Docs
  • Release notes
  • Troubleshoot
  • Reference
  • Get started
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account and preferences
  • Troubleshoot
  • Extend and contribute
  • Release notes
  • Security
    • Fields and object schemas
      • Elastic Security ECS field reference
      • Timeline schema
      • Alert schema
    • Endpoint command reference
    • Detection Rules Overview
  • Observability
    • Fields and object schemas
  • Elasticsearch and index management
    • Configuration
      • Circuit breaker settings
      • Auditing settings
      • Enrich settings
      • Cluster-level shard allocation and routing settings
      • Miscellaneous cluster settings
      • Cross-cluster replication settings
      • Discovery and cluster formation settings
      • Field data cache settings
      • Health Diagnostic settings
      • Index lifecycle management settings
      • Data stream lifecycle settings
      • Index management settings
      • Index recovery settings
      • Indexing buffer settings
      • License settings
      • Local gateway
      • Machine learning settings
      • Inference settings
      • Monitoring settings
      • Node settings
      • Networking settings
      • Node query cache settings
      • Search settings
      • Security settings
      • Shard request cache
      • Snapshot and restore settings
      • Transforms settings
      • Thread pool settings
      • Watcher settings
    • JVM settings
    • Roles
    • Elasticsearch privileges
    • Index settings
      • Data tier allocation
      • General
      • History retention
      • Index block
      • Index recovery prioritization
      • Indexing pressure
      • Mapping limit
      • Merge
      • Path
      • Shard allocation
        • Total shards per node
      • Similarity
      • Slow log
      • Sorting
        • Use index sorting to speed up conjunctions
      • Store
        • Preloading data into the file system cache
      • Time series
      • Translog
    • Index lifecycle actions
      • Allocate
      • Delete
      • Force merge
      • Migrate
      • Read only
      • Rollover
      • Downsample
      • Searchable snapshot
      • Set priority
      • Shrink
      • Unfollow
      • Wait for snapshot
    • REST APIs
      • API conventions
      • Common options
      • Compatibility
      • API examples
        • The refresh parameter
        • Optimistic concurrency control
        • Sort search results
        • Paginate search results
        • Retrieve selected fields
        • Search multiple data streams and indices
        • Collapse search results
        • Filter search results
        • Highlighting
        • Retrieve inner hits
        • Search shard routing
        • Searching with query rules
        • Reciprocal rank fusion
        • Retrievers
        • Reindex data stream
        • Create index from source
        • The shard request cache
        • Suggesters
        • Profile search requests
        • Ranking evaluation
    • Mapping
      • Document metadata fields
        • _doc_count field
        • _field_names field
        • _ignored field
        • _id field
        • _index field
        • _meta field
        • _routing field
        • _source field
        • _tier field
      • Field data types
        • Aggregate metric
        • Alias
        • Arrays
        • Binary
        • Boolean
        • Completion
        • Date
        • Date nanoseconds
        • Dense vector
        • Flattened
        • Geopoint
        • Geoshape
        • Histogram
        • IP
        • Join
        • Keyword
        • Nested
        • Numeric
        • Object
        • Pass-through object
        • Percolator
        • Point
        • Range
        • Rank feature
        • Rank features
        • Rank Vectors
        • Search-as-you-type
        • Semantic text
        • Shape
        • Sparse vector
        • Text
        • Token count
        • Unsigned long
        • Version
      • Mapping parameters
        • analyzer
        • coerce
        • copy_to
        • doc_values
        • dynamic
        • eager_global_ordinals
        • enabled
        • format
        • ignore_above
        • index.mapping.ignore_above
        • ignore_malformed
        • index
        • index_options
        • index_phrases
        • index_prefixes
        • meta
        • fields
        • normalizer
        • norms
        • null_value
        • position_increment_gap
        • properties
        • search_analyzer
        • similarity
        • store
        • subobjects
        • term_vector
    • Elasticsearch audit events
    • Command line tools
      • elasticsearch-certgen
      • elasticsearch-certutil
      • elasticsearch-create-enrollment-token
      • elasticsearch-croneval
      • elasticsearch-keystore
      • elasticsearch-node
      • elasticsearch-reconfigure-node
      • elasticsearch-reset-password
      • elasticsearch-saml-metadata
      • elasticsearch-service-tokens
      • elasticsearch-setup-passwords
      • elasticsearch-shard
      • elasticsearch-syskeygen
      • elasticsearch-users
    • Curator
      • Curator and index lifecycle management
        • ILM Actions
        • ILM or Curator?
        • ILM and Curator!
      • About
        • Origin
        • Features
        • Command-Line Interface (CLI)
        • Application Program Interface (API)
        • License
        • Site Corrections
        • Contributing
      • Installation
        • pip
        • Installation from source
        • Docker
      • Running Curator
        • Command Line Interface
        • Singleton Command Line Interface
        • Exit Codes
      • Configuration
        • Environment Variables
        • Action File
        • Configuration File
      • Actions
        • Alias
        • Allocation
        • Close
        • Cluster Routing
        • Cold2Frozen
        • Create Index
        • Delete Indices
        • Delete Snapshots
        • Forcemerge
        • Index Settings
        • Open
        • Reindex
        • Replicas
        • Restore
        • Rollover
        • Shrink
        • Snapshot
      • Options
        • allocation_type
        • allow_ilm_indices
        • continue_if_exception
        • copy_aliases
        • count
        • delay
        • delete_after
        • delete_aliases
        • skip_flush
        • disable_action
        • extra_settings
        • ignore_empty_list
        • ignore_unavailable
        • include_aliases
        • include_global_state
        • indices
        • key
        • max_age
        • max_docs
        • max_size
        • max_num_segments
        • max_wait
        • migration_prefix
        • migration_suffix
        • name
        • new_index
        • node_filters
        • number_of_replicas
        • number_of_shards
        • partial
        • post_allocation
        • preserve_existing
        • refresh
        • remote_certificate
        • remote_client_cert
        • remote_client_key
        • remote_filters
        • remote_url_prefix
        • rename_pattern
        • rename_replacement
        • repository
        • requests_per_second
        • request_body
        • retry_count
        • retry_interval
        • routing_type
        • search_pattern
        • setting
        • shrink_node
        • shrink_prefix
        • shrink_suffix
        • slices
        • skip_repo_fs_check
        • timeout
        • timeout_override
        • value
        • wait_for_active_shards
        • wait_for_completion
        • wait_for_rebalance
        • wait_interval
        • warn_if_no_indices
      • Filters
        • filtertype
        • age
        • alias
        • allocated
        • closed
        • count
        • empty
        • forcemerged
        • kibana
        • none
        • opened
        • pattern
        • period
        • space
        • state
      • Filter Elements
        • aliases
        • allocation_type
        • count
        • date_from
        • date_from_format
        • date_to
        • date_to_format
        • direction
        • disk_space
        • epoch
        • exclude
        • field
        • intersect
        • key
        • kind
        • max_num_segments
        • pattern
        • period_type
        • range_from
        • range_to
        • reverse
        • source
        • state
        • stats_result
        • timestring
        • threshold_behavior
        • unit
        • unit_count
        • unit_count_pattern
        • use_age
        • value
        • week_starts_on
      • Examples
        • alias
        • allocation
        • close
        • cluster_routing
        • create_index
        • delete_indices
        • delete_snapshots
        • forcemerge
        • index_settings
        • open
        • reindex
        • replicas
        • restore
        • rollover
        • shrink
        • snapshot
      • Frequently Asked Questions
        • Q: How can I report an error in the documentation?
