An example document:
{
"_index": "metricbeat-7.9.2-000003",
"_type": "_doc",
"_id": "t4k3J3UBGS9yby_KINOp",
"_version": 1,
"_score": null,
"_source": {
"@version": "1",
"ecs": {
"version": "1.5.0"
},
"tags": [
"beats_input_raw_event"
],
"service": {
"type": "system"
},
"process": {
"args": [
"/usr/bin/python2",
"/usr/bin/ansible-playbook",
"--ask-vault-pass",
"-i",
"inventories/dev",
"--skip-tags",
"debug",
"--tags",
"install",
"-e",
"",
"playbooks/filebeat.yml"
],
"pid": 9628,
"ppid": 9626,
"pgid": 9606,
"name": "ansible-playboo"
},
"metricset": {
"period": 10000,
"name": "process"
},
"system": {
"process": {
"memory": {
"share": 5541888,
"size": 467177472,
"rss": {
"pct": 0.002,
"bytes": 66600960
}
},
"state": "running",
"cpu": {
"start_time": "2020-10-14T13:04:14.000Z",
"total": {
"pct": 0.4792,
"norm": {
"pct": 0.0599
},
"value": 20800
}
},
"cmdline": "/usr/bin/python2 /usr/bin/ansible-playbook --ask-vault-pass -i inventories/dev --skip-tags debug --tags install -e playbooks/filebeat.yml"
}
},
"@timestamp": "2020-10-14T13:05:24.435Z",
"user": {
"name": "faadmin"
},
"host": {
"architecture": "x86_64",
"hostname": "my_kibana_server",
"ip": [
"10.128.113.8",
"fe80::250:56ff:fe3e:724"
],
"mac": [
"00:50:56:3e:07:24"
],
"name": "my_kibana_server",
"os": {
"family": "redhat",
"version": "7.9 (Maipo)",
"codename": "Maipo",
"name": "Red Hat Enterprise Linux Server",
"platform": "rhel",
"kernel": "3.10.0-1160.2.1.el7.x86_64"
},
"containerized": false,
"id": "30f130795bbc40239af1345f312f1319"
},
"event": {
"module": "system",
"duration": 63018385,
"dataset": "system.process"
},
"agent": {
"hostname": "my_kibana_server",
"name": "my_kibana_server",
"type": "metricbeat",
"version": "7.9.2",
"ephemeral_id": "dd4c76bf-42a5-40b4-b5f9-5546a3aab142",
"id": "780381de-2def-4cdb-9df0-3e7806ebcf96"
}
},
"fields": {
"system.process.cpu.start_time": [
"2020-10-14T13:04:14.000Z"
],
"@timestamp": [
"2020-10-14T13:05:24.435Z"
]
},
"highlight": {
"process.name": [
"@kibana-highlighted-field@ansible-playboo@/kibana-highlighted-field@"
],
"mongodb.status.process": [
"@kibana-highlighted-field@ansible-playboo@/kibana-highlighted-field@"
]
},
"sort": [
1602680724435
]
}