System Fields

edit

System status metrics, like CPU and memory usage, that are collected from the operating system.

system Fields

edit

system contains local system metrics.

core Fields

edit

system-core contains local CPU core stats.

system.core.id

edit

type: long

CPU Core number.

system.core.user.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in user space. On multi-core systems, you can have percentages that are greater than 100%. For example, if 3 cores are at 60% use, then the cpu.user_p will be 180%.

system.core.user.ticks

edit

type: long

The amount of CPU time spent in user space.

system.core.system.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in kernel space.

system.core.system.ticks

edit

type: long

The amount of CPU time spent in kernel space.

system.core.nice.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent on low-priority processes.

system.core.nice.ticks

edit

type: long

The amount of CPU time spent on low-priority processes.

system.core.idle.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent idle.

system.core.idle.ticks

edit

type: long

The amount of CPU time spent idle.

system.core.iowait.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in wait (on disk).

system.core.iowait.ticks

edit

type: long

The amount of CPU time spent in wait (on disk).

system.core.irq.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent servicing and handling hardware interrupts.

system.core.irq.ticks

edit

type: long

The amount of CPU time spent servicing and handling hardware interrupts.

system.core.softirq.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent servicing and handling software interrupts.

system.core.softirq.ticks

edit

type: long

The amount of CPU time spent servicing and handling software interrupts.

system.core.steal.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in involuntary wait by the virtual CPU while the hypervisor was servicing another processor. Available only on Unix.

system.core.steal.ticks

edit

type: long

The amount of CPU time spent in involuntary wait by the virtual CPU while the hypervisor was servicing another processor. Available only on Unix.

cpu Fields

edit

cpu contains local CPU stats.

system.cpu.cores

edit

type: long

The number of CPU cores.

system.cpu.user.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in user space. On multi-core systems, you can have percentages that are greater than 100%. For example, if 3 cores are at 60% use, then the cpu.user_p will be 180%.

system.cpu.system.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in kernel space.

system.cpu.nice.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent on low-priority processes.

system.cpu.idle.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent idle.

system.cpu.iowait.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in wait (on disk).

system.cpu.irq.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent servicing and handling hardware interrupts.

system.cpu.softirq.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent servicing and handling software interrupts.

system.cpu.steal.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent in involuntary wait by the virtual CPU while the hypervisor was servicing another processor. Available only on Unix.

system.cpu.user.ticks

edit

type: long

The amount of CPU time spent in user space.

system.cpu.system.ticks

edit

type: long

The amount of CPU time spent in kernel space.

system.cpu.nice.ticks

edit

type: long

The amount of CPU time spent on low-priority processes.

system.cpu.idle.ticks

edit

type: long

The amount of CPU time spent idle.

system.cpu.iowait.ticks

edit

type: long

The amount of CPU time spent in wait (on disk).

system.cpu.irq.ticks

edit

type: long

The amount of CPU time spent servicing and handling hardware interrupts.

system.cpu.softirq.ticks

edit

type: long

The amount of CPU time spent servicing and handling software interrupts.

system.cpu.steal.ticks

edit

type: long

The amount of CPU time spent in involuntary wait by the virtual CPU while the hypervisor was servicing another processor. Available only on Unix.

diskio Fields

edit

disk contains disk IO metrics collected from the operating system.

system.diskio.name

edit

type: keyword

example: sda1

The disk name.

system.diskio.serial_number

edit

type: keyword

The disk’s serial number. This may not be provided by all operating systems.

system.diskio.read.count

edit

type: long

The total number of reads completed successfully.

system.diskio.write.count

edit

type: long

The total number of writes completed successfully.

system.diskio.read.bytes

edit

type: long

format: bytes

The total number of bytes read successfully. On Linux this is the number of sectors read multiplied by an assumed sector size of 512.

system.diskio.write.bytes

edit

type: long

format: bytes

The total number of bytes written successfully. On Linux this is the number of sectors written multiplied by an assumed sector size of 512.

system.diskio.read.time

edit

type: long

The total number of milliseconds spent by all reads.

system.diskio.write.time

edit

type: long

The total number of milliseconds spent by all writes.

system.diskio.io.time

edit

type: long

The total number of of milliseconds spent doing I/Os.

filesystem Fields

edit

filesystem contains local filesystem stats.

