# System health based on multiple metrics

**URL:** <https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531>\
**Category:** Kibana\
**Created:** [March 12, 2022, 5:13pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531 "2022-03-12T17:13:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [March 12, 2022, 5:13pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531/1 "2022-03-12T17:13:48Z")

</div>

I am looking to display the health of a system based on multiple metrics, e.g. cpu/memory/page load times via iis/uptime etc.

So I have multiple beats and Elasticsearch ingesting multiple data points.

Ideally I want to look at all the individual metrics mentioned above then display whether a system is healthy based on whether or not the individual metrics meet certain conditions.

Does anyone have any experience doing this or can point me in the right direction?

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [March 14, 2022, 1:42pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531/2 "2022-03-14T13:42:20Z")

</div>

Hi @Garry. Can the fields in a single document determine the health or do you need to use aggregations to determine health?

You might be able to write a [runtime field](https://www.elastic.co/guide/en/kibana/current/managing-data-views.html#runtime-fields) to output a health value for each document.

But, if you need to use aggregations to determine health, you might want to look at some of the advanced capabilities of [TSVB](https://www.elastic.co/guide/en/kibana/current/tsvb.html).

---

<div class="post-metadata">

**Author:** ![Garry](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@Garry](https://discuss.elastic.co/u/Garry)\
**Post date:** [March 14, 2022, 3:08pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531/3 "2022-03-14T15:08:10Z")

</div>

Hi @nickpeihl, I will need to look at the values in various indices.  
For example, for the health in one system I may need to look at uptime values for 2 URLs from heartbeat index, then look at the average page load times in IIS from filebeat index then look at latest metricbeat index for cpu and memory. Based on these returned values in each index i then need to make a decision on where that system is healthy. E.g. URLs are 'UP' + avg page load time for past 30 mins is \<x + avg cpu for past 30 mins \<90% and memory usage\<95%

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [March 14, 2022, 3:44pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531/4 "2022-03-14T15:44:40Z")

</div>

Hi Garry. You might be able to use [TSVB](https://www.elastic.co/guide/en/kibana/current/tsvb.html) for this.

You can create a Data view (called "Index pattern" before 8.0) that matches your indices. The pattern can accept comma separated values as well (example: `logs-*,metrics-*`). This way you have a single Data view that can be used by TSVB to pull data from multiple indices. TSVB supports pipeline aggregations that should help with advanced determinations such as yours.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2022, 3:45pm UTC](https://discuss.elastic.co/t/system-health-based-on-multiple-metrics/299531/5 "2022-04-11T15:45:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
