• Guides
  • APIs
  • Reference
  • Release notes
  • Troubleshoot
  1. Elastic Docs /
  2. Reference /
  3. Ingestion tools /
  4. Beats /
  5. Packetbeat

Troubleshoot

This page applies to
Versions

If you have issues installing or running Packetbeat, read the following tips:

  • Get help
  • Debug
  • Understand logged metrics
  • Record a trace
  • Common problems
Previous
Kibana queries and filters
Next
Get help
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
  • Elasticsearch fundamentals
    • Get started in seconds
      • Evaluate Elastic during a trial
    • Elasticsearch concepts
      • Elasticsearch essentials (Core document database)
      • Ingest data into Elasticsearch
      • Core search features
      • Visualize and analyze (Kibana)
      • Use cases
        • Geospatial analysis
        • Add search to your site or app
        • RAG
  • Install, deploy, and administer
    • Distributed architecture
      • Clusters, nodes, and shards
        • Node roles
      • Reading and writing documents
      • Shard allocation, relocation, and recovery
        • Shard allocation awareness
        • Index-level shard allocation filtering
          • Delaying allocation when a node leaves
      • The shard request cache
      • Discovery and cluster formation
        • Discovery hosts providers
        • Quorum-based decision making
        • Voting configurations
        • Bootstrapping a cluster
        • Cluster state
        • Cluster fault detection
      • Kibana task management
    • Plan your install
      • Deployment comparison
      • Versioning and compatibility
      • Reference architectures
        • Hot/Frozen - High Availability
        • GenAI Search - High Availability
      • Production guidance
        • Run Elasticsearch in production
          • Design for resilience
            • Resilience in small clusters
            • Resilience in larger clusters
            • Resilience in ECH and ECE
          • Scaling considerations
          • Performance optimizations
            • General recommendations
            • Tune for indexing speed
            • Tune for search speed
            • Tune approximate kNN search
            • Tune for disk usage
            • Size your shards
        • Run Kibana in production
          • High availability and load balancing
          • Configure memory
          • Manage background tasks
          • Traffic scaling considerations
          • Optimize alerting performance
          • Reporting production considerations
    • Install and deploy Elasticsearch
      • Skills for installation and deployment
      • Deploy in Elastic Cloud
        • Create an organization
        • Elastic Cloud Serverless
          • Create a serverless project
          • Regions
          • Production readiness checklist
        • Elastic Cloud Hosted
          • Create a deployment
          • Connect to Elasticsearch
          • Access Kibana
          • Prepare for production
            • Customize deployment components
            • Production readiness checklist
        • FedRAMP authorized Cloud offerings
      • Elastic Cloud Enterprise
        • Service-oriented architecture
        • Prepare your environment
          • Identify your deployment scenario
          • Hardware prerequisites
          • Software prerequisites
          • System configuration
          • Networking prerequisites
          • Users and permissions
          • High availability
          • Separation of roles
          • JVM heap size
        • Configure your operating system
          • Ubuntu
          • RHEL
          • SUSE
        • Install ECE
          • Installation procedures
            • Small installation
            • Medium installation
            • Large installation
            • Deploy using Podman
          • Ansible playbook
          • Air-gapped install
            • With your private Docker registry
            • Without a private Docker registry
            • Available Docker images
          • Log into the Cloud UI
        • Post-installation
          • Wildcard DNS and certificates
          • Load balancers
          • System deployments configuration
        • Create your first deployment
          • Create a deployment
          • Connect to Elasticsearch
          • Access Kibana
      • Elastic Cloud on Kubernetes
        • Deploy an orchestrator
          • YAML manifests
          • Helm chart
          • Deploy on OpenShift
            • Deploy the operator
            • Deploy Elasticsearch
            • Deploy Kibana
            • anyuid SCC workaround
          • Deploy on GKE Autopilot
          • Deploy on Google Distributed Cloud air-gapped
          • FIPS compatibility
          • Air-gapped environments
          • Required RBAC permissions
        • Deploy your first workloads
          • Deploy an Elasticsearch cluster
          • Deploy a Kibana instance
          • Accessing services
        • Production readiness checklist
      • Self-managed cluster
        • Install Elasticsearch
          • Local installation (quickstart)
          • Important system configuration
            • Elasticsearch service user
            • Configuration methods
            • Disable swapping
            • File descriptors
            • Virtual memory
            • Increase max number of threads
            • JNA temporary directory
            • TCP retransmission timeout
            • Bootstrap checks
          • Linux or macOS archive
          • Windows .zip
          • Debian package
          • RPM
          • Docker
            • Single-node cluster
            • Multi-node with Docker Compose
            • Docker in production
            • Configure with Docker
          • Important Elasticsearch settings
          • Configure Elasticsearch
        • Install Kibana
          • Linux or macOS archive
          • Windows
          • Debian package
          • RPM
          • Docker
          • Configure Kibana
        • Access Elasticsearch
        • Access Kibana
        • Air-gapped install
        • Tutorials
          • Install a self-managed Elastic Stack
          • Customize TLS certificates for a self-managed Elastic Stack
        • Production readiness checklist
    • Administer your orchestrator, deployment, or project
      • Administration skills
      • Deployment-specific administration
      • Elastic Cloud Hosted
        • Manage deployments
          • Configure
            • Manage hardware profiles
            • Customize deployment components
            • Edit stack settings
            • Add plugins and extensions
            • Custom endpoint aliases
          • Manage Integrations Server
          • Find your Cloud ID
          • Manage deployments using the API
          • Keep track of deployment activity
        • Access Kibana
        • vCPU boosting and credits
        • Available stack versions
        • Restrictions and known problems
        • Tools and APIs
      • Elastic Cloud Serverless
        • Manage project settings
        • Manage projects with API
        • Tools and APIs
      • Elastic Cloud Enterprise
        • Manage your orchestrator
          • Log into the Cloud UI
          • Assign roles to hosts
          • System deployments configuration
          • Deployment templates
            • Deployment templates reference
            • Tag allocators
            • Edit instance configurations
            • Create instance configurations
            • Create templates
            • Configure default templates
            • Configure index management
            • Data tiers and autoscaling support
            • Integrations server support
            • Default instance configurations
          • Change the API URL
          • Change endpoint URLs
          • Enable custom endpoint aliases
          • Manage allocator capacity
          • Configure allocator affinity
          • Change allocator disconnect timeout
          • Add hosts
          • Migrate to Podman
          • Include additional Kibana plugins
          • Manage stack versions
          • Statistics collected by ECE
          • Tools and APIs
        • Manage deployments
          • Deployment templates reference
          • Create a deployment
          • Access Kibana
          • Connect to Elasticsearch
          • Configure
          • Search and filter deployments
          • Keep track of deployment activity
          • Manage Integrations Server
      • Elastic Cloud on Kubernetes
        • Manage the ECK operator
          • Apply configuration settings
          • Validating webhook
          • Cross-namespace restrictions
          • Service meshes
            • Istio
            • Linkerd
          • Webhook namespace selectors
        • Manage deployments and workloads
          • Elastic Stack Helm chart
          • Applying updates
          • Accessing services
          • Configure deployments
            • Elasticsearch configuration
              • Nodes orchestration
              • Storage recommendations
              • Node configuration
              • Volume claim templates
              • Virtual memory
              • Settings managed by ECK
              • Custom configuration files and plugins
              • Init containers for plugins
              • Update strategy
              • Pod disruption budget
              • Advanced node scheduling
              • Readiness probe
              • Pod PreStop hook
              • Security context
              • Traffic splitting
            • Kibana configuration
              • Connect Kibana to Elasticsearch
              • Advanced configuration
              • Kibana plugins
            • Customize pods
            • Labels and annotations
            • Compute resources
            • Recipes
            • Connect to external resources
            • Stack configuration policies
          • Other Elastic applications
            • APM Server
              • Use an ECK-managed cluster
              • Advanced configuration
              • Connect to APM Server
            • Standalone Elastic Agent
              • Quickstart
              • Configuration
              • Configuration examples
              • Agent on OpenShift
            • Fleet-managed Elastic Agent
              • Quickstart
              • Configuration
              • Configuration examples
              • Known limitations
            • Elastic Maps Server
              • Deploy Maps Server
              • Map data
              • Advanced configuration
              • HTTP configuration
            • Beats
              • Quickstart
              • Configuration
              • Configuration examples
              • Troubleshooting
              • Beats on OpenShift
            • Logstash
              • Quickstart
              • Configuration
              • Securing the API
              • Plugins
              • Configuration examples
              • Update strategy
              • Advanced configuration
            • Elastic Package Registry
        • Custom images
        • Tools and APIs
      • Self-managed clusters
        • Configure Elasticsearch
        • Configure Kibana
        • Manage plugins
        • Access Kibana
        • Tools and APIs
      • ───
      • Security and encryption
        • Secure your orchestrator
        • Secure your cluster, deployment, or project
        • Secure other Elastic Stack components
        • Securing HTTP client applications
        • Limitations
        • FIPS compliance
      • Authentication and authorization
        • Cloud organization
        • ECE orchestrator