        • Q: Can I delete only certain data from within indices?
        • Q: Can Curator handle index names with strange characters?
    • Clients
      • Eland
        • Installation
        • Data Frames
        • Machine Learning
      • Go
        • Getting started
        • Installation
        • Connecting
        • Typed API
          • Getting started with the API
          • Conventions
          • Running queries
          • Using ES|QL
          • Examples
      • Java
        • Getting started
        • Setup
          • Installation
          • Connecting
          • Using OpenTelemetry
        • API conventions
          • Package structure and namespace clients
          • Method naming conventions
          • Blocking and asynchronous clients
          • Building API objects
          • Lists and maps
          • Variant types
          • Object life cycles and thread safety
          • Creating API objects from JSON data
          • Exceptions
        • Using the Java API client
          • Indexing single documents
          • Bulk: indexing multiple documents
          • Reading documents by id
          • Searching for documents
          • Aggregations
          • ES|QL in the Java client
        • Troubleshooting
          • Missing required property
          • NoSuchMethodError: removeHeader
          • IOReactor errors
          • Serializing without typed keys
          • Could not resolve dependencies
          • NoClassDefFoundError: LogFactory
        • Transport layer
          • REST 5 Client
            • Getting started
              • Initialization
              • Performing requests
              • Reading responses
              • Logging
            • Common configuration
              • Timeouts
              • Number of threads
              • Basic authentication
              • Other authentication methods
              • Encrypted communication
              • Others
              • Node selector
            • Sniffer
          • Legacy REST Client
            • Getting started
              • Javadoc
              • Maven Repository
              • Dependencies
              • Shading
              • Initialization
              • Performing requests
              • Reading responses
              • Logging
            • Common configuration
              • Timeouts
              • Number of threads
              • Basic authentication
              • Other authentication methods
              • Encrypted communication
              • Others
              • Node selector
            • Sniffer
              • Javadoc
              • Maven Repository
              • Usage
        • Javadoc and source code
        • External resources
        • Breaking changes policy
        • Release highlights
        • License
      • JavaScript
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Basic configuration
          • Advanced configuration
          • Creating a child client
          • Testing
        • Integrations
          • Observability
          • Transport
          • TypeScript support
        • API Reference
        • Examples
          • asStream
          • Bulk
          • Exists
          • Get
          • Ignore
          • MSearch
          • Scroll
          • Search
          • Suggest
          • transport.request
          • SQL
          • Update
          • Update By Query
          • Reindex
        • Client helpers
        • Timeout best practices
      • .NET
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Options on ElasticsearchClientSettings
        • Client concepts
          • Serialization
            • Source serialization
        • Using the .NET Client
          • Aggregation examples
          • Using ES|QL
          • CRUD usage examples
          • Custom mapping examples
          • Query examples
          • Usage recommendations
          • Low level Transport example
        • Troubleshoot
          • Logging
            • Logging with OnRequestCompleted
            • Logging with Fiddler
          • Debugging
            • Audit trail
            • Debug information
            • Debug mode
      • PHP
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Dealing with JSON arrays and objects in PHP
          • Host Configuration
          • Set retries
          • HTTP Meta Data
          • Enabling the Logger
          • Configure the HTTP client
          • Namespaces
          • Node Pool
        • Operations
          • Index management operations
          • Search operations
          • Indexing documents
          • Getting documents
          • Updating documents
          • Deleting documents
        • Client helpers
          • Iterators
          • ES|QL
      • Python
        • Getting started
        • Installation
        • Connecting
        • Configuration
        • Querying
        • Using with asyncio
        • Integrations
          • Using OpenTelemetry
          • ES|QL and Pandas
        • Examples
        • Elasticsearch Python DSL
          • Configuration
          • Tutorials
          • How-To Guides
          • Examples
          • Migrating from the elasticsearch-dsl package
        • Client helpers
      • Ruby
        • Getting started
        • Installation
        • Connecting
        • Configuration
          • Basic configuration
          • Advanced configuration
        • Integrations
          • Transport
          • Elasticsearch API
          • Using OpenTelemetry
          • Elastic Common Schema (ECS)
          • ActiveModel / ActiveRecord
          • Ruby On Rails
          • Persistence
          • Elasticsearch DSL
        • Examples
        • Client helpers
          • Bulk and Scroll helpers
          • ES|QL
        • Troubleshoot
      • Rust
        • Installation
      • Community-contributed clients
  • Elastic Distributions of OpenTelemetry (EDOT)
    • Quickstart
      • Self-managed
        • Kubernetes
        • Hosts / VMs
        • Docker
      • Elastic Cloud Serverless
        • Kubernetes
        • Hosts and VMs
        • Docker
      • Elastic Cloud Hosted
        • Kubernetes
        • Hosts and VMs
        • Docker
    • Reference Architecture
      • Kubernetes environments
      • Hosts / VMs environments
    • Use cases
      • Kubernetes observability
        • Prerequisites and compatibility
        • Components description
        • Deployment
        • Instrumenting Applications
        • Upgrade
        • Customization
      • LLM observability
    • Compatibility and support
      • Features
      • Collector distributions
      • SDK Distributions
      • Limitations
      • Nomenclature
    • EDOT Collector
      • Download
      • Configuration
        • Default config (Standalone)
        • Default config (Kubernetes)
        • Configure Logs Collection
        • Configure Metrics Collection
      • Customization
        • Components
        • Custom Collector
      • Troubleshooting
    • EDOT SDKs
      • EDOT .NET
        • Setup
          • ASP.NET
          • Console applications
          • .NET worker services
          • Zero-code instrumentation
          • Opinionated defaults
        • Configuration
        • Supported technologies
        • Troubleshooting
        • Migration
      • EDOT Java
        • Setup
          • Kubernetes Setup
          • Runtime attach Setup
        • Configuration
        • Features
        • Supported Technologies
        • Troubleshooting
        • Migration
        • Performance overhead
      • EDOT Node.js
        • Setup
          • Kubernetes
        • Configuration
        • Supported Technologies
        • Metrics
        • Troubleshooting
        • Migration
      • EDOT PHP
        • Setup
          • Limitations
        • Configuration
        • Supported Technologies
        • Troubleshooting
        • Migration
        • Performance overhead
      • EDOT Python
        • Setup
          • Kubernetes
          • Manual Instrumentation
        • Configuration
        • Supported Technologies
        • Troubleshooting
        • Migration
        • Performance Overhead
  • Ingestion tools
    • Fleet and Elastic Agent
      • Restrictions for Elastic Cloud Serverless
      • Migrate from Beats to Elastic Agent
        • Migrate from Auditbeat to Elastic Agent
      • Deployment models
        • What is Fleet Server?
