I have a use case where we do have different applications running in separate containers. We want to monitor the user activity by keeping track of the open TCP connections on each application.
I am using the official metricbeat container image (
docker.elastic.co/beats/metricbeat:6.5.0). It seems like the socket_summary module is what I'm looking for, especially the field
"system.socket.summary.tcp.all.count" where it's documented to be "All open TCP connections". However the data I get from the module doesn't change at all, even if I open multiple connections onto the application the count always remains "1". My suspicion is now that "system.socket.summary.tcp.all.count" doesn't return the connection count but just the socket count.
Is the documentation inaccurate or might there be a bug in the metricbeat?
Thanks in advance for your help!