        • Serverless project custom roles
        • Cluster or deployment
      • API keys
        • Elasticsearch API keys
        • Serverless project API keys
        • Elastic Cloud API keys
        • Elastic Cloud Enterprise API keys
      • Spaces
      • Monitoring
        • AutoOps
        • Stack monitoring
        • AutoOps vs. Stack Monitoring
        • Cloud deployment health
        • Kibana task manager monitoring
        • Monitoring orchestrators
        • Logging
      • Configure Kibana reporting
      • Backup, high availability, and resilience tools
        • Snapshot and restore
        • Cross-cluster replication
      • Autoscaling
        • In ECE and ECH
        • In ECK
        • Autoscaling deciders
        • Trained model autoscaling
      • Stack settings
      • Connectors
      • Remote clusters
        • Security models
        • Connection modes
        • On Elastic Cloud Hosted
        • On Elastic Cloud Enterprise
        • On self-managed Elastic Stack
        • On Elastic Cloud on Kubernetes
      • Cross-project search
        • Link and manage projects
        • Access and scope
      • Cloud Connect
      • ───
      • Maintenance
        • ECE maintenance
        • Start and stop services
        • Start and stop routing requests
        • Add and Remove Elasticsearch nodes
      • Upgrade
        • Plan your upgrade
        • Preparation steps
        • Upgrade your deployment or cluster
        • Upgrade your ingest components
        • Upgrade your ECE or ECK orchestrator
      • Uninstall
        • Uninstall Elastic Cloud Enterprise
        • Uninstall Elastic Cloud on Kubernetes
        • Delete an orchestrated deployment
      • Licenses and subscriptions
        • Elastic Cloud Enterprise
        • Elastic Cloud on Kubernetes
        • Self-managed cluster
      • Manage your Cloud organization
        • Billing
        • Operational emails
        • Update billing and operational contacts
        • Service status
        • Tools and APIs
    • Deployment and administration tools
      • Elastic cloud control (ECCTL)
        • Installing
        • Configuring
          • Authentication
          • Example: A shared configuration file
          • Environment variables
          • Multiple configuration files
          • Output format
          • Custom formatting
        • Usage examples
          • List deployments
          • Create a deployment
          • Update a deployment
          • Delete a deployment
        • Command reference
          • ecctl
          • ecctl auth
          • ecctl auth key
          • ecctl auth key create
          • ecctl auth key delete
          • ecctl auth key list
          • ecctl auth key show
          • ecctl comment
          • ecctl comment create
          • ecctl comment delete
          • ecctl comment list
          • ecctl comment show
          • ecctl comment update
          • ecctl deployment
          • ecctl deployment create
          • ecctl deployment delete
          • ecctl deployment elasticsearch
          • ecctl deployment elasticsearch keystore
          • ecctl deployment elasticsearch keystore show
          • ecctl deployment elasticsearch keystore update
          • ecctl deployment extension
          • ecctl deployment extension create
          • ecctl deployment extension delete
          • ecctl deployment extension list
          • ecctl deployment extension show
          • ecctl deployment extension update
          • ecctl deployment list
          • ecctl deployment plan
          • ecctl deployment plan cancel
          • ecctl deployment resource
          • ecctl deployment resource delete
          • ecctl deployment resource restore
          • ecctl deployment resource shutdown
          • ecctl deployment resource start-maintenance
          • ecctl deployment resource start
          • ecctl deployment resource stop-maintenance
          • ecctl deployment resource stop
          • ecctl deployment resource upgrade
          • ecctl deployment restore
          • ecctl deployment resync
          • ecctl deployment search
          • ecctl deployment show
          • ecctl deployment shutdown
          • ecctl deployment template
          • ecctl deployment template create
          • ecctl deployment template delete
          • ecctl deployment template list
          • ecctl deployment template show
          • ecctl deployment template update
          • ecctl deployment traffic-filter
          • ecctl deployment traffic-filter association
          • ecctl deployment traffic-filter association create
          • ecctl deployment traffic-filter association delete
          • ecctl deployment traffic-filter create
          • ecctl deployment traffic-filter delete
          • ecctl deployment traffic-filter list
          • ecctl deployment traffic-filter show
          • ecctl deployment traffic-filter update
          • ecctl deployment update
          • ecctl generate
          • ecctl generate completions
          • ecctl generate docs
          • ecctl init
          • ecctl platform
          • ecctl platform allocator
          • ecctl platform allocator list
          • ecctl platform allocator maintenance
          • ecctl platform allocator metadata
          • ecctl platform allocator metadata delete
          • ecctl platform allocator metadata set
          • ecctl platform allocator metadata show
          • ecctl platform allocator search
          • ecctl platform allocator show
          • ecctl platform allocator vacate
          • ecctl platform constructor
          • ecctl platform constructor list
          • ecctl platform constructor maintenance
          • ecctl platform constructor resync
          • ecctl platform constructor show
          • ecctl platform enrollment-token
          • ecctl platform enrollment-token create
          • ecctl platform enrollment-token delete
          • ecctl platform enrollment-token list
          • ecctl platform info
          • ecctl platform instance-configuration
          • ecctl platform instance-configuration create
          • ecctl platform instance-configuration delete
          • ecctl platform instance-configuration list
          • ecctl platform instance-configuration pull
          • ecctl platform instance-configuration show
          • ecctl platform instance-configuration update
          • ecctl platform proxy
          • ecctl platform proxy filtered-group
          • ecctl platform proxy filtered-group create
          • ecctl platform proxy filtered-group delete
          • ecctl platform proxy filtered-group list
          • ecctl platform proxy filtered-group show
          • ecctl platform proxy filtered-group update
          • ecctl platform proxy list
          • ecctl platform proxy settings
          • ecctl platform proxy settings show
          • ecctl platform proxy settings update
          • ecctl platform proxy show
          • ecctl platform repository
          • ecctl platform repository create
          • ecctl platform repository delete
          • ecctl platform repository list
          • ecctl platform repository show
          • ecctl platform role
          • ecctl platform role create
          • ecctl platform role delete
          • ecctl platform role list
          • ecctl platform role show
          • ecctl platform role update
          • ecctl platform runner
          • ecctl platform runner list
          • ecctl platform runner resync
          • ecctl platform runner search
          • ecctl platform runner show
          • ecctl project
          • ecctl project create
          • ecctl project delete
          • ecctl project list
          • ecctl project show
          • ecctl stack
          • ecctl stack delete
          • ecctl stack list
          • ecctl stack show
          • ecctl stack upload
          • ecctl user
          • ecctl user create
          • ecctl user delete
          • ecctl user disable
          • ecctl user enable
          • ecctl user key
          • ecctl user key delete
          • ecctl user key list
          • ecctl user key show
          • ecctl user list
          • ecctl user show
          • ecctl user update
          • ecctl version
      • Command-line tools
      • Account and preferences
        • Join or leave an organization
        • Update your email address
        • Change your password
        • Add a login method
        • Multifactor authentication
        • Use dark mode in Kibana
        • Use high-contrast mode in Kibana
  • The Elasticsearch platform
    • Ingest and manage data
      • Ingest or migrate: bring your data into Elasticsearch
        • Choose/Plan your ingest method
        • Ingest architectures
          • Agent to Elasticsearch
            • Elastic Agent (installed)
            • Elastic Agent via APIs
          • Agent with Logstash
            • Logstash for enrichment
            • Logstash persistent queue
            • Logstash as a network bridge
            • Logstash for multiple destinations
          • Agent through a proxy
          • Agent with Kafka
            • Agent to Kafka via Logstash
            • Agent to Kafka with Elasticsearch sink
          • Logstash as input
          • Air-gapped environments
            • Agent to Elasticsearch (air-gapped)
            • Agent with Logstash (air-gapped)
        • Ingest by solution
          • Ingesting data for search use cases
          • Ingesting data for observability
          • Ingesting data for security (Move from Solutions)
        • Ingesting time series data
        • Ingest logs
          • Get started with system logs
          • Stream any log file
          • Stream any log file using EDOT Collector
          • Stream application logs
            • Plaintext application logs
            • ECS formatted application logs
            • APM agent log sending
          • Parse and route logs
          • Filter and aggregate logs
          • Explore logs
            • Discover logs
            • Categorize log entries
            • Inspect log anomalies
          • Run pattern analysis on log data
          • Log data sources
          • Logs data retention
          • Add service name to logs
          • Logs index template reference
            • Logs index template defaults
        • Ingest data with agentless integrations
          • Cloud connector deployment
          • Agentless integrations FAQ
          • Agentless integrations reference
        • Ingest data from applications
          • APM agents
            • APM .NET Agent
              • Supported technologies
              • Set up the APM .NET Agent
                • Profiler auto-instrumentation
                • ASP.NET Core
                • .NET 8+
                • ASP.NET
                • Azure Functions
                • Other .NET applications
              • NuGet packages
                • Entity Framework Core
                • Entity Framework 6
                • Elasticsearch
                • gRPC
                • SqlClient
                • StackExchange.Redis
                • Azure Cosmos DB
                • Azure Service Bus
                • Azure Storage
                • MongoDB
                • Confluent Kafka
              • Configuration
                • Configuration on ASP.NET Core
                • Configuration for Windows services
                • Configuration on ASP.NET
                • Core configuration options
                • Reporter configuration options
                • HTTP configuration options