        • Deploy on Elastic Cloud
        • Deploy on-premises and self-managed
        • Deploy Fleet Server on-premises and Elasticsearch on Cloud
        • Deploy Fleet Server on Kubernetes
        • Fleet Server scalability
        • Fleet Server Secrets
          • Secret files guide
        • Monitor a self-managed Fleet Server
      • Install Elastic Agents
        • Install Fleet-managed Elastic Agents
        • Install standalone Elastic Agents
          • Upgrade standalone Elastic Agents
        • Install Elastic Agents in a containerized environment
          • Run Elastic Agent in a container
          • Run Elastic Agent on Kubernetes managed by Fleet
          • Install Elastic Agent on Kubernetes using Helm
            • Example: Install standalone Elastic Agent on Kubernetes using Helm
            • Example: Install Fleet-managed Elastic Agent on Kubernetes using Helm
          • Advanced Elastic Agent configuration managed by Fleet
          • Configuring Kubernetes metadata enrichment on Elastic Agent
          • Run Elastic Agent on GKE managed by Fleet
          • Configure Elastic Agent Add-On on Amazon EKS
          • Run Elastic Agent on Azure AKS managed by Fleet
          • Run Elastic Agent Standalone on Kubernetes
          • Scaling Elastic Agent on Kubernetes
          • Using a custom ingest pipeline with the Kubernetes Integration
          • Environment variables
        • Run Elastic Agent as an EDOT Collector
        • Transform an installed Elastic Agent to run as an EDOT Collector
        • Run Elastic Agent without administrative privileges
        • Install Elastic Agent from an MSI package
        • Installation layout
        • Air-gapped environments
        • Using a proxy server with Elastic Agent and Fleet
          • When to configure proxy settings
          • Proxy Server connectivity using default host variables
          • Fleet managed Elastic Agent connectivity using a proxy server
          • Standalone Elastic Agent connectivity using a proxy server
          • Set the proxy URL of the Elastic Package Registry
        • Uninstall Elastic Agents from edge hosts
        • Start and stop Elastic Agents on edge hosts
        • Elastic Agent configuration encryption
      • Secure connections
        • Configure SSL/TLS for self-managed Fleet Servers
        • Rotate SSL/TLS CA certificates
        • Elastic Agent deployment models with mutual TLS
        • One-way and mutual TLS certifications flow
        • Configure SSL/TLS for the Logstash output
      • Manage Elastic Agents in Fleet
        • Fleet settings
          • Elasticsearch output settings
          • Logstash output settings
          • Kafka output settings
          • Remote Elasticsearch output
          • Considerations when changing outputs
        • Elastic Agents
          • Unenroll Elastic Agents
          • Set inactivity timeout
          • Upgrade Elastic Agents
          • Migrate Elastic Agents
          • Monitor Elastic Agents
          • Elastic Agent health status
          • Add tags to filter the Agents list
          • Enrollment handing for containerized agents
        • Policies
          • Create an agent policy without using the UI
          • Enable custom settings in an agent policy
          • Set environment variables in an Elastic Agent policy
        • Required roles and privileges
        • Fleet enrollment tokens
        • Kibana Fleet APIs
      • Configure standalone Elastic Agents
        • Create a standalone Elastic Agent policy
        • Structure of a config file
        • Inputs
          • Simplified log ingestion
          • Elastic Agent inputs
          • Variables and conditions in input configurations
        • Providers
          • Local
          • Agent provider
          • Host provider
          • Env Provider
          • Filesource provider
          • Kubernetes Secrets Provider
          • Kubernetes LeaderElection Provider
          • Local dynamic provider
          • Docker Provider
          • Kubernetes Provider
        • Outputs
          • Elasticsearch
          • Kafka
          • Logstash
        • SSL/TLS
        • Logging
        • Feature flags
        • Agent download
        • Config file examples
          • Apache HTTP Server
          • Nginx HTTP Server
        • Grant standalone Elastic Agents access to Elasticsearch
        • Example: Use standalone Elastic Agent with Elastic Cloud Serverless to monitor nginx
        • Example: Use standalone Elastic Agent with Elastic Cloud Hosted to monitor nginx
        • Debug standalone Elastic Agents
        • Kubernetes autodiscovery with Elastic Agent
          • Conditions based autodiscover
          • Hints annotations based autodiscover
        • Monitoring
        • Reference YAML
      • Manage integrations
        • Package signatures
        • Add an integration to an Elastic Agent policy
        • View integration policies
        • Edit or delete an integration policy
        • Install and uninstall integration assets
        • View integration assets
        • Set integration-level outputs
        • Upgrade an integration
        • Managed integrations content
        • Best practices for integration assets
        • Data streams
          • Tutorials: Customize data retention policies
          • Scenario 1
          • Scenario 2
          • Scenario 3
          • Tutorial: Transform data with custom ingest pipelines
          • Advanced data stream features
      • Command reference
      • Agent processors
        • Processor syntax
        • add_cloud_metadata
        • add_cloudfoundry_metadata
        • add_docker_metadata
        • add_fields
        • add_host_metadata
        • add_id
        • add_kubernetes_metadata
        • add_labels
        • add_locale
        • add_network_direction
        • add_nomad_metadata
        • add_observer_metadata
        • add_process_metadata
        • add_tags
        • community_id
        • convert
        • copy_fields
        • decode_base64_field
        • decode_cef
        • decode_csv_fields
        • decode_duration
        • decode_json_fields
        • decode_xml
        • decode_xml_wineventlog
        • decompress_gzip_field
        • detect_mime_type
        • dissect
        • dns
        • drop_event
        • drop_fields
        • extract_array
        • fingerprint
        • include_fields
        • move_fields
        • parse_aws_vpc_flow_log
        • rate_limit
        • registered_domain
        • rename
        • replace
        • script
        • syslog
        • timestamp
        • translate_sid
        • truncate_fields
        • urldecode
    • APM
      • APM settings
      • APM settings for Elastic Cloud
      • APM settings for Elastic Cloud Enterprise
      • APM Attacher for Kubernetes
        • Instrument and configure pods
          • Add the helm repository to Helm
          • Configure the webhook with a Helm values file
          • Install the webhook with Helm
          • Add a pod template annotation to each pod you want to auto-instrument
          • Watch data flow into the Elastic Stack
      • APM Architecture for AWS Lambda
        • Performance impact and overhead
        • Configuration options
        • Using AWS Secrets Manager to manage APM authentication keys
      • APM agents
        • APM Android agent
          • Getting started
          • Configuration
