Since this issue has been closed by @jsoriano I'm asking for a solution here.
I was just trying out Metricbeat to see if I can log outgoing traffic in an LXC container. I couldn't specify other option than the interface (e.g., ports) but I let that go. Unfortunately, I couldn't tell the outgoing traffic in a specific time period after enabling the system network metric. I don't need visualizing it, I simply need a sum.
The hard part is, that whenever the container resets, the counter resets. This isn't, of course, Metricbeat's fault, but there isn't any way to query the data from ES where I can say that I need all the "max" values between X and Y, except for the first one, where you need to take the first document and subtract its
value from the first "max".
I was hoping that there will be an optional setting for non-incremental values for those who need this.
I played around a bit with derivative queries but I couldn't get the result I needed.
My question would be if I'm missing something or this is simply impossible with Metricbeats?