                • Messaging configuration options
                • Stacktrace configuration options
                • Supportability configuration options
                • All options summary
              • Public API
              • OpenTelemetry bridge
              • Metrics
              • Logs
                • Serilog
                • NLog
                • Manual log correlation
              • Performance tuning
              • MongoDB
              • Troubleshooting
            • APM Go agent
              • Set up the APM Go Agent
                • Built-in instrumentation modules
                • Custom instrumentation
                • Context propagation
              • Supported technologies
              • Configuration
              • API documentation
              • Metrics
              • Logs
              • Log correlation
              • OpenTelemetry API
              • OpenTracing API
              • Contributing
              • Upgrading
              • Troubleshooting
            • APM Java agent
              • Set up the APM Java Agent
                • Manual setup with -javaagent flag
                • Automatic setup with apm-agent-attach-cli.jar
                • Programmatic API setup to self-attach
                • SSL/TLS communication with APM Server
                • Monitoring AWS Lambda Java Functions
              • Supported technologies
              • Configuration
                • Circuit-Breaker
                • Core
                • Datastore
                • HTTP
                • Huge Traces
                • JAX-RS
                • JMX
                • Logging
                • Messaging
                • Metrics
                • Profiling
                • Reporter
                • Serverless
                • Stacktrace
                • Property file reference
              • Tracing APIs
                • Public API
                • OpenTelemetry bridge
                • OpenTracing bridge
              • Plugin API
              • Metrics
              • Logs
              • How to find slow methods
                • Sampling-based profiler
                • API/Code
                • Annotations
                • Configuration-based
              • Overhead and performance tuning
              • Frequently asked questions
              • Community plugins
              • Upgrading
              • Troubleshooting
            • APM Node.js agent
              • Set up the Agent
                • Monitoring AWS Lambda Node.js Functions
                • Monitoring Node.js Azure Functions
                • Get started with Express
                • Get started with Fastify
                • Get started with hapi
                • Get started with Koa
                • Get started with TypeScript
                • Get started with a custom Node.js stack
                • Starting the agent
              • Supported technologies
              • Configuration
                • Configuring the agent
                • Configuration options
                • Custom transactions
                • Custom spans
              • API Reference
                • Agent API
                • Transaction API
                • Span API
              • Metrics
              • Logs
              • OpenTelemetry bridge
              • OpenTracing bridge
              • Source map support
              • ECMAScript module support
              • Distributed tracing
              • Message queues
              • Performance Tuning
              • Upgrading
                • Upgrade to v4.x
                • Upgrade to v3.x
                • Upgrade to v2.x
                • Upgrade to v1.x
              • Troubleshooting
            • APM PHP agent
              • Set up the APM PHP Agent
              • Supported technologies
              • Configuration
                • Configuration reference
              • Public API
              • Troubleshooting
            • APM Python agent
              • Set up the APM Python Agent
                • Django support
                • Flask support
                • Aiohttp Server support
                • Tornado Support
                • Starlette/FastAPI Support
                • Sanic Support
                • Monitoring AWS Lambda Python Functions
                • Monitoring Azure Functions
                • Wrapper Support
                • ASGI Middleware
              • Supported technologies
              • Configuration
              • Advanced topics
                • Instrumenting custom code
                • Sanitizing data
                • How the Agent works
                • Run Tests Locally
              • API reference
              • Metrics
              • OpenTelemetry API Bridge
              • Logs
              • Performance tuning
              • Upgrading
                • Upgrading to version 6 of the agent
                • Upgrading to version 5 of the agent
                • Upgrading to version 4 of the agent
              • Troubleshooting
            • APM Ruby agent
              • Set up the APM Ruby agent
                • Getting started with Rails
                • Getting started with Rack
              • Supported technologies
              • Configuration
              • Advanced topics
                • Adding additional context
                • Custom instrumentation
              • API reference
              • Metrics
              • Logs
              • OpenTracing API
              • GraphQL
              • Performance tuning
              • Upgrading
              • Troubleshooting
            • APM RUM JavaScript agent
              • Set up the APM Real User Monitoring JavaScript Agent
                • Install the Agent
                • Configure CORS
              • Supported technologies
              • Configuration
              • API reference
                • Agent API
                • Transaction API
                • Span API
              • Source maps
              • Framework-specific integrations
                • React integration
                • Angular integration
                • Vue integration
              • Distributed tracing
              • Breakdown metrics
              • OpenTracing
              • Advanced topics
                • How to interpret long task spans in the UI
                • Using with TypeScript
                • Custom page load transaction names
                • Custom Transactions
              • Performance tuning
              • Upgrading
              • Troubleshooting
          • Ingest data with Node.js
          • Ingest data with Python
          • Ingest data from Beats with Logstash as a proxy
          • Ingest data from a relational database
          • Ingest logs from a Python application using Filebeat
          • Ingest logs from a Node.js web application using Filebeat
        • Ingest data using the API
        • Ingest tools overview
        • Upload data files
        • Sample data
        • Migrating your Elasticsearch data
          • Reindex using a private CA
          • Migrate Elastic Cloud Hosted data to Serverless with Logstash
          • Minimal-downtime migration using snapshots
          • Migrate system indices
      • Ingest tools
        • Elastic OpenTelemetry
          • Quickstarts
          • Reference Architecture
            • Kubernetes environments
            • Hosts / VMs environments
            • Kafka ingest pipelines
          • Use cases
          • Compatibility and support
            • Features
            • Collector distributions
            • SDK Distributions
            • Elastic OpenTelemetry compared to upstream
            • Limitations
            • Nomenclature
            • Data streams comparison
          • Data streams
          • Central configuration
          • EDOT SDKs
          • Elastic Cloud Forwarder
            • Elastic Cloud Forwarder for GCP
          • OpenTelemetry
            • Download
            • Deployment modes
            • Configuration
              • Default config (Standalone)
              • Default config (Kubernetes)
              • Logs collection
              • Metrics collection
              • Tracing collection
              • Authentication methods
              • Profiles collection
              • Monitor internal metrics
              • Custom data stream routing
              • Migrate components
              • Proxy settings
            • Components
              • APM Config extension
              • Attributes processor
              • Elastic APM connector
              • Elastic APM intake receiver
              • Elastic APM processor
              • Elasticsearch exporter
              • File log receiver
              • Host metrics receiver
              • Kubernetes cluster receiver
              • Kubernetes objects receiver
              • Kubelet stats receiver
              • Prometheus remote Write receiver
            • Customization
              • Custom Collector
            • Use the contrib Collector
            • Troubleshooting
          • EDOT Android
            • Get started
            • Configuration
            • Manual instrumentation
            • Automatic instrumentation
            • Troubleshooting
            • Release notes
          • EDOT .NET
            • Setup
              • ASP.NET
              • Console applications
              • .NET worker services
              • Zero-code instrumentation
              • Opinionated defaults
            • Configuration
            • Supported technologies
            • Migration
            • Troubleshooting
            • Release notes
          • EDOT iOS
            • Get started
            • Configuration
            • Automatic instrumentation
            • Manual instrumentation
            • Troubleshooting
            • Release notes
          • EDOT Java
            • Setup
              • Kubernetes Setup
              • Runtime attach Setup
            • Configuration
            • Features
            • Supported Technologies
            • Migration
            • Performance overhead
            • Troubleshooting
            • Release notes
          • EDOT Node.js
            • Setup
              • Kubernetes
            • Configuration
            • Supported Technologies
            • Metrics
            • Migration
            • Troubleshooting
            • Release notes
          • EDOT PHP
            • Setup
              • Limitations
            • Configuration
            • Attribute-based instrumentation
            • Supported Technologies
            • Migration
            • Long-running PHP servers
            • Performance overhead
            • Troubleshooting
            • Release notes
          • EDOT Python
            • Setup
              • Kubernetes
              • Manual instrumentation
            • Configuration
            • Supported Technologies
            • Migration
            • Performance overhead
            • Troubleshooting
            • Release notes
          • EDOT Browser
            • Setup
              • Install the agent
              • Proxy and CORS
            • Configuration
            • Metrics, traces, and logs
            • Supported technologies
            • Troubleshooting
        • Fleet and Elastic Agent
          • Restrictions for Elastic Cloud Serverless
          • Beats and Elastic Agent capabilities
          • Elastic Agent as an OTel Collector
          • Migrate from Beats to Elastic Agent
            • Migrate from Auditbeat to Elastic Agent
          • Deployment models
            • What is Fleet Server?