          • Manual instrumentation
          • Automatic instrumentation
          • Frequently asked questions
          • How-tos
          • Troubleshooting
        • APM .NET agent
          • Set up the APM .NET agent
            • Profiler Auto instrumentation
            • ASP.NET Core
            • .NET Core and .NET 5+
            • ASP.NET
            • Azure Functions
            • Other .NET applications
          • NuGet packages
            • Entity Framework Core
            • Entity Framework 6
            • Elasticsearch
            • gRPC
            • SqlClient
            • StackExchange.Redis
            • Azure Cosmos DB
            • Azure Service Bus
            • Azure Storage
            • MongoDB
          • Supported technologies
          • Configuration
            • Configuration on ASP.NET Core
            • Configuration for Windows Services
            • Configuration on ASP.NET
            • Core configuration options
            • Reporter configuration options
            • HTTP configuration options
            • Messaging configuration options
            • Stacktrace configuration options
            • Supportability configuration options
            • All options summary
          • Public API
          • OpenTelemetry bridge
          • Metrics
          • Logs
            • Serilog
            • NLog
            • Manual log correlation
          • Performance tuning
          • Upgrading
        • APM Go agent
          • Set up the APM Go Agent
            • Built-in instrumentation modules
            • Custom instrumentation
            • Context propagation
          • Supported technologies
          • Configuration
          • API documentation
          • Metrics
          • Logs
          • Log correlation
          • OpenTelemetry API
          • OpenTracing API
          • Contributing
          • Upgrading
        • APM iOS agent
          • Supported technologies
          • Set up the APM iOS Agent
          • Configuration
          • Instrumentation
        • APM Java agent
          • Set up the APM Java Agent
            • Manual setup with -javaagent flag
            • Automatic setup with apm-agent-attach-cli.jar
            • Programmatic API setup to self-attach
            • SSL/TLS communication with APM Server
            • Monitoring AWS Lambda Java Functions
          • Supported technologies
          • Configuration
            • Circuit-Breaker
            • Core
            • Datastore
            • HTTP
            • Huge Traces
            • JAX-RS
            • JMX
            • Logging
            • Messaging
            • Metrics
            • Profiling
            • Reporter
            • Serverless
            • Stacktrace
            • Property file reference
          • Tracing APIs
            • Public API
            • OpenTelemetry bridge
            • OpenTracing bridge
          • Plugin API
          • Metrics
          • Logs
          • How to find slow methods
            • Sampling-based profiler
            • API/Code
            • Annotations
            • Configuration-based
          • Overhead and performance tuning
          • Frequently asked questions
          • Community plugins
          • Upgrading
        • APM Node.js agent
          • Set up the Agent
            • Monitoring AWS Lambda Node.js Functions
            • Monitoring Node.js Azure Functions
            • Get started with Express
            • Get started with Fastify
            • Get started with hapi
            • Get started with Koa
            • Get started with Next.js
            • Get started with Restify
            • Get started with TypeScript
            • Get started with a custom Node.js stack
            • Starting the agent
          • Supported technologies
          • Configuration
            • Configuring the agent
            • Configuration options
            • Custom transactions
            • Custom spans
          • API Reference
            • Agent API
            • Transaction API
            • Span API
          • Metrics
          • Logs
          • OpenTelemetry bridge
          • OpenTracing bridge
          • Source map support
          • ECMAScript module support
          • Distributed tracing
          • Message queues
          • Performance Tuning
          • Upgrading
            • Upgrade to v4.x
            • Upgrade to v3.x
            • Upgrade to v2.x
            • Upgrade to v1.x
        • APM PHP agent
          • Set up the APM PHP Agent
          • Supported technologies
          • Configuration
            • Configuration reference
          • Public API
        • APM Python agent
          • Set up the APM Python Agent
            • Django support
            • Flask support
            • Aiohttp Server support
            • Tornado Support
            • Starlette/FastAPI Support
            • Sanic Support
            • Monitoring AWS Lambda Python Functions
            • Monitoring Azure Functions
            • Wrapper Support
            • ASGI Middleware
          • Supported technologies
          • Configuration
          • Advanced topics
            • Instrumenting custom code
            • Sanitizing data
            • How the Agent works
            • Run Tests Locally
          • API reference
          • Metrics
          • OpenTelemetry API Bridge
          • Logs
          • Performance tuning
          • Upgrading
            • Upgrading to version 6 of the agent
            • Upgrading to version 5 of the agent
            • Upgrading to version 4 of the agent
        • APM Ruby agent
          • Set up the APM Ruby agent
            • Getting started with Rails
            • Getting started with Rack
          • Supported technologies
          • Configuration
          • Advanced topics
            • Adding additional context
            • Custom instrumentation
          • API reference
          • Metrics
          • Logs
          • OpenTracing API
          • GraphQL
          • Performance tuning
          • Upgrading
        • APM RUM JavaScript agent
          • Set up the APM Real User Monitoring JavaScript Agent
            • Install the Agent
            • Configure CORS
          • Supported technologies
          • Configuration
          • API reference
            • Agent API
            • Transaction API
            • Span API
          • Source maps
          • Framework-specific integrations
            • React integration
            • Angular integration
            • Vue integration
          • Distributed tracing
          • Breakdown metrics
          • OpenTracing
          • Advanced topics
            • How to interpret long task spans in the UI
            • Using with TypeScript
            • Custom page load transaction names
            • Custom Transactions
          • Performance tuning
          • Upgrading
    • Beats
      • Beats
      • Config file format
        • Namespacing
        • Config file data types
        • Environment variables
        • Reference variables
        • Config file ownership and permissions
        • Command line arguments
        • YAML tips and gotchas
      • Auditbeat
        • Quick start
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Auditbeat on Docker
          • Running Auditbeat on Kubernetes
          • Auditbeat and systemd
          • Start Auditbeat