system.filesystem.available

edit

type: long

format: bytes

The disk space available to an unprivileged user in bytes.

system.filesystem.device_name

edit

type: keyword

The disk name. For example: /dev/disk1

system.filesystem.mount_point

edit

type: keyword

The mounting point. For example: /

system.filesystem.files

edit

type: long

The total number of file nodes in the file system.

system.filesystem.free

edit

type: long

format: bytes

The disk space available in bytes.

system.filesystem.free_files

edit

type: long

The number of free file nodes in the file system.

system.filesystem.total

edit

type: long

format: bytes

The total disk space in bytes.

system.filesystem.used.bytes

edit

type: long

format: bytes

The used disk space in bytes.

system.filesystem.used.pct

edit

type: scaled_float

format: percent

The percentage of used disk space.

fsstat Fields

edit

system.fsstat contains filesystem metrics aggregated from all mounted filesystems, similar with what df -a prints out.

system.fsstat.count

edit

type: long

Number of file systems found.

system.fsstat.total_files

edit

type: long

Total number of files.

total_size Fields

edit

Nested file system docs.

system.fsstat.total_size.free

edit

type: long

format: bytes

Total free space.

system.fsstat.total_size.used

edit

type: long

format: bytes

Total used space.

system.fsstat.total_size.total

edit

type: long

format: bytes

Total space (used plus free).

load Fields

edit

Load averages.

system.load.1

edit

type: scaled_float

Load average for the last minute.

system.load.5

edit

type: scaled_float

Load average for the last 5 minutes.

system.load.15

edit

type: scaled_float

Load average for the last 15 minutes.

system.load.norm.1

edit

type: scaled_float

Load divided by the number of cores for the last minute.

system.load.norm.5

edit

type: scaled_float

Load divided by the number of cores for the last 5 minutes.

system.load.norm.15

edit

type: scaled_float

Load divided by the number of cores for the last 15 minutes.

memory Fields

edit

memory contains local memory stats.

system.memory.total

edit

type: long

format: bytes

Total memory.

system.memory.used.bytes

edit

type: long

format: bytes

Used memory.

system.memory.free

edit

type: long

format: bytes

The total amount of free memory in bytes. This value does not include memory consumed by system caches and buffers (see system.memory.actual.free).

system.memory.used.pct

edit

type: scaled_float

format: percent

The percentage of used memory.

actual Fields

edit

Actual memory used and free.

system.memory.actual.used.bytes

edit

type: long

format: bytes

Actual used memory in bytes. It represents the difference between the total and the available memory. The available memory depends on the OS. For more details, please check system.actual.free.

system.memory.actual.free

edit

type: long

format: bytes

Actual free memory in bytes. It is calculated based on the OS. On Linux it consists of the free memory plus caches and buffers. On OSX it is a sum of free memory and the inactive memory. On Windows, it is equal to system.memory.free.

system.memory.actual.used.pct

edit

type: scaled_float

format: percent

The percentage of actual used memory.

swap Fields

edit

This group contains statistics related to the swap memory usage on the system.

system.memory.swap.total

edit

type: long

format: bytes

Total swap memory.

system.memory.swap.used.bytes

edit

type: long

format: bytes

Used swap memory.

system.memory.swap.free

edit

type: long

format: bytes

Available swap memory.

system.memory.swap.used.pct

edit

type: scaled_float

format: percent

The percentage of used swap memory.

network Fields

edit

network contains network IO metrics for a single network interface.

system.network.name

edit

type: keyword

example: eth0

The network interface name.

system.network.out.bytes

edit

type: long

format: bytes

The number of bytes sent.

system.network.in.bytes

edit

type: long

format: bytes

The number of bytes received.

system.network.out.packets

edit

type: long

The number of packets sent.

system.network.in.packets

edit

type: long

The number or packets received.

system.network.in.errors

edit

type: long

The number of errors while receiving.

system.network.out.errors

edit

type: long

The number of errors while sending.

system.network.in.dropped

edit

type: long

The number of incoming packets that were dropped.

system.network.out.dropped

edit

type: long

The number of outgoing packets that were dropped. This value is always 0 on Darwin and BSD because it is not reported by the operating system.

process Fields

edit

process contains process metadata, CPU metrics, and memory metrics.

system.process.name

edit

type: keyword

The process name.

system.process.state

edit

type: keyword

The process state. For example: "running".