            • Deploy on Elastic Cloud
            • Deploy on-premises and self-managed
            • Deploy Fleet Server on-premises and Elasticsearch on Elastic Cloud
            • Deploy on Kubernetes
            • Fleet Server scalability
            • Fleet Server secrets
              • Secret files guide
            • Monitor a self-managed Fleet Server
          • Install Elastic Agents
            • Elastic Agent release process
            • Install Fleet-managed Elastic Agents
            • Install standalone Elastic Agents
              • Upgrade standalone Elastic Agents
            • Install Elastic Agents in a containerized environment
              • Run Elastic Agent in a container
              • Run Elastic Agent on Kubernetes managed by Fleet
              • Install Elastic Agent on Kubernetes using Helm
                • Example: Install standalone Elastic Agent on Kubernetes using Helm
                • Example: Install Fleet-managed Elastic Agent on Kubernetes using Helm
              • Advanced Elastic Agent configuration managed by Fleet
              • Configuring Kubernetes metadata enrichment on Elastic Agent
              • Run Elastic Agent on GKE managed by Fleet
              • Configure Elastic Agent Add-On on Amazon EKS
              • Run Elastic Agent on Azure AKS managed by Fleet
              • Run Elastic Agent Standalone on Kubernetes
              • Scaling Elastic Agent on Kubernetes
              • Using a custom ingest pipeline with the Kubernetes Integration
              • Environment variables
            • Run Elastic Agent as an EDOT Collector
            • Transform an installed Elastic Agent to run as an EDOT Collector
            • Run Elastic Agent without administrative privileges
            • Install Elastic Agent from an MSI package
            • Installation layout
            • Air-gapped environments
            • Using a proxy server with Elastic Agent and Fleet
              • When to configure proxy settings
              • Proxy server connectivity using default host variables
              • Fleet-managed Elastic Agent connectivity using a proxy server
              • Standalone Elastic Agent connectivity using a proxy server
              • Set the proxy URL of the Elastic Package Registry
            • Uninstall Elastic Agents from edge hosts
            • Start and stop Elastic Agents on edge hosts
            • Elastic Agent configuration encryption
          • Secure connections
            • Configure SSL/TLS for self-managed Fleet Servers
            • Certificate fingerprints
            • Rotate SSL/TLS CA certificates
            • Elastic Agent deployment models with mutual TLS
            • One-way and mutual TLS certifications flow
            • Configure SSL/TLS for the Logstash output
          • Manage Elastic Agents in Fleet
            • Fleet settings
              • Elasticsearch output settings
              • Logstash output settings
              • Kafka output settings
              • Remote Elasticsearch output
                • Automatic integrations synchronization
              • Considerations when changing outputs
            • Elastic Agents
              • Unenroll Elastic Agents
              • Set inactivity timeout
              • Upgrade Elastic Agents
              • Migrate Elastic Agents
              • Monitor Elastic Agents
              • Elastic Agent built-in alerts
              • Elastic Agent health status
              • Add tags to filter the Agents list
              • Enrollment handling for containerized agents
              • Remove agent elevated privileges
            • Policies
              • Create an agent policy without using the UI
              • Enable custom settings in an agent policy
              • Set environment variables in an Elastic Agent policy
            • Roles and privileges
            • Fleet enrollment tokens
            • Kibana Fleet APIs
          • Configure standalone Elastic Agents
            • Create a standalone Elastic Agent policy
            • Structure of a config file
            • Inputs
              • Simplified log ingestion
              • Elastic Agent inputs
              • Variables and conditions in input configurations
            • Outputs
              • Elasticsearch
              • Kafka
              • Logstash
            • SSL/TLS
            • Logging
            • Feature flags
            • Agent download
            • Config file examples
              • Apache HTTP Server
              • Nginx HTTP Server
            • Grant standalone Elastic Agents access to Elasticsearch
            • Example: Use standalone Elastic Agent with Elastic Cloud Serverless to monitor nginx
            • Example: Use standalone Elastic Agent with Elastic Cloud Hosted to monitor nginx
            • Debug standalone Elastic Agents
            • Kubernetes autodiscovery with Elastic Agent
              • Conditions based autodiscover
              • Hints annotations based autodiscover
            • Monitoring
            • Reference YAML
          • Manage integrations
            • Package signatures
            • Add an integration to an Elastic Agent policy
            • View integration policies
            • Edit or delete an integration policy
            • Install and uninstall integration assets
            • View integration assets
            • Set integration-level outputs
            • Upgrade an integration
            • Roll back an integration
            • Managed integrations content
            • Best practices for integration assets
            • OpenTelemetry integration packages
            • Deprecated integrations
            • Data streams
              • Tutorials: Customize data retention policies
                • Scenario 1
                • Scenario 2
                • Scenario 3
                • Scenario 4
              • Tutorial: Transform data with custom ingest pipelines
              • Advanced data stream features
            • Alerting rule templates
          • Command reference
          • Agent providers
            • Local provider
            • Agent provider
            • Host provider
            • Env provider
            • Filesource provider
            • Kubernetes Secrets provider
            • Kubernetes LeaderElection Provider
            • Local dynamic provider
            • Docker provider
            • Kubernetes provider
          • Agent processors
            • Processor syntax
            • add_cloud_metadata
            • add_cloudfoundry_metadata
            • add_docker_metadata
            • add_fields
            • add_host_metadata
            • add_id
            • add_kubernetes_metadata
            • add_labels
            • add_locale
            • add_network_direction
            • add_nomad_metadata
            • add_observer_metadata
            • add_process_metadata
            • add_tags
            • community_id
            • convert
            • copy_fields
            • decode_base64_field
            • decode_cef
            • decode_csv_fields
            • decode_duration
            • decode_json_fields
            • decode_xml
            • decode_xml_wineventlog
            • decompress_gzip_field
            • detect_mime_type
            • dissect
            • dns
            • drop_event
            • drop_fields
            • extract_array
            • fingerprint
            • include_fields
            • move_fields
            • parse_aws_vpc_flow_log
            • rate_limit
            • registered_domain
            • rename
            • replace
            • script
            • syslog
            • timestamp
            • translate_sid
            • truncate_fields
            • urldecode
        • Content connectors
          • Connectors references
            • Azure Blob Storage
            • Box
            • Confluence
            • Dropbox
            • GitHub
            • GitLab
            • Gmail
            • Google Cloud Storage
            • Google Drive
            • GraphQL
            • Jira
            • Microsoft SQL
            • MongoDB
            • MySQL
            • Network drive
            • Notion
            • OneDrive
            • OpenText Documentum
            • Oracle
            • Outlook
            • PostgreSQL
            • Redis
            • S3
            • Salesforce
            • Sandfly Security
            • ServiceNow
            • SharePoint Online
            • SharePoint Server
            • Slack
            • Teams
            • Zoom
          • Self-managed connectors
            • Running from a Docker container
            • Running from the source code
            • Docker Compose quickstart
            • Tutorial
          • Build and customize connectors
          • Connectors UI
          • Connector APIs
            • API tutorial
          • Content syncs
          • Extract and transform
            • Content extraction
            • Sync rules
          • Document level security for content connectors
            • How DLS works
            • DLS in Search Applications
          • Management topics
            • Scalability
            • Security
            • Troubleshooting
            • Logs
          • Use cases
            • Internal knowledge search
          • Known issues
          • Release notes
        • Logstash
          • Getting started with Logstash
            • Installing Logstash
            • Stashing Your First Event
            • Parsing Logs with Logstash
            • Stitching Together Multiple Input and Output Plugins
          • How Logstash Works
            • Execution Model
            • ECS in Logstash
            • Processing Details
          • Setting up and running Logstash
            • Logstash Directory Layout
            • Logstash Configuration Files
            • logstash.yml
            • Secrets keystore for secure settings
            • Running Logstash from the Command Line
            • Running Logstash as a Service on Debian or RPM
            • Running Logstash on Docker
            • Configuring Logstash for Docker
            • Running Logstash on Kubernetes
            • Running Logstash on Windows
            • Logging
            • Shutting Down Logstash
          • Upgrading Logstash
            • Upgrading using package managers
            • Upgrading using a direct download
            • Upgrading between minor versions
          • Creating a Logstash Pipeline
            • Structure of a pipeline
            • Accessing event data and fields
            • Using environment variables
            • Sending data to Elastic Cloud Hosted
            • Sending data to Elasticsearch Serverless
            • Logstash configuration examples
          • Secure your connection
          • Advanced Logstash configurations
            • Multiple Pipelines
            • Pipeline-to-pipeline communication
            • Reloading the Config File
            • Managing Multiline Events
            • Glob Pattern Support
          • Logstash-to-Logstash communications
            • Logstash-to-Logstash: Lumberjack output to Beats input
            • Logstash-to-Logstash: HTTP output to HTTP input
            • Logstash-to-Logstash: Output to Input
          • Managing Logstash
            • Centralized Pipeline Management
            • Configure Centralized Pipeline Management
          • Using Logstash with Elastic integrations
            • Tutorial to extend Elastic Integrations
          • Working with Filebeat modules
            • Use ingest pipelines for parsing
            • Example: Set up Filebeat modules to work with Kafka and Logstash
          • Working with Winlogbeat modules
          • Queues and data resiliency
            • Memory queue
            • Persistent queues (PQ)
            • Dead letter queues (DLQ)
          • Transforming data
            • Performing Core Operations
            • Deserializing Data
            • Extracting Fields and Wrangling Data
            • Enriching Data with Lookups
          • Deploying and scaling Logstash
          • Managing GeoIP databases
            • GeoIP Database Management
            • Configure GeoIP Database Management
          • Performance tuning
            • Performance troubleshooting
            • Tuning and profiling logstash pipeline performance
          • Monitoring Logstash with Elastic Agent
            • Collect monitoring data for dashboards
            • Collect monitoring data for dashboards (Serverless )
            • Collect monitoring data for stack monitoring
          • Monitoring Logstash (Legacy)
            • Metricbeat collection
            • Legacy collection (deprecated)
            • Monitoring UI
            • Pipeline Viewer UI
            • Troubleshooting
          • Monitoring Logstash with APIs
          • Working with plugins
            • Cross-plugin concepts and features
            • Generating plugins
            • Offline Plugin Management
            • Private Gem Repositories