          • Stop Auditbeat
        • Upgrade Auditbeat
        • Configure
          • Modules
          • General settings
          • Project paths
          • Config file reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_session_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • rate_limit
            • registered_domain
            • rename
            • replace
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • auditbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Parse data using an ingest pipeline
          • Use environment variables in the configuration
          • Avoid YAML formatting problems
        • Modules
          • Auditd Module
          • File Integrity Module
          • System Module
            • System host dataset
            • System login dataset
            • System package dataset
            • System process dataset
            • System socket dataset
            • System user dataset
        • Exported fields
          • Auditd fields
          • Beat fields
          • Cloud provider metadata fields
          • Common fields
          • Docker fields
          • ECS fields
          • File Integrity fields
          • Host fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • Process fields
          • System fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get Help
          • Debug
          • Understand logged metrics
          • Common problems
            • Auditbeat fails to watch folders because too many files are open
            • Auditbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
        • Contribute
      • Filebeat
        • Quick start
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Filebeat on Docker
          • Run Filebeat on Kubernetes
          • Run Filebeat on Cloud Foundry
          • Filebeat and systemd
          • Start Filebeat
          • Stop Filebeat
        • Upgrade
        • How Filebeat works
        • Configure
          • Inputs
            • Multiline messages
            • AWS CloudWatch
            • AWS S3
            • Azure Event Hub
            • Azure Blob Storage
            • Benchmark
            • CEL
            • Cloud Foundry
            • CometD
            • Container
            • Entity Analytics
            • ETW
            • filestream
            • GCP Pub/Sub
            • Google Cloud Storage
            • HTTP Endpoint
            • HTTP JSON
            • journald
            • Kafka
            • Log
            • MQTT
            • NetFlow
            • Office 365 Management Activity API
            • Redis
            • Salesforce
            • Stdin
            • Streaming
            • Syslog
            • TCP
            • UDP
            • Unified Logs
            • Unix
            • winlog
          • Modules
            • Override input settings
          • General settings
          • Project paths
          • Config file loading
            • Live reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • cache
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_cef
            • decode_csv_fields
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • parse_aws_vpc_flow_log
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • timestamp
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • filebeat.reference.yml
        • How to guides
          • Override configuration settings
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Load ingest pipelines
          • Enrich events with geoIP information
          • Deduplicate data
          • Parse data using an ingest pipeline
          • Use environment variables in the configuration
          • Avoid YAML formatting problems
          • Migrate log or container input configurations to filestream
          • How to choose file identity for filestream
          • Migrating from a Deprecated Filebeat Module
        • Modules
          • Modules
          • ActiveMQ module
          • Apache module
          • Auditd module
          • AWS module
          • AWS Fargate module
          • Azure module
          • CEF module
          • Check Point module
          • Cisco module
          • CoreDNS module
          • CrowdStrike module
          • Cyberark PAS module
          • Elasticsearch module
          • Envoyproxy Module
          • Fortinet module
          • Google Cloud module
          • Google Workspace module
          • HAproxy module
          • IBM MQ module
          • Icinga module
          • IIS module
          • Iptables module
          • Juniper module
          • Kafka module
          • Kibana module
          • Logstash module
          • Microsoft module
          • MISP module
          • MongoDB module
          • MSSQL module
          • MySQL module
          • MySQL Enterprise module
          • NATS module
          • NetFlow module
          • Nginx module
          • Office 365 module
          • Okta module
          • Oracle module
          • Osquery module
          • Palo Alto Networks module
          • pensando module
          • PostgreSQL module
          • RabbitMQ module
          • Redis module
          • Salesforce module
            • Set up the OAuth App in the Salesforce
          • Santa module
          • Snyk module
          • Sophos module
          • Suricata module
          • System module
          • Threat Intel module
          • Traefik module
          • Zeek (Bro) Module
          • ZooKeeper module
          • Zoom module
        • Exported fields
          • ActiveMQ fields
          • Apache fields
          • Auditd fields
          • AWS fields
          • AWS CloudWatch fields
          • AWS Fargate fields
          • Azure fields
          • Beat fields
          • Decode CEF processor fields fields
          • CEF fields
          • Checkpoint fields
          • Cisco fields
          • Cloud provider metadata fields
          • Coredns fields
          • Crowdstrike fields
          • CyberArk PAS fields
          • Docker fields
          • ECS fields
          • Elasticsearch fields
          • Envoyproxy fields
          • Fortinet fields
          • Google Cloud Platform (GCP) fields
          • google_workspace fields
          • HAProxy fields
          • Host fields
          • ibmmq fields
          • Icinga fields
          • IIS fields
          • iptables fields
          • Jolokia Discovery autodiscover provider fields
          • Juniper JUNOS fields
          • Kafka fields
          • kibana fields
          • Kubernetes fields
          • Log file content fields
          • logstash fields
          • Lumberjack fields
          • Microsoft fields
          • MISP fields
          • mongodb fields
          • mssql fields
          • MySQL fields
          • MySQL Enterprise fields
          • NATS fields
          • NetFlow fields
          • Nginx fields
          • Office 365 fields
          • Okta fields
          • Oracle fields
          • Osquery fields
          • panw fields
          • Pensando fields
          • PostgreSQL fields
          • Process fields
          • RabbitMQ fields
          • Redis fields
          • s3 fields
          • Salesforce fields
          • Google Santa fields
          • Snyk fields
          • sophos fields
          • Suricata fields
          • System fields
          • threatintel fields
          • Traefik fields
          • Windows ETW fields
          • Zeek fields