system.process.pid

edit

type: long

The process pid.

system.process.ppid

edit

type: long

The process parent pid.

system.process.pgid

edit

type: long

The process group id.

system.process.cmdline

edit

type: keyword

The full command-line used to start the process, including the arguments separated by space.

system.process.username

edit

type: keyword

The username of the user that created the process. If the username cannot be determined, the field will contain the user’s numeric identifier (UID). On Windows, this field includes the user’s domain and is formatted as domain\username.

cpu Fields

edit

CPU-specific statistics per process.

system.process.cpu.user

edit

type: long

The amount of CPU time the process spent in user space.

system.process.cpu.total.pct

edit

type: scaled_float

format: percent

The percentage of CPU time spent by the process since the last update. Its value is similar to the %CPU value of the process displayed by the top command on Unix systems.

system.process.cpu.system

edit

type: long

The amount of CPU time the process spent in kernel space.

system.process.cpu.total.ticks

edit

type: long

The total CPU time spent by the process.

system.process.cpu.start_time

edit

type: date

The time when the process was started.

memory Fields

edit

Memory-specific statistics per process.

system.process.memory.size

edit

type: long

format: bytes

The total virtual memory the process has.

system.process.memory.rss.bytes

edit

type: long

format: bytes

The Resident Set Size. The amount of memory the process occupied in main memory (RAM).

system.process.memory.rss.pct

edit

type: scaled_float

format: percent

The percentage of memory the process occupied in main memory (RAM).

system.process.memory.share

edit

type: long

format: bytes

The shared memory the process uses.

fd Fields

edit

File descriptor usage metrics. This set of metrics is available for Linux and FreeBSD.

system.process.fd.open

edit

type: long

The number of file descriptors open by the process.

system.process.fd.limit.soft

edit

type: long

The soft limit on the number of file descriptors opened by the process. The soft limit can be changed by the process at any time.

system.process.fd.limit.hard

edit

type: long

The hard limit on the number of file descriptors opened by the process. The hard limit can only be raised by root.

cgroup Fields

edit

This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.

Metrics and limits from the cgroup of which the task is a member. cgroup metrics are reported when the process has membership in a non-root cgroup. These metrics are only available on Linux.

system.process.cgroup.id

edit

type: keyword

The ID common to all cgroups associated with this task. If there isn’t a common ID used by all cgroups this field will be absent.

system.process.cgroup.path

edit

type: keyword

The path to the cgroup relative to the cgroup subsystem’s mountpoint. If there isn’t a common path used by all cgroups this field will be absent.

cpu Fields

edit

The cpu subsystem schedules CPU access for tasks in the cgroup. Access can be controlled by two separate schedulers, CFS and RT. CFS stands for completely fair scheduler which proportionally divides the CPU time between cgroups based on weight. RT stands for real time scheduler which sets a maximum amount of CPU time that processes in the cgroup can consume during a given period.

system.process.cgroup.cpu.id

edit

type: keyword

ID of the cgroup.

system.process.cgroup.cpu.path

edit

type: keyword

Path to the cgroup relative to the cgroup subsystem’s mountpoint.

system.process.cgroup.cpu.cfs.period.us

edit

type: long

Period of time in microseconds for how regularly a cgroup’s access to CPU resources should be reallocated.

system.process.cgroup.cpu.cfs.quota.us

edit

type: long

Total amount of time in microseconds for which all tasks in a cgroup can run during one period (as defined by cfs.period.us).

system.process.cgroup.cpu.cfs.shares

edit

type: long

An integer value that specifies a relative share of CPU time available to the tasks in a cgroup. The value specified in the cpu.shares file must be 2 or higher.

system.process.cgroup.cpu.rt.period.us

edit

type: long

Period of time in microseconds for how regularly a cgroup’s access to CPU resources is reallocated.

system.process.cgroup.cpu.rt.runtime.us

edit

type: long

Period of time in microseconds for the longest continuous period in which the tasks in a cgroup have access to CPU resources.

system.process.cgroup.cpu.stats.periods

edit

type: long

Number of period intervals (as specified in cpu.cfs.period.us) that have elapsed.

system.process.cgroup.cpu.stats.throttled.periods

edit

type: long

Number of times tasks in a cgroup have been throttled (that is, not allowed to run because they have exhausted all of the available time as specified by their quota).