            • Event API
          • Tips and best practices
            • JVM settings
            • File descriptors
        • APM
          • APM settings
          • APM settings for Elastic Cloud
          • APM settings for Elastic Cloud Enterprise
          • APM Attacher for Kubernetes
            • Instrument and configure pods
              • Add the helm repository to Helm
              • Configure the webhook with a Helm values file
              • Install the webhook with Helm
              • Add a pod template annotation to each pod you want to auto-instrument
              • Watch data flow into the Elastic Stack
          • APM Architecture for AWS Lambda
            • Performance impact and overhead
            • Configuration options
            • Using AWS Secrets Manager to manage APM authentication keys
          • APM agents
            • APM .NET Agent
              • Supported technologies
              • Set up the APM .NET Agent
                • Profiler auto-instrumentation
                • ASP.NET Core
                • .NET 8+
                • ASP.NET
                • Azure Functions
                • Other .NET applications
              • NuGet packages
                • Entity Framework Core
                • Entity Framework 6
                • Elasticsearch
                • gRPC
                • SqlClient
                • StackExchange.Redis
                • Azure Cosmos DB
                • Azure Service Bus
                • Azure Storage
                • MongoDB
                • Confluent Kafka
              • Configuration
                • Configuration on ASP.NET Core
                • Configuration for Windows services
                • Configuration on ASP.NET
                • Core configuration options
                • Reporter configuration options
                • HTTP configuration options
                • Messaging configuration options
                • Stacktrace configuration options
                • Supportability configuration options
                • All options summary
              • Public API
              • OpenTelemetry bridge
              • Metrics
              • Logs
                • Serilog
                • NLog
                • Manual log correlation
              • Performance tuning
              • MongoDB
              • Troubleshooting
            • APM Go agent
              • Set up the APM Go Agent
                • Built-in instrumentation modules
                • Custom instrumentation
                • Context propagation
              • Supported technologies
              • Configuration
              • API documentation
              • Metrics
              • Logs
              • Log correlation
              • OpenTelemetry API
              • OpenTracing API
              • Contributing
              • Upgrading
              • Troubleshooting
            • APM Java agent
              • Set up the APM Java Agent
                • Manual setup with -javaagent flag
                • Automatic setup with apm-agent-attach-cli.jar
                • Programmatic API setup to self-attach
                • SSL/TLS communication with APM Server
                • Monitoring AWS Lambda Java Functions
              • Supported technologies
              • Configuration
                • Circuit-Breaker
                • Core
                • Datastore
                • HTTP
                • Huge Traces
                • JAX-RS
                • JMX
                • Logging
                • Messaging
                • Metrics
                • Profiling
                • Reporter
                • Serverless
                • Stacktrace
                • Property file reference
              • Tracing APIs
                • Public API
                • OpenTelemetry bridge
                • OpenTracing bridge
              • Plugin API
              • Metrics
              • Logs
              • How to find slow methods
                • Sampling-based profiler
                • API/Code
                • Annotations
                • Configuration-based
              • Overhead and performance tuning
              • Frequently asked questions
              • Community plugins
              • Upgrading
              • Troubleshooting
            • APM Node.js agent
              • Set up the Agent
                • Monitoring AWS Lambda Node.js Functions
                • Monitoring Node.js Azure Functions
                • Get started with Express
                • Get started with Fastify
                • Get started with hapi
                • Get started with Koa
                • Get started with TypeScript
                • Get started with a custom Node.js stack
                • Starting the agent
              • Supported technologies
              • Configuration
                • Configuring the agent
                • Configuration options
                • Custom transactions
                • Custom spans
              • API Reference
                • Agent API
                • Transaction API
                • Span API
              • Metrics
              • Logs
              • OpenTelemetry bridge
              • OpenTracing bridge
              • Source map support
              • ECMAScript module support
              • Distributed tracing
              • Message queues
              • Performance Tuning
              • Upgrading
                • Upgrade to v4.x
                • Upgrade to v3.x
                • Upgrade to v2.x
                • Upgrade to v1.x
              • Troubleshooting
            • APM PHP agent
              • Set up the APM PHP Agent
              • Supported technologies
              • Configuration
                • Configuration reference
              • Public API
              • Troubleshooting
            • APM Python agent
              • Set up the APM Python Agent
                • Django support
                • Flask support
                • Aiohttp Server support
                • Tornado Support
                • Starlette/FastAPI Support
                • Sanic Support
                • Monitoring AWS Lambda Python Functions
                • Monitoring Azure Functions
                • Wrapper Support
                • ASGI Middleware
              • Supported technologies
              • Configuration
              • Advanced topics
                • Instrumenting custom code
                • Sanitizing data
                • How the Agent works
                • Run Tests Locally
              • API reference
              • Metrics
              • OpenTelemetry API Bridge
              • Logs
              • Performance tuning
              • Upgrading
                • Upgrading to version 6 of the agent
                • Upgrading to version 5 of the agent
                • Upgrading to version 4 of the agent
              • Troubleshooting
            • APM Ruby agent
              • Set up the APM Ruby agent
                • Getting started with Rails
                • Getting started with Rack
              • Supported technologies
              • Configuration
              • Advanced topics
                • Adding additional context
                • Custom instrumentation
              • API reference
              • Metrics
              • Logs
              • OpenTracing API
              • GraphQL
              • Performance tuning
              • Upgrading
              • Troubleshooting
            • APM RUM JavaScript agent
              • Set up the APM Real User Monitoring JavaScript Agent
                • Install the Agent
                • Configure CORS
              • Supported technologies
              • Configuration
              • API reference
                • Agent API
                • Transaction API
                • Span API
              • Source maps
              • Framework-specific integrations
                • React integration
                • Angular integration
                • Vue integration
              • Distributed tracing
              • Breakdown metrics
              • OpenTracing
              • Advanced topics
                • How to interpret long task spans in the UI
                • Using with TypeScript
                • Custom page load transaction names
                • Custom Transactions
              • Performance tuning
              • Upgrading
              • Troubleshooting
        • Beats
          • Beats for Elasticsearch Serverless
          • Config file format
            • Namespacing
            • Config file data types
            • Environment variables
            • Reference variables
            • Config file ownership and permissions
            • Command line arguments
            • YAML tips and gotchas
          • Auditbeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Repositories for APT and YUM
              • Run Auditbeat on Docker
              • Running Auditbeat on Kubernetes
              • Auditbeat and systemd
              • Start Auditbeat
              • Stop Auditbeat
            • Upgrade Auditbeat
            • Configure
              • Modules
              • General settings
              • Project paths
              • Config file reloading
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Kibana endpoint
              • Kibana dashboards
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_session_metadata
                • add_tags
                • append
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • rate_limit
                • registered_domain
                • rename
                • replace
                • syslog
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Internal queue
              • Logging
              • HTTP endpoint
              • Regular expression support
              • Instrumentation
              • Feature flags
              • auditbeat.reference.yml
            • How to guides
              • Load the Elasticsearch index template
              • Change the index name
              • Load Kibana dashboards
              • Enrich events with geoIP information
              • Parse data using an ingest pipeline
              • Use environment variables in the configuration
              • Avoid YAML formatting problems
            • Modules
              • Auditd Module
              • File Integrity Module
              • System Module
                • System host dataset
                • System login dataset
                • System package dataset
                • System process dataset
                • System socket dataset
                • System user dataset
            • Exported fields
              • Auditd fields
              • Beat fields
              • Cloud provider metadata fields
              • Common fields
              • Docker fields
              • ECS fields
              • File Integrity fields
              • Host fields
              • Jolokia Discovery autodiscover provider fields
              • Kubernetes fields
              • Process fields
              • System fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
              • Use Linux Secure Computing Mode (seccomp)
            • Troubleshoot
              • Get Help
              • Debug
              • Understand logged metrics
              • Common problems
                • Auditbeat fails to watch folders because too many files are open
                • Auditbeat uses too much bandwidth
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • Dashboard could not locate the index-pattern
                • High RSS memory usage due to MADV settings
            • Contribute
          • Filebeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Repositories for APT and YUM
              • Run Filebeat on Docker
              • Run Filebeat on Kubernetes
              • Run Filebeat on Cloud Foundry
              • Filebeat and systemd
              • Start Filebeat
              • Stop Filebeat
            • Upgrade
            • How Filebeat works
            • Configure
              • Inputs
                • Multiline messages
                • AWS CloudWatch
                • AWS S3
                • Azure Event Hub
                • Azure Blob Storage
                • Benchmark
                • CEL
                • Cloud Foundry
                • CometD
                • Container
                • Entity Analytics
                • ETW
                • filestream
                • GCP Pub/Sub
                • Google Cloud Storage
                • HTTP Endpoint
                • HTTP JSON
                • journald
                • Kafka
                • Log
                • MQTT
                • NetFlow
                • Office 365 Management Activity API
                • Redis
                • Salesforce
                • Stdin
                • Streaming
                • Syslog
                • TCP
                • UDP
                • Unified Logs
                • Unix