          • ZooKeeper fields
          • Zoom fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • Error extracting container id while using Kubernetes metadata
            • Can't read log files from network volumes
            • Filebeat isn't collecting lines from a file
            • Too many open file handlers
            • Registry file is too large
            • Inode reuse causes Filebeat to skip lines
            • Log rotation results in lost or duplicate events
            • Open file handlers cause issues with Windows file rotation
            • Filebeat is using too much CPU
            • Dashboard in Kibana is breaking up data fields incorrectly
            • Fields are not indexed or usable in Kibana visualizations
            • Filebeat isn't shipping the last line of a file
            • Filebeat keeps open file handlers of deleted files for a long time
            • Filebeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
        • Contribute
      • Heartbeat
        • Quick start
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Heartbeat on Docker
          • Running Heartbeat on Kubernetes
          • Heartbeat and systemd
          • Stop Heartbeat
        • Configure
          • Monitors
            • Common monitor options
            • ICMP options
            • TCP options
            • HTTP options
          • Task scheduler
          • General settings
          • Project paths
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • heartbeat.reference.yml
        • How to guides
          • Add observer and geo metadata
          • Load the Elasticsearch index template
          • Change the index name
          • Enrich events with geoIP information
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Exported fields
          • Beat fields
          • Synthetics browser metrics fields
          • Cloud provider metadata fields
          • Common heartbeat monitor fields
          • Docker fields
          • ECS fields
          • Host fields
          • HTTP monitor fields
          • ICMP fields
          • Jolokia Discovery autodiscover provider fields
          • Kubernetes fields
          • Process fields
          • Host lookup fields
          • APM Service fields
          • SOCKS5 proxy fields
          • Monitor state fields
          • Monitor summary fields
          • Synthetics types fields
          • TCP layer fields
          • TLS encryption layer fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • Heartbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • High RSS memory usage due to MADV settings
        • Contribute
      • Metricbeat
        • Quick start
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Metricbeat on Docker
          • Run Metricbeat on Kubernetes
          • Run Metricbeat on Cloud Foundry
          • Metricbeat and systemd
          • Start Metricbeat
          • Stop Metricbeat
        • Upgrade Metricbeat
        • How Metricbeat works
          • Event structure
          • Error event structure
          • Key metricbeat features
        • Configure
          • Modules
          • General settings
          • Project paths
          • Config file loading
            • Live reloading
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Autodiscover
            • Hints based autodiscover
            • Advanced usage
          • Internal queue
          • Logging
          • HTTP endpoint
          • Regular expression support
          • Instrumentation
          • Feature flags
          • metricbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems
        • Modules
          • ActiveMQ module
            • ActiveMQ broker metricset
            • ActiveMQ queue metricset
            • ActiveMQ topic metricset
          • Aerospike module
            • Aerospike namespace metricset
          • Airflow module
            • Airflow statsd metricset
          • Apache module
            • Apache status metricset
          • AWS module
            • AWS awshealth metricset
            • AWS billing metricset
            • AWS cloudwatch metricset
            • AWS dynamodb metricset
            • AWS ebs metricset
            • AWS ec2 metricset
            • AWS elb metricset
            • AWS kinesis metricset
            • AWS lambda metricset
            • AWS natgateway metricset
            • AWS rds metricset
            • AWS s3_daily_storage metricset
            • AWS s3_request metricset
            • AWS sns metricset
            • AWS sqs metricset
            • AWS transitgateway metricset
            • AWS usage metricset
            • AWS vpn metricset
          • AWS Fargate module
            • AWS Fargate task_stats metricset
          • Azure module
            • Azure app_insights metricset
            • Azure app_state metricset
            • Azure billing metricset
            • Azure compute_vm metricset
            • Azure compute_vm_scaleset metricset
            • Azure container_instance metricset
            • Azure container_registry metricset
            • Azure container_service metricset
            • Azure database_account metricset
            • Azure monitor metricset
            • Azure storage metricset
          • Beat module
            • Beat state metricset
            • Beat stats metricset
          • Benchmark module
            • Benchmark info metricset
          • Ceph module
            • Ceph cluster_disk metricset
            • Ceph cluster_health metricset
            • Ceph cluster_status metricset
            • Ceph mgr_cluster_disk metricset
            • Ceph mgr_cluster_health metricset
            • Ceph mgr_osd_perf metricset
            • Ceph mgr_osd_pool_stats metricset
            • Ceph mgr_osd_tree metricset
            • Ceph mgr_pool_disk metricset
            • Ceph monitor_health metricset
            • Ceph osd_df metricset
            • Ceph osd_tree metricset
            • Ceph pool_disk metricset
          • Cloudfoundry module
            • Cloudfoundry container metricset
            • Cloudfoundry counter metricset
            • Cloudfoundry value metricset
          • CockroachDB module
            • CockroachDB status metricset
          • Consul module
            • Consul agent metricset
          • Containerd module
            • Containerd blkio metricset
            • Containerd cpu metricset
            • Containerd memory metricset
          • Coredns module
            • Coredns stats metricset
          • Couchbase module
            • Couchbase bucket metricset
            • Couchbase cluster metricset
            • Couchbase node metricset
          • CouchDB module
            • CouchDB server metricset
          • Docker module
            • Docker container metricset
            • Docker cpu metricset
            • Docker diskio metricset
            • Docker event metricset
            • Docker healthcheck metricset
            • Docker image metricset
            • Docker info metricset
            • Docker memory metricset
            • Docker network metricset
            • Docker network_summary metricset
          • Dropwizard module
            • Dropwizard collector metricset
          • Elasticsearch module
            • Elasticsearch ccr metricset
            • Elasticsearch cluster_stats metricset
            • Elasticsearch enrich metricset
            • Elasticsearch index metricset
