# What does Output Errors mean in Beats monitoring in Kibana?

**URL:** <https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365>\
**Category:** Metrics\
**Tags:** elastic-stack-monitoring\
**Created:** [September 5, 2021, 9:20am UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365 "2021-09-05T09:20:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tterranigma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tterranigma/32/48360_2.png) [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Post date:** [September 5, 2021, 9:20am UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/1 "2021-09-05T09:20:31Z")

</div>

Hello,

In the Stack Monitoring page in Kibana, in the beats section, there is a column called Output Errors. What is this about? I can't see errors in the logs of the remote beats that are being monitored.

If it is about events/logs not being written due to an error when connecting to elasticsearch, does this mean that the logs get lost? Will their sending be retried until success?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 5, 2021, 6:50pm UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/2 "2021-09-05T18:50:54Z")

</div>

Here are the definitions of the beats monitoring fields.

> **[Beat fields | Metricbeat Reference \[7.14\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-beat.html#_output)**

However I am with you ...even here the definitions are a bit vague  
Perhaps someone from the beats team will add some perspective.

@jsoriano

What is the difference between these.

```auto

beat.stats.libbeat.output.write.errors

beat.stats.libbeat.output.events.dropped

beat.stats.libbeat.output.events.failed

```

---

<div class="post-metadata">

**Author:** ![tterranigma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tterranigma/32/48360_2.png) [@tterranigma](https://discuss.elastic.co/u/tterranigma)\
**Post date:** [September 5, 2021, 11:09pm UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/3 "2021-09-05T23:09:18Z")

</div>

Thanks @stephenb . To add to the available info, when you click a specific beat agent in the kibana interface, there are some info ballons that mention:

For the "Fail rate" metric:

> Interval: 10 seconds.  
> Failed in Pipeline: Failures that happened before event was added to the publishing pipeline (output was disabled or publisher client closed).  
> Dropped in Pipeline: Events that have been dropped after N retries (N = max\_retries setting).  
> Dropped in Output: (Fatal drop) Events dropped by the output as being "invalid." The output still acknowledges the event for the Beat to remove it from the queue..  
> Retry in Pipeline: Events in the pipeline that are trying again to be sent to the output

And in the "Output errors" metric:

> Interval: 10 seconds.  
> Sending: Errors in writing the response from the output.  
> Receiving: Errors in reading the response from the output

From the above, I feel that I am safe if the Fail Rate is zero. I don't understand what the output error is though and how it could potentially relate to these fail rates. Looking forward to a reply from @jsoriano.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 5, 2021, 11:28pm UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/4 "2021-09-05T23:28:28Z")

</div>

Thanks @tterranigma

I did not realize those info balloons were there 🙂

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 6, 2021, 11:55am UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/5 "2021-09-06T11:55:47Z")

</div>

Hey,

I agree that this is not very clear in the docs, even after looking at the code I am not 100% sure of the meaning, but let me try to explain 🙂

> [@stephenb](#):
>
> What is the difference between these.
> 
> ```auto
> beat.stats.libbeat.output.write.errors
> 
> beat.stats.libbeat.output.events.dropped
> 
> beat.stats.libbeat.output.events.failed
> 
> ```

`beat.stats.libbeat.output.write.errors` are low-level errors in the underlying http request or tcp connection. These errors are probably harm-less if there are no failed or dropped events, but a high number may indicate that there is some kind of issue in the network or in the output cluster, or that there is some kind of congestion somewhere.

`beat.stats.libbeat.output.events.failed` indicates a higher-level failure at the output level, this means that the output hasn't been able to confirm if an event has been written, and it will be probably retried. So in general, they are transient failures that shouldn't lead to data loss.

`beat.stats.libbeat.output.events.dropped` are dropped events, they are lost for sure. This uses to indicate that the beat is sending events that cannot be indexed. This uses to be a bug in Beats, or some kind of misconfiguration or weird setup. Logs may help to identify the culprit when they happen.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 6, 2021, 11:56am UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/6 "2021-09-06T11:56:16Z")

</div>

I have created an issue to clarify this in the docs [https://github.com/elastic/beats/issues/27763](https://github.com/elastic/beats/issues/27763)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2021, 11:56am UTC](https://discuss.elastic.co/t/what-does-output-errors-mean-in-beats-monitoring-in-kibana/283365/7 "2021-10-04T11:56:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
