# Strange behaviour of metrics.count

**URL:** <https://discuss.elastic.co/t/strange-behaviour-of-metrics-count/98981>\
**Category:** Logstash\
**Created:** [August 31, 2017, 9:51am UTC](https://discuss.elastic.co/t/strange-behaviour-of-metrics-count/98981 "2017-08-31T09:51:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Par\_Svensson](https://avatars.discourse-cdn.com/v4/letter/p/b38774/32.png) [@Par\_Svensson](https://discuss.elastic.co/u/Par_Svensson)\
**Post date:** [August 31, 2017, 9:51am UTC](https://discuss.elastic.co/t/strange-behaviour-of-metrics-count/98981/1 "2017-08-31T09:51:58Z")

</div>

I'm seeing intermittent drops of the count value in the metrics plugin that I cant explain.

 ![42](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c090e8871a723aa3e4af5a56a8054478f759612.png)

My setup is that I have an java application, using the logstash-logback-encoder, configured to emit only ERROR log messages and connecting via tcp to logstash which uses the metrics plugin to count the number of events, and output that to carbon-cache from the graphite package.

The goal of my exercise is to get statistics of the number of error log events per day, and somehow visualize when they occur.

Why do I see intermittent "dips" in the metrics.count value several times per day? The logstash process is NOT restarted during the time period.

I'm using the following versions:  
logstash-filter-metrics (4.0.2), logstash 5.1.1, python-carbon-0.9.12-3.el6.1.noarch, graphite-web-0.9.12-5.el6.noarch

Relevant parts of my logstash configuration is:  
input {  
tcp {  
port =\> 4560  
codec =\> json\_lines  
tags =\> ["logback-tcp"]  
}  
}

filter {  
if "logback-tcp" in [tags] and [level] == "ERROR" {  
metrics {  
meter =\> ["servers.%{[service]}.error\_log"]  
add\_tag =\> ["ERROR-logback-tcp"]  
flush\_interval =\> 60  
}  
}  
}

if "ERROR-logback-tcp" in [tags] {  
graphite {  
host =\> "{{ inventory\_hostname }}"  
port =\> 2003  
include\_metrics =\> ["servers.\*error\_log"]  
fields\_are\_metrics =\> true  
}  
}  
}

Regards  
/Pär

---

<div class="post-metadata">

**Author:** ![Par\_Svensson](https://avatars.discourse-cdn.com/v4/letter/p/b38774/32.png) [@Par\_Svensson](https://discuss.elastic.co/u/Par_Svensson)\
**Post date:** [August 31, 2017, 10:02am UTC](https://discuss.elastic.co/t/strange-behaviour-of-metrics-count/98981/2 "2017-08-31T10:02:33Z")

</div>

The strange thing is that the rate from the same metrics looks perfectly normal

 ![11](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88031ac04341e872937a28899c51c4519ab3da13.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 10:02am UTC](https://discuss.elastic.co/t/strange-behaviour-of-metrics-count/98981/3 "2017-09-28T10:02:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