            • Elasticsearch index_recovery metricset
            • Elasticsearch index_summary metricset
            • Elasticsearch ingest_pipeline metricset
            • Elasticsearch ml_job metricset
            • Elasticsearch node metricset
            • Elasticsearch node_stats metricset
            • Elasticsearch pending_tasks metricset
            • Elasticsearch shard metricset
          • Envoyproxy module
            • Envoyproxy server metricset
          • Etcd module
            • Etcd leader metricset
            • Etcd metrics metricset
            • Etcd self metricset
            • Etcd store metricset
          • Google Cloud Platform module
            • Google Cloud Platform billing metricset
            • Google Cloud Platform carbon metricset
            • Google Cloud Platform compute metricset
            • Google Cloud Platform dataproc metricset
            • Google Cloud Platform firestore metricset
            • Google Cloud Platform gke metricset
            • Google Cloud Platform loadbalancing metricset
            • Google Cloud Platform metrics metricset
            • Google Cloud Platform pubsub metricset
            • Google Cloud Platform storage metricset
          • Golang module
            • Golang expvar metricset
            • Golang heap metricset
          • Graphite module
            • Graphite server metricset
          • HAProxy module
            • HAProxy info metricset
            • HAProxy stat metricset
          • HTTP module
            • HTTP json metricset
            • HTTP server metricset
          • IBM MQ module
            • IBM MQ qmgr metricset
          • IIS module
            • IIS application_pool metricset
            • IIS webserver metricset
            • IIS website metricset
          • Istio module
            • Istio citadel metricset
            • Istio galley metricset
            • Istio istiod metricset
            • Istio mesh metricset
            • Istio mixer metricset
            • Istio pilot metricset
            • Istio proxy metricset
          • Jolokia module
            • Jolokia jmx metricset
          • Kafka module
            • Kafka broker metricset
            • Kafka consumer metricset
            • Kafka consumergroup metricset
            • Kafka partition metricset
            • Kafka producer metricset
          • Kibana module
            • Kibana cluster_actions metricset
            • Kibana cluster_rules metricset
            • Kibana node_actions metricset
            • Kibana node_rules metricset
            • Kibana stats metricset
            • Kibana status metricset
          • Kubernetes module
            • Kubernetes apiserver metricset
            • Kubernetes container metricset
            • Kubernetes controllermanager metricset
            • Kubernetes event metricset
            • Kubernetes node metricset
            • Kubernetes pod metricset
            • Kubernetes proxy metricset
            • Kubernetes scheduler metricset
            • Kubernetes state_container metricset
            • Kubernetes state_cronjob metricset
            • Kubernetes state_daemonset metricset
            • Kubernetes state_deployment metricset
            • Kubernetes state_job metricset
            • Kubernetes state_node metricset
            • Kubernetes state_persistentvolumeclaim metricset
            • Kubernetes state_pod metricset
            • Kubernetes state_replicaset metricset
            • Kubernetes state_resourcequota metricset
            • Kubernetes state_service metricset
            • Kubernetes state_statefulset metricset
            • Kubernetes state_storageclass metricset
            • Kubernetes system metricset
            • Kubernetes volume metricset
          • KVM module
            • KVM dommemstat metricset
            • KVM status metricset
          • Linux module
            • Linux conntrack metricset
            • Linux iostat metricset
            • Linux ksm metricset
            • Linux memory metricset
            • Linux pageinfo metricset
            • Linux pressure metricset
            • Linux rapl metricset
          • Logstash module
            • Logstash node metricset
            • Logstash node_stats metricset
          • Memcached module
            • Memcached stats metricset
          • Cisco Meraki module
            • Cisco Meraki device_health metricset
          • MongoDB module
            • MongoDB collstats metricset
            • MongoDB dbstats metricset
            • MongoDB metrics metricset
            • MongoDB replstatus metricset
            • MongoDB status metricset
          • MSSQL module
            • MSSQL performance metricset
            • MSSQL transaction_log metricset
          • Munin module
            • Munin node metricset
          • MySQL module
            • MySQL galera_status metricset
            • galera status MetricSet
            • MySQL performance metricset
            • MySQL query metricset
            • MySQL status metricset
          • NATS module
            • NATS connection metricset
            • NATS connections metricset
            • NATS JetStream metricset
            • NATS route metricset
            • NATS routes metricset
            • NATS stats metricset
            • NATS subscriptions metricset
          • Nginx module
            • Nginx stubstatus metricset
          • openai module
            • openai usage metricset
          • Openmetrics module
            • Openmetrics collector metricset
          • Oracle module
            • Oracle performance metricset
            • Oracle sysmetric metricset
            • Oracle tablespace metricset
          • Panw module
            • Panw interfaces metricset
            • Panw routing metricset
            • Panw system metricset
            • Panw vpn metricset
          • PHP_FPM module
            • PHP_FPM pool metricset
            • PHP_FPM process metricset
          • PostgreSQL module
            • PostgreSQL activity metricset
            • PostgreSQL bgwriter metricset
            • PostgreSQL database metricset
            • PostgreSQL statement metricset
          • Prometheus module
            • Prometheus collector metricset
            • Prometheus query metricset
            • Prometheus remote_write metricset
          • RabbitMQ module
            • RabbitMQ connection metricset
            • RabbitMQ exchange metricset
            • RabbitMQ node metricset
            • RabbitMQ queue metricset
            • RabbitMQ shovel metricset
          • Redis module
            • Redis info metricset
            • Redis key metricset
            • Redis keyspace metricset
          • Redis Enterprise module
            • Redis Enterprise node metricset
            • Redis Enterprise proxy metricset
          • SQL module
            • Host Setup
            • SQL query metricset
          • Stan module
            • Stan channels metricset
            • Stan stats metricset
            • Stan subscriptions metricset
          • Statsd module
            • Metricsets
            • Statsd server metricset
          • SyncGateway module
            • SyncGateway db metricset
            • SyncGateway memory metricset
            • SyncGateway replication metricset
            • SyncGateway resources metricset
          • System module
            • System core metricset
            • System cpu metricset