system.process.cgroup.cpu.stats.throttled.ns

edit

type: long

The total time duration (in nanoseconds) for which tasks in a cgroup have been throttled.

cpuacct Fields

edit

CPU accounting metrics.

system.process.cgroup.cpuacct.id

edit

type: keyword

ID of the cgroup.

system.process.cgroup.cpuacct.path

edit

type: keyword

Path to the cgroup relative to the cgroup subsystem’s mountpoint.

system.process.cgroup.cpuacct.total.ns

edit

type: long

Total CPU time in nanoseconds consumed by all tasks in the cgroup.

system.process.cgroup.cpuacct.stats.user.ns

edit

type: long

CPU time consumed by tasks in user mode.

system.process.cgroup.cpuacct.stats.system.ns

edit

type: long

CPU time consumed by tasks in user (kernel) mode.

system.process.cgroup.cpuacct.percpu

edit

type: dict

CPU time (in nanoseconds) consumed on each CPU by all tasks in this cgroup.

memory Fields

edit

Memory limits and metrics.

system.process.cgroup.memory.id

edit

type: keyword

ID of the cgroup.

system.process.cgroup.memory.path

edit

type: keyword

Path to the cgroup relative to the cgroup subsystem’s mountpoint.

system.process.cgroup.memory.mem.usage.bytes

edit

type: long

format: bytes

Total memory usage by processes in the cgroup (in bytes).

system.process.cgroup.memory.mem.usage.max.bytes

edit

type: long

format: bytes

The maximum memory used by processes in the cgroup (in bytes).

system.process.cgroup.memory.mem.limit.bytes

edit

type: long

format: bytes

The maximum amount of user memory in bytes (including file cache) that tasks in the cgroup are allowed to use.

system.process.cgroup.memory.mem.failures

edit

type: long

The number of times that the memory limit (mem.limit.bytes) was reached.

system.process.cgroup.memory.memsw.usage.bytes

edit

type: long

format: bytes

The sum of current memory usage plus swap space used by processes in the cgroup (in bytes).

system.process.cgroup.memory.memsw.usage.max.bytes

edit

type: long

format: bytes

The maximum amount of memory and swap space used by processes in the cgroup (in bytes).

system.process.cgroup.memory.memsw.limit.bytes

edit

type: long

format: bytes

The maximum amount for the sum of memory and swap usage that tasks in the cgroup are allowed to use.

system.process.cgroup.memory.memsw.failures

edit

type: long

The number of times that the memory plus swap space limit (memsw.limit.bytes) was reached.

system.process.cgroup.memory.kmem.usage.bytes

edit

type: long

format: bytes

Total kernel memory usage by processes in the cgroup (in bytes).

system.process.cgroup.memory.kmem.usage.max.bytes

edit

type: long

format: bytes

The maximum kernel memory used by processes in the cgroup (in bytes).

system.process.cgroup.memory.kmem.limit.bytes

edit

type: long

format: bytes

The maximum amount of kernel memory that tasks in the cgroup are allowed to use.

system.process.cgroup.memory.kmem.failures

edit

type: long

The number of times that the memory limit (kmem.limit.bytes) was reached.

system.process.cgroup.memory.kmem_tcp.usage.bytes

edit

type: long

format: bytes

Total memory usage for TCP buffers in bytes.

system.process.cgroup.memory.kmem_tcp.usage.max.bytes

edit

type: long

format: bytes

The maximum memory used for TCP buffers by processes in the cgroup (in bytes).

system.process.cgroup.memory.kmem_tcp.limit.bytes

edit

type: long

format: bytes

The maximum amount of memory for TCP buffers that tasks in the cgroup are allowed to use.

system.process.cgroup.memory.kmem_tcp.failures

edit

type: long

The number of times that the memory limit (kmem_tcp.limit.bytes) was reached.

system.process.cgroup.memory.stats.active_anon.bytes

edit

type: long

format: bytes

Anonymous and swap cache on active least-recently-used (LRU) list, including tmpfs (shmem), in bytes.

system.process.cgroup.memory.stats.active_file.bytes

edit

type: long

format: bytes

File-backed memory on active LRU list, in bytes.

system.process.cgroup.memory.stats.cache.bytes

edit

type: long

format: bytes

Page cache, including tmpfs (shmem), in bytes.