                • winlog
              • Modules
                • Override input settings
              • General settings
              • Project paths
              • Config file loading
                • Live reloading
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Kibana endpoint
              • Kibana dashboards
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_tags
                • append
                • cache
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_cef
                • decode_csv_fields
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • parse_aws_vpc_flow_log
                • rate_limit
                • registered_domain
                • rename
                • replace
                • script
                • syslog
                • timestamp
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Autodiscover
                • Hints based autodiscover
                • Advanced usage
              • Internal queue
              • Logging
              • HTTP endpoint
              • Regular expression support
              • Instrumentation
              • Feature flags
              • filebeat.reference.yml
            • How to guides
              • Override configuration settings
              • Load the Elasticsearch index template
              • Change the index name
              • Load Kibana dashboards
              • Load ingest pipelines
              • Enrich events with geoIP information
              • Deduplicate data
              • Parse data using an ingest pipeline
              • Use environment variables in the configuration
              • Avoid YAML formatting problems
              • Migrate log or container input configurations to filestream
              • How to choose file identity for filestream
              • Migrating from a Deprecated Filebeat Module
              • Removing files after ingestion
            • Modules
              • Modules
              • ActiveMQ module
              • Apache module
              • Auditd module
              • AWS module
              • AWS Fargate module
              • Azure module
              • CEF module
              • Check Point module
              • Cisco module
              • CoreDNS module
              • CrowdStrike module
              • Cyberark PAS module
              • Elasticsearch module
              • Envoyproxy module
              • Fortinet module
              • Google Cloud Platform (GCP) module
              • Google Workspace module
              • HAProxy module
              • IBM MQ module
              • Icinga module
              • IIS module
              • Iptables module
              • Juniper JUNOS module
              • Kafka module
              • Kibana module
              • Logstash module
              • Microsoft module
              • MISP module
              • MongoDB module
              • MSSQL module
              • MySQL module
              • MySQL Enterprise module
              • NATS module
              • NetFlow module
              • Nginx module
              • Office 365 module
              • Okta module
              • Oracle module
              • Osquery module
              • Palo Alto Networks module
              • Pensando module
              • PostgreSQL module
              • RabbitMQ module
              • Redis module
              • Salesforce module
                • Set up the OAuth App in the Salesforce
              • Google Santa module
              • Snyk module
              • Sophos module
              • Suricata module
              • System module
              • Threat Intel module
              • Traefik module
              • Zeek (Bro) module
              • ZooKeeper module
              • Zoom module
            • Exported fields
              • ActiveMQ fields
              • Apache fields
              • Auditd fields
              • AWS fields
              • AWS CloudWatch fields
              • AWS Fargate fields
              • Azure fields
              • Beat fields
              • Decode CEF processor fields fields
              • CEF fields
              • Check Point fields
              • Cisco fields
              • Cloud provider metadata fields
              • CoreDNS fields
              • CrowdStrike fields
              • Cyberark PAS fields
              • Docker fields
              • ECS fields
              • Elasticsearch fields
              • Elasticsearch query log fields
              • Envoyproxy fields
              • Fortinet fields
              • Google Cloud Platform (GCP) fields
              • Google Workspace fields
              • HAProxy fields
              • Host fields
              • IBM MQ fields
              • Icinga fields
              • IIS fields
              • Iptables fields
              • Jolokia Discovery autodiscover provider fields
              • Juniper JUNOS fields
              • Kafka fields
              • Kibana fields
              • Kubernetes fields
              • Log file content fields
              • Logstash fields
              • Lumberjack fields
              • Microsoft fields
              • MISP fields
              • MongoDB fields
              • MSSQL fields
              • MySQL fields
              • MySQL Enterprise fields
              • NATS fields
              • NetFlow fields
              • Nginx fields
              • Office 365 fields
              • Okta fields
              • Oracle fields
              • Osquery fields
              • Palo Alto Networks fields
              • Pensando fields
              • PostgreSQL fields
              • Process fields
              • RabbitMQ fields
              • Redis fields
              • s3 fields
              • Salesforce fields
              • Google Santa fields
              • Snyk fields
              • Sophos fields
              • Suricata fields
              • System fields
              • Threat Intel fields
              • Traefik fields
              • Windows ETW fields
              • Zeek (Bro) fields
              • ZooKeeper fields
              • Zoom fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
              • Use Linux Secure Computing Mode (seccomp)
            • Troubleshoot
              • Get help
              • Debug
              • Understand logged metrics
              • Common problems
                • Error extracting container id while using Kubernetes metadata
                • Can't read log files from network volumes
                • Filebeat isn't collecting lines from a file
                • Too many open file handlers
                • Registry file is too large
                • Inode reuse causes Filebeat to skip lines
                • Log rotation results in lost or duplicate events
                • Open file handlers cause issues with Windows file rotation
                • Filebeat is using too much CPU
                • Dashboard in Kibana is breaking up data fields incorrectly
                • Fields are not indexed or usable in Kibana visualizations
                • Filebeat isn't shipping the last line of a file
                • Filebeat keeps open file handlers of deleted files for a long time
                • Filebeat uses too much bandwidth
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • Dashboard could not locate the index-pattern
                • High RSS memory usage due to MADV settings
                • Files are not fully ingested when using autodiscover
            • Contribute
          • Heartbeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Repositories for APT and YUM
              • Run Heartbeat on Docker
              • Running Heartbeat on Kubernetes
              • Heartbeat and systemd
              • Stop Heartbeat
            • Configure
              • Monitors
                • Common monitor options
                • ICMP options
                • TCP options
                • HTTP options
              • Task scheduler
              • General settings
              • Project paths
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_tags
                • append
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • rate_limit
                • registered_domain
                • rename
                • replace
                • script
                • syslog
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Autodiscover
                • Hints based autodiscover
                • Advanced usage
              • Internal queue
              • Logging
              • HTTP endpoint
              • Regular expression support
              • Instrumentation
              • Feature flags
              • heartbeat.reference.yml
            • How to guides
              • Add observer and geo metadata
              • Load the Elasticsearch index template
              • Change the index name
              • Enrich events with geoIP information
              • Use environment variables in the configuration
              • Parse data using an ingest pipeline
              • Avoid YAML formatting problems
            • Exported fields
              • Beat fields
              • Synthetics browser metrics fields
              • Cloud provider metadata fields
              • Common heartbeat monitor fields
              • Docker fields
              • ECS fields
              • Host fields
              • HTTP monitor fields
              • ICMP fields
              • Jolokia Discovery autodiscover provider fields
              • Kubernetes fields
              • Process fields
              • Host lookup fields
              • APM Service fields
              • SOCKS5 proxy fields
              • Monitor state fields
              • Monitor summary fields
              • Synthetics types fields
              • TCP layer fields
              • TLS encryption layer fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
              • Use Linux Secure Computing Mode (seccomp)
            • Troubleshoot
              • Get help
              • Debug
              • Understand logged metrics
              • Common problems
                • Heartbeat uses too much bandwidth
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • High RSS memory usage due to MADV settings
            • Contribute
          • Metricbeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Repositories for APT and YUM
              • Run Metricbeat on Docker
              • Run Metricbeat on Kubernetes
              • Run Metricbeat on Cloud Foundry
              • Metricbeat and systemd
              • Start Metricbeat
              • Stop Metricbeat
            • Upgrade Metricbeat
            • How Metricbeat works
              • Event structure
              • Error event structure
              • Key metricbeat features
            • Configure
              • Modules
              • General settings
              • Project paths
              • Config file loading
                • Live reloading
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Kibana endpoint
              • Kibana dashboards
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_tags
                • append
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • rate_limit
                • registered_domain
                • rename
                • replace
                • script
                • syslog
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Autodiscover
                • Hints based autodiscover
                • Advanced usage
              • Internal queue
              • Logging
              • HTTP endpoint
              • Regular expression support
              • Instrumentation
              • Feature flags
              • metricbeat.reference.yml
            • How to guides
              • Load the Elasticsearch index template
              • Change the index name
              • Load Kibana dashboards
              • Enrich events with geoIP information
              • Use environment variables in the configuration
              • Parse data using an ingest pipeline
              • Avoid YAML formatting problems
            • Modules
              • ActiveMQ module
                • ActiveMQ broker metricset
                • ActiveMQ queue metricset
                • ActiveMQ topic metricset
              • Aerospike module
                • Aerospike namespace metricset
              • Airflow module
                • Airflow statsd metricset
              • Apache module
                • Apache status metricset
              • AWS module
                • AWS awshealth metricset
                • AWS billing metricset
                • AWS cloudwatch metricset
                • AWS dynamodb metricset
                • AWS ebs metricset
                • AWS ec2 metricset
                • AWS elb metricset
                • AWS kinesis metricset
                • AWS lambda metricset
                • AWS natgateway metricset
                • AWS rds metricset
                • AWS s3_daily_storage metricset
