more then a standard search. I will look at it  
you may want to check out this project though

> **[sivasamyk/logtrail](https://github.com/sivasamyk/logtrail)**
>
> logtrail - Kibana plugin to view, search & live tail log events

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:46pm UTC](https://discuss.elastic.co/t/new-plugin-logstash-input-proc-linux-proc-parser/2098/14 "2017-07-05T21:46:26Z")

</div>