            • System diskio metricset
            • System entropy metricset
            • System filesystem metricset
            • System fsstat metricset
            • System load metricset
            • System memory metricset
            • System network metricset
            • System network_summary metricset
            • System process metricset
            • System process_summary metricset
            • System raid metricset
            • System service metricset
            • System socket metricset
            • System socket_summary metricset
            • System uptime metricset
            • System users metricset
          • Tomcat module
            • Tomcat cache metricset
            • Tomcat memory metricset
            • Tomcat requests metricset
            • Tomcat threading metricset
          • Traefik module
            • Traefik health metricset
          • uWSGI module
            • uWSGI status metricset
          • vSphere module
            • vSphere cluster metricset
            • vSphere datastore metricset
            • vSphere datastorecluster metricset
            • vSphere host metricset
            • vSphere network metricset
            • vSphere resourcepool metricset
            • vSphere virtualmachine metricset
          • Windows module
            • Windows perfmon metricset
            • Windows service metricset
            • Windows wmi metricset
          • ZooKeeper module
            • ZooKeeper connection metricset
            • ZooKeeper mntr metricset
            • ZooKeeper server metricset
        • Exported fields
          • ActiveMQ fields
          • Aerospike fields
          • Airflow fields
          • Apache fields
          • AWS fields
          • AWS Fargate fields
          • Azure fields
          • Beat fields
          • Beat fields
          • Benchmark fields
          • Ceph fields
          • Cloud provider metadata fields
          • Cloudfoundry fields
          • CockroachDB fields
          • Common fields
          • Consul fields
          • Containerd fields
          • Coredns fields
          • Couchbase fields
          • CouchDB fields
          • Docker fields
          • Docker fields
          • Dropwizard fields
          • ECS fields
          • Elasticsearch fields
          • Envoyproxy fields
          • Etcd fields
          • Google Cloud Platform fields
          • Golang fields
          • Graphite fields
          • HAProxy fields
          • Host fields
          • HTTP fields
          • IBM MQ fields
          • IIS fields
          • Istio fields
          • Jolokia fields
          • Jolokia Discovery autodiscover provider fields
          • Kafka fields
          • Kibana fields
          • Kubernetes fields
          • Kubernetes fields
          • KVM fields
          • Linux fields
          • Logstash fields
          • Memcached fields
          • MongoDB fields
          • MSSQL fields
          • Munin fields
          • MySQL fields
          • NATS fields
          • Nginx fields
          • openai fields
          • Openmetrics fields
          • Oracle fields
          • Panw fields
          • PHP_FPM fields
          • PostgreSQL fields
          • Process fields
          • Prometheus fields
          • Prometheus typed metrics fields
          • RabbitMQ fields
          • Redis fields
          • Redis Enterprise fields
          • SQL fields
          • Stan fields
          • Statsd fields
          • SyncGateway fields
          • System fields
          • Tomcat fields
          • Traefik fields
          • uWSGI fields
          • vSphere fields
          • Windows fields
          • ZooKeeper fields
        • Monitor
          • Use internal collection
            • Settings for internal collection
          • Use Metricbeat collection
        • Secure
          • Grant users access to secured resources
            • Create a setup user
            • Create a monitoring user
            • Create a publishing user
            • Create a reader user
            • Learn more about privileges, roles, and users
          • Grant access using API keys
          • Secure communication with Elasticsearch
          • Secure communication with Logstash
          • Use Linux Secure Computing Mode (seccomp)
        • Troubleshoot
          • Get help
          • Debug
          • Understand logged metrics
          • Common problems
            • open /compat/linux/proc: no such file or directory error on FreeBSD
            • Metricbeat collects system metrics for interfaces you didn't configure
            • Metricbeat uses too much bandwidth
            • Error loading config file
            • Found unexpected or unknown characters
            • Logstash connection doesn't work
            • Publishing to Logstash fails with "connection reset by peer" message
            • @metadata is missing in Logstash
            • Not sure whether to use Logstash or Beats
            • SSL client fails to connect to Logstash
            • Monitoring UI shows fewer Beats than expected
            • Dashboard could not locate the index-pattern
            • High RSS memory usage due to MADV settings
        • Contribute
      • Packetbeat
        • Quick start
        • Set up and run
          • Directory layout
          • Secrets keystore
          • Command reference
          • Repositories for APT and YUM
          • Run Packetbeat on Docker
          • Packetbeat and systemd
          • Start Packetbeat
          • Stop Packetbeat
        • Upgrade Packetbeat
        • Configure
          • Traffic sniffing
          • Network flows
          • Protocols
            • Common protocol options
            • ICMP
            • DNS
            • HTTP
            • AMQP
            • Cassandra
            • Memcache
            • MySQL
            • PgSQL
            • Thrift
            • MongoDB
            • TLS
            • Redis
          • Processes
          • General settings
          • Project paths
          • Output
            • Elastic Cloud Hosted
            • Elasticsearch
            • Logstash
            • Kafka
            • Redis
            • File
            • Console
            • Discard
            • Change the output codec
          • Kerberos
          • SSL
          • Index lifecycle management (ILM)
          • Elasticsearch index template
          • Kibana endpoint
          • Kibana dashboards
          • Processors
            • Define processors
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • append
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • rate_limit
            • registered_domain
            • rename
            • replace
            • syslog
            • translate_ldap_attribute
            • translate_sid
            • truncate_fields
            • urldecode
          • Internal queue
          • Logging
          • HTTP endpoint
            • Protocol-Specific Metrics
          • Instrumentation
          • Feature flags
          • packetbeat.reference.yml
        • How to guides
          • Load the Elasticsearch index template
          • Change the index name
          • Load Kibana dashboards
          • Enrich events with geoIP information
          • Load ingest pipelines
          • Use environment variables in the configuration
          • Parse data using an ingest pipeline
          • Avoid YAML formatting problems