                • AWS s3_request metricset
                • AWS sns metricset
                • AWS sqs metricset
                • AWS transitgateway metricset
                • AWS usage metricset
                • AWS vpn metricset
              • AWS Fargate module
                • AWS Fargate task_stats metricset
              • Azure module
                • Azure app_insights metricset
                • Azure app_state metricset
                • Azure billing metricset
                • Azure compute_vm metricset
                • Azure compute_vm_scaleset metricset
                • Azure container_instance metricset
                • Azure container_registry metricset
                • Azure container_service metricset
                • Azure database_account metricset
                • Azure monitor metricset
                • Azure storage metricset
              • Beat module
                • Beat state metricset
                • Beat stats metricset
              • Benchmark module
                • Benchmark info metricset
              • Ceph module
                • Ceph cluster_disk metricset
                • Ceph cluster_health metricset
                • Ceph cluster_status metricset
                • Ceph mgr_cluster_disk metricset
                • Ceph mgr_cluster_health metricset
                • Ceph mgr_osd_perf metricset
                • Ceph mgr_osd_pool_stats metricset
                • Ceph mgr_osd_tree metricset
                • Ceph mgr_pool_disk metricset
                • Ceph monitor_health metricset
                • Ceph osd_df metricset
                • Ceph osd_tree metricset
                • Ceph pool_disk metricset
              • Cloudfoundry module
                • Cloudfoundry container metricset
                • Cloudfoundry counter metricset
                • Cloudfoundry value metricset
              • CockroachDB module
                • CockroachDB status metricset
              • Consul module
                • Consul agent metricset
              • Containerd module
                • Containerd blkio metricset
                • Containerd cpu metricset
                • Containerd memory metricset
              • Coredns module
                • Coredns stats metricset
              • Couchbase module
                • Couchbase bucket metricset
                • Couchbase cluster metricset
                • Couchbase node metricset
              • CouchDB module
                • CouchDB server metricset
              • Docker module
                • Docker container metricset
                • Docker cpu metricset
                • Docker diskio metricset
                • Docker event metricset
                • Docker healthcheck metricset
                • Docker image metricset
                • Docker info metricset
                • Docker memory metricset
                • Docker network metricset
                • Docker network_summary metricset
              • Dropwizard module
                • Dropwizard collector metricset
              • Elasticsearch module
                • Elasticsearch ccr metricset
                • Elasticsearch cluster_stats metricset
                • Elasticsearch enrich metricset
                • Elasticsearch index metricset
                • Elasticsearch index_recovery metricset
                • Elasticsearch index_summary metricset
                • Elasticsearch ingest_pipeline metricset
                • Elasticsearch ml_job metricset
                • Elasticsearch node metricset
                • Elasticsearch node_stats metricset
                • Elasticsearch pending_tasks metricset
                • Elasticsearch security_stats metricset
                • Elasticsearch shard metricset
              • Envoyproxy module
                • Envoyproxy server metricset
              • Etcd module
                • Etcd leader metricset
                • Etcd metrics metricset
                • Etcd self metricset
                • Etcd store metricset
              • Google Cloud Platform module
                • Google Cloud Platform billing metricset
                • Google Cloud Platform carbon metricset
                • Google Cloud Platform compute metricset
                • Google Cloud Platform dataproc metricset
                • Google Cloud Platform firestore metricset
                • Google Cloud Platform gke metricset
                • Google Cloud Platform loadbalancing metricset
                • Google Cloud Platform metrics metricset
                • Google Cloud Platform pubsub metricset
                • Google Cloud Platform storage metricset
                • Google Cloud Platform vertexai_logs metricset
              • Golang module
                • Golang expvar metricset
                • Golang heap metricset
              • Graphite module
                • Graphite server metricset
              • HAProxy module
                • HAProxy info metricset
                • HAProxy stat metricset
              • HTTP module
                • HTTP json metricset
                • HTTP server metricset
              • IBM MQ module
                • IBM MQ qmgr metricset
              • IIS module
                • IIS application_pool metricset
                • IIS webserver metricset
                • IIS website metricset
              • Istio module
                • Istio citadel metricset
                • Istio galley metricset
                • Istio istiod metricset
                • Istio mesh metricset
                • Istio mixer metricset
                • Istio pilot metricset
                • Istio proxy metricset
              • Jolokia module
                • Jolokia jmx metricset
              • Kafka module
                • Kafka broker metricset
                • Kafka consumer metricset
                • Kafka consumergroup metricset
                • Kafka partition metricset
                • Kafka producer metricset
              • Kibana module
                • Kibana cluster_actions metricset
                • Kibana cluster_rules metricset
                • Kibana node_actions metricset
                • Kibana node_rules metricset
                • Kibana stats metricset
                • Kibana status metricset
              • Kubernetes module
                • Kubernetes apiserver metricset
                • Kubernetes container metricset
                • Kubernetes controllermanager metricset
                • Kubernetes event metricset
                • Kubernetes node metricset
                • Kubernetes pod metricset
                • Kubernetes proxy metricset
                • Kubernetes scheduler metricset
                • Kubernetes state_container metricset
                • Kubernetes state_cronjob metricset
                • Kubernetes state_daemonset metricset
                • Kubernetes state_deployment metricset
                • Kubernetes state_horizontalpodautoscaler metricset
                • Kubernetes state_job metricset
                • Kubernetes state_node metricset
                • Kubernetes state_persistentvolumeclaim metricset
                • Kubernetes state_pod metricset
                • Kubernetes state_replicaset metricset
                • Kubernetes state_resourcequota metricset
                • Kubernetes state_service metricset
                • Kubernetes state_statefulset metricset
                • Kubernetes state_storageclass metricset
                • Kubernetes system metricset
                • Kubernetes volume metricset
              • KVM module
                • KVM dommemstat metricset
                • KVM status metricset
              • Linux module
                • Linux conntrack metricset
                • Linux iostat metricset
                • Linux ksm metricset
                • Linux memory metricset
                • Linux pageinfo metricset
                • Linux pressure metricset
                • Linux rapl metricset
              • Logstash module
                • Logstash node metricset
                • Logstash node_stats metricset
              • Memcached module
                • Memcached stats metricset
              • Cisco Meraki module
                • Cisco Meraki device_health metricset
                • Cisco Meraki network_health metricset
              • MongoDB module
                • MongoDB collstats metricset
                • MongoDB dbstats metricset
                • MongoDB metrics metricset
                • MongoDB replstatus metricset
                • MongoDB status metricset
              • MSSQL module
                • MSSQL performance metricset
                • MSSQL transaction_log metricset
              • Munin module
                • Munin node metricset
              • MySQL module
                • MySQL galera_status metricset
                • galera status MetricSet
                • MySQL performance metricset
                • MySQL query metricset
                • MySQL status metricset
              • NATS module
                • NATS connection metricset
                • NATS connections metricset
                • NATS jetstream metricset
                • NATS route metricset
                • NATS routes metricset
                • NATS stats metricset
                • NATS subscriptions metricset
              • Nginx module
                • Nginx stubstatus metricset
              • Openmetrics module
                • Openmetrics collector metricset
              • Oracle module
                • Oracle performance metricset
                • Oracle sysmetric metricset
                • Oracle tablespace metricset
              • Panw module
                • Panw interfaces metricset
                • Panw routing metricset
                • Panw system metricset
                • Panw vpn metricset
              • PHP_FPM module
                • PHP_FPM pool metricset
                • PHP_FPM process metricset
              • PostgreSQL module
                • PostgreSQL activity metricset
                • PostgreSQL bgwriter metricset
                • PostgreSQL database metricset
                • PostgreSQL statement metricset
              • Prometheus module
                • Prometheus collector metricset
                • Prometheus query metricset
                • Prometheus remote_write metricset
              • RabbitMQ module
                • RabbitMQ connection metricset
                • RabbitMQ exchange metricset
                • RabbitMQ node metricset
                • RabbitMQ queue metricset
                • RabbitMQ shovel metricset
              • Redis module
                • Redis info metricset
                • Redis key metricset
                • Redis keyspace metricset
              • Redis Enterprise module
                • Redis Enterprise node metricset
                • Redis Enterprise proxy metricset
              • SQL module
                • Host Setup
                • SQL query metricset
              • Stan module
                • Stan channels metricset
                • Stan stats metricset
                • Stan subscriptions metricset
              • Statsd module
                • Metricsets
                • Statsd server metricset
              • SyncGateway module
                • SyncGateway db metricset
                • SyncGateway memory metricset
                • SyncGateway replication metricset
                • SyncGateway resources metricset
              • System module
                • System core metricset
                • System cpu metricset
                • System diskio metricset
                • System entropy metricset
                • System filesystem metricset
                • System fsstat metricset
                • System load metricset
                • System memory metricset
                • System network metricset
                • System network_summary metricset
                • System process metricset
                • System process_summary metricset
                • System raid metricset
                • System service metricset
                • System socket metricset
                • System socket_summary metricset
                • System uptime metricset
                • System users metricset
                • System ntp metricset
              • Tomcat module
                • Tomcat cache metricset
                • Tomcat memory metricset
                • Tomcat requests metricset
                • Tomcat threading metricset
              • Traefik module
                • Traefik health metricset
              • uWSGI module
                • uWSGI status metricset
              • vSphere module
                • vSphere cluster metricset
                • vSphere datastore metricset
                • vSphere datastorecluster metricset
                • vSphere host metricset
                • vSphere network metricset
                • vSphere resourcepool metricset
                • vSphere virtualmachine metricset