system.process.cgroup.memory.stats.hierarchical_memory_limit.bytes

edit

type: long

format: bytes

Memory limit for the hierarchy that contains the memory cgroup, in bytes.

system.process.cgroup.memory.stats.hierarchical_memsw_limit.bytes

edit

type: long

format: bytes

Memory plus swap limit for the hierarchy that contains the memory cgroup, in bytes.

system.process.cgroup.memory.stats.inactive_anon.bytes

edit

type: long

format: bytes

Anonymous and swap cache on inactive LRU list, including tmpfs (shmem), in bytes

system.process.cgroup.memory.stats.inactive_file.bytes

edit

type: long

format: bytes

File-backed memory on inactive LRU list, in bytes.

system.process.cgroup.memory.stats.mapped_file.bytes

edit

type: long

format: bytes

Size of memory-mapped mapped files, including tmpfs (shmem), in bytes.

system.process.cgroup.memory.stats.page_faults

edit

type: long

Number of times that a process in the cgroup triggered a page fault.

system.process.cgroup.memory.stats.major_page_faults

edit

type: long

Number of times that a process in the cgroup triggered a major fault. "Major" faults happen when the kernel actually has to read the data from disk.

system.process.cgroup.memory.stats.pages_in

edit

type: long

Number of pages paged into memory. This is a counter.

system.process.cgroup.memory.stats.pages_out

edit

type: long

Number of pages paged out of memory. This is a counter.

system.process.cgroup.memory.stats.rss.bytes

edit

type: long

format: bytes

Anonymous and swap cache (includes transparent hugepages), not including tmpfs (shmem), in bytes.

system.process.cgroup.memory.stats.rss_huge.bytes

edit

type: long

format: bytes

Number of bytes of anonymous transparent hugepages.

system.process.cgroup.memory.stats.swap.bytes

edit

type: long

format: bytes

Swap usage, in bytes.

system.process.cgroup.memory.stats.unevictable.bytes

edit

type: long

format: bytes

Memory that cannot be reclaimed, in bytes.

blkio Fields

edit

Block IO metrics.

system.process.cgroup.blkio.id

edit

type: keyword

ID of the cgroup.

system.process.cgroup.blkio.path

edit

type: keyword

Path to the cgroup relative to the cgroup subsystems mountpoint.

system.process.cgroup.blkio.total.bytes

edit

type: long

format: bytes

Total number of bytes transferred to and from all block devices by processes in the cgroup.

system.process.cgroup.blkio.total.ios

edit

type: long

Total number of I/O operations performed on all devices by processes in the cgroup as seen by the throttling policy.

socket Fields

edit

TCP sockets that are active.

system.socket.direction

edit

type: keyword

example: incoming

How the socket was initiated. Possible values are incoming, outgoing, or listening.

system.socket.family

edit

type: keyword

example: ipv4

Address family.

system.socket.local.ip

edit

type: ip

example: 192.0.2.1 or 2001:0DB8:ABED:8536::1

Local IP address. This can be an IPv4 or IPv6 address.

system.socket.local.port

edit

type: long

example: 22

Local port.

system.socket.remote.ip

edit

type: ip

example: 192.0.2.1 or 2001:0DB8:ABED:8536::1

Remote IP address. This can be an IPv4 or IPv6 address.

system.socket.remote.port

edit

type: long

example: 22

Remote port.

system.socket.remote.host

edit

type: keyword

example: 76-211-117-36.nw.example.com.

PTR record associated with the remote IP. It is obtained via reverse IP lookup.

system.socket.remote.etld_plus_one

edit

type: keyword

example: example.com.

The effective top-level domain (eTLD) of the remote host plus one more label. For example, the eTLD+1 for "foo.bar.golang.org." is "golang.org.". The data for determining the eTLD comes from an embedded copy of the data from http://publicsuffix.org.

system.socket.remote.host_error

edit

type: keyword

Error describing the cause of the reverse lookup failure.

system.socket.process.pid

edit

type: long

ID of the process that opened the socket.

system.socket.process.command

edit

type: keyword

Name of the command (limited to 20 chars by the OS).

system.socket.process.cmdline

edit

type: keyword

system.socket.process.exe

edit

type: keyword

Absolute path to the executable.

system.socket.user.id

edit

type: long

UID of the user running the process.

system.socket.user.name

edit

type: keyword

Name of the user running the process.