# Sequence number for ECS Events received by TCP?

**URL:** <https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348>\
**Category:** Beats\
**Tags:** ecs-elastic-common-schema, filebeat\
**Created:** [December 9, 2021, 4:34pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348 "2021-12-09T16:34:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthias\_W](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthias_w/32/96451_2.png) [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Post date:** [December 9, 2021, 4:34pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/1 "2021-12-09T16:34:26Z")

</div>

Hi,

I have configured my application server (JBoss) to format log messages using the ECS formatter and directly send them to Filebeat via TCP.

This works mostly fine - however, there is one issue: Log entries having the same timestamp might appear in random order because apparently no sequence number is being written.

Any idea how to fix that?

Thank you!

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [December 9, 2021, 6:15pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/2 "2021-12-09T18:15:13Z")

</div>

This may impact performance of filebeat, but you can try setting the number of processors with the [max\_procs](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-general-options.html#_max_procs) setting to 1. This may force entries to be process in the order that they are received without any sort of multithreading, which is what I suspect is happening.

---

<div class="post-metadata">

**Author:** ![Matthias\_W](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthias_w/32/96451_2.png) [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Post date:** [December 10, 2021, 2:58am UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/3 "2021-12-10T02:58:28Z")

</div>

> [@AquaX](#):
>
> This may force entries to be process in the order that they are received without any sort of multithreading, which is what I suspect is happening.

Thanks for the reply!

The order of the log entries in the log view is only part of the issue, though. At some points, I also want to export log streams back to file based logs (e.g. if some third party requests a log to diagnose an issue). For this, I am using Elasticsearch’s search API which requires sorting the events before export in order to export more than 10,000 events.

Thus, I really need a sequence number as a second sort criteria to uniquely identify events.

If I force FileBeat to process events single-threaded: Is there any processor available which I can use to add a sequence number as a field?  
Or can I rely on the event IDs (or any other field) generated by FileBeat to be strictly monotonically increasing (at least for most cases in which timestamps are the same)?

If not: Should the ECS formatter component maybe be responsible for generating the sequence number instead? Not sure where the responsibility should lie for this.

---

<div class="post-metadata">

**Author:** ![Matthias\_W](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthias_w/32/96451_2.png) [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Post date:** [December 10, 2021, 3:18am UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/4 "2021-12-10T03:18:18Z")

</div>

> [@Matthias\_W](#):
>
> If not: Should the ECS formatter component maybe be responsible for generating the sequence number instead? Not sure where the responsibility should lie for this.

Just to double down on that one:  
I just realized that the [LogRecord class](https://docs.oracle.com/javase/7/docs/api/java/util/logging/LogRecord.html?is-external=true) already provides a method `getSequenceNumber`. However, the [EcsFormatter](https://github.com/elastic/ecs-logging-java/blob/master/jboss-logmanager-ecs-formatter/src/main/java/co/elastic/logging/jboss/logmanager/EcsFormatter.java) ignores this field.

I have created an issue in GitHub to request this feature: [Write SequenceNumber in jboss-logmanager-ecs-formatter · Issue #154 · elastic/ecs-logging-java · GitHub](https://github.com/elastic/ecs-logging-java/issues/154)

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [December 10, 2021, 2:27pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/5 "2021-12-10T14:27:58Z")

</div>

Good catch!  
I thought that maybe using the [UUID filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-uuid.html) from logstash would be a good solution as that generates a unique ID for each event (no matter the content of the event because it uses time as part of the generation) and you may be able to sort by that field on output. However, it's not something I've tried before.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2022, 4:28pm UTC](https://discuss.elastic.co/t/sequence-number-for-ecs-events-received-by-tcp/291348/6 "2022-01-07T16:28:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