              • Windows module
                • Windows perfmon metricset
                • Windows service metricset
                • Windows wmi metricset
              • ZooKeeper module
                • ZooKeeper connection metricset
                • ZooKeeper mntr metricset
                • ZooKeeper server metricset
            • Exported fields
              • ActiveMQ fields
              • Aerospike fields
              • Airflow fields
              • Apache fields
              • AutoOps ES fields
              • AWS fields
              • AWS Fargate fields
              • Azure fields
              • Beat fields
              • Beat fields
              • Benchmark fields
              • Ceph fields
              • Cloud provider metadata fields
              • Cloudfoundry fields
              • CockroachDB fields
              • Common fields
              • Consul fields
              • Containerd fields
              • Coredns fields
              • Couchbase fields
              • CouchDB fields
              • Docker fields
              • Docker fields
              • Dropwizard fields
              • ECS fields
              • Elasticsearch fields
              • Envoyproxy fields
              • Etcd fields
              • Google Cloud Platform fields
              • Golang fields
              • Graphite fields
              • HAProxy fields
              • Host fields
              • HTTP fields
              • IBM MQ fields
              • IIS fields
              • Istio fields
              • Jolokia fields
              • Jolokia Discovery autodiscover provider fields
              • Kafka fields
              • Kibana fields
              • Kubernetes fields
              • Kubernetes fields
              • KVM fields
              • Linux fields
              • Logstash fields
              • Memcached fields
              • Cisco Meraki fields
              • MongoDB fields
              • MSSQL fields
              • Munin fields
              • MySQL fields
              • NATS fields
              • Nginx fields
              • Openmetrics fields
              • Oracle fields
              • Panw fields
              • PHP_FPM fields
              • PostgreSQL fields
              • Process fields
              • Prometheus fields
              • Prometheus typed metrics fields
              • RabbitMQ fields
              • Redis fields
              • Redis Enterprise fields
              • SQL fields
              • Stan fields
              • Statsd fields
              • SyncGateway fields
              • System fields
              • Tomcat fields
              • Traefik fields
              • uWSGI fields
              • vSphere fields
              • Windows fields
              • ZooKeeper fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
              • Use Linux Secure Computing Mode (seccomp)
            • Troubleshoot
              • Get help
              • Debug
              • Understand logged metrics
              • Common problems
                • open /compat/linux/proc: no such file or directory error on FreeBSD
                • Metricbeat collects system metrics for interfaces you didn't configure
                • Metricbeat uses too much bandwidth
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • Dashboard could not locate the index-pattern
                • High RSS memory usage due to MADV settings
            • Contribute
          • Packetbeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Repositories for APT and YUM
              • Run Packetbeat on Docker
              • Packetbeat and systemd
              • Start Packetbeat
              • Stop Packetbeat
            • Upgrade Packetbeat
            • Configure
              • Traffic sniffing
              • Network flows
              • Protocols
                • Common protocol options
                • ICMP
                • DNS
                • HTTP
                • AMQP
                • Cassandra
                • Memcache
                • MySQL
                • PgSQL
                • Thrift
                • MongoDB
                • TLS
                • Redis
              • Processes
              • General settings
              • Project paths
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Kibana endpoint
              • Kibana dashboards
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_tags
                • append
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • rate_limit
                • registered_domain
                • rename
                • replace
                • syslog
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Internal queue
              • Logging
              • HTTP endpoint
                • Protocol-Specific Metrics
              • Instrumentation
              • Feature flags
              • packetbeat.reference.yml
            • How to guides
              • Load the Elasticsearch index template
              • Change the index name
              • Load Kibana dashboards
              • Enrich events with geoIP information
              • Load ingest pipelines
              • Use environment variables in the configuration
              • Parse data using an ingest pipeline
              • Avoid YAML formatting problems
            • Exported fields
              • AMQP fields
              • Beat fields
              • Cassandra fields
              • Cloud provider metadata fields
              • Common fields
              • DHCPv4 fields
              • DNS fields
              • Docker fields
              • ECS fields
              • Flow Event fields
              • Host fields
              • HTTP fields
              • ICMP fields
              • Jolokia Discovery autodiscover provider fields
              • Kubernetes fields
              • Memcache fields
              • MongoDb fields
              • MySQL fields
              • NFS fields
              • PostgreSQL fields
              • Process fields
              • Raw fields
              • Redis fields
              • SIP fields
              • Thrift-RPC fields
              • Detailed TLS fields
              • Transaction Event fields
              • Measurements (Transactions) fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
              • Use Linux Secure Computing Mode (seccomp)
            • Visualize Packetbeat data in Kibana
              • Customize the Discover page
              • Kibana queries and filters
            • Troubleshoot
              • Get help
              • Debug
              • Understand logged metrics
              • Record a trace
              • Common problems
                • Dashboard in Kibana is breaking up data fields incorrectly
                • Packetbeat doesn't see any packets when using mirror ports
                • Packetbeat Can't capture traffic from Windows loopback interface
                • Packetbeat is missing long running transactions
                • Packetbeat isn't capturing MySQL performance data
                • Packetbeat uses too much bandwidth
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • Dashboard could not locate the index-pattern
                • High RSS memory usage due to MADV settings
                • Fields show up as nested JSON in Kibana
            • Contribute
          • Winlogbeat
            • Quick start
              • Installation script
            • Set up and run
              • Directory layout
              • Secrets keystore
              • Command reference
              • Start Winlogbeat
              • Stop Winlogbeat
            • Upgrade
            • Configure
              • Winlogbeat
              • General settings
              • Project paths
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • File
                • Console
                • Discard
                • Change the output codec
              • Kerberos
              • SSL
              • Index lifecycle management (ILM)
              • Elasticsearch index template
              • Kibana endpoint
              • Kibana dashboards
              • Processors
                • Define processors
                • add_cloud_metadata
                • add_cloudfoundry_metadata
                • add_docker_metadata
                • add_fields
                • add_host_metadata
                • add_id
                • add_kubernetes_metadata
                • add_labels
                • add_locale
                • add_network_direction
                • add_nomad_metadata
                • add_observer_metadata
                • add_process_metadata
                • add_tags
                • append
                • community_id
                • convert
                • copy_fields
                • decode_base64_field
                • decode_duration
                • decode_json_fields
                • decode_xml
                • decode_xml_wineventlog
                • decompress_gzip_field
                • detect_mime_type
                • dissect
                • dns
                • drop_event
                • drop_fields
                • extract_array
                • fingerprint
                • include_fields
                • move_fields
                • now
                • rate_limit
                • registered_domain
                • rename
                • replace
                • script
                • syslog
                • timestamp
                • translate_ldap_attribute
                • translate_sid
                • truncate_fields
                • urldecode
              • Internal queue
              • Logging
              • HTTP endpoint
                • Event Processing Metrics
              • Instrumentation
              • winlogbeat.reference.yml
            • How to guides
              • Enrich events with geoIP information
              • Load the Elasticsearch index template
              • Change the index name
              • Load Kibana dashboards
              • Load ingest pipelines
              • Use environment variables in the configuration
              • Parse data using an ingest pipeline
              • Avoid YAML formatting problems
            • Modules
              • PowerShell Module
              • Security Module
              • Sysmon Module
            • Exported fields
              • Beat fields
              • Cloud provider metadata fields
              • Docker fields
              • ECS fields
              • Legacy Winlogbeat alias fields
              • Host fields
              • Jolokia Discovery autodiscover provider fields
              • Kubernetes fields
              • PowerShell module fields
              • Process fields
              • Security module fields
              • Sysmon module fields
              • Winlogbeat fields
            • Monitor
              • Use internal collection
                • Settings for internal collection
              • Use Metricbeat collection
            • Secure
              • Grant users access to secured resources
                • Create a setup user
                • Create a monitoring user
                • Create a publishing user
                • Create a reader user
                • Learn more about privileges, roles, and users
              • Grant access using API keys
              • Secure communication with Elasticsearch
              • Secure communication with Logstash
            • Troubleshoot
              • Get Help
              • Debug
              • Understand logged metrics
              • Common problems
                • Dashboard in Kibana is breaking up data fields incorrectly
                • Bogus computer_name fields are reported in some events
                • Error loading config file
                • Found unexpected or unknown characters
                • Logstash connection doesn't work
                • Publishing to Logstash fails with "connection reset by peer" message
                • @metadata is missing in Logstash
                • Not sure whether to use Logstash or Beats
                • SSL client fails to connect to Logstash
                • Monitoring UI shows fewer Beats than expected
                • Dashboard could not locate the index-pattern
                • High RSS memory usage due to MADV settings
                • Not sure how to read from .evtx files
            • Contribute
          • Upgrade
          • Community Beats
          • Contribute
          • Elastic logging plugin for Docker
            • Install and configure
            • Configuration options
            • Usage examples
            • Known problems and limitations
        • Other ingest tools
          • Elasticsearch for Apache Hadoop
            • Setup and requirements
              • Key features
              • Requirements
              • Installation
            • Reference
              • Architecture
              • Configuration
              • Runtime options
              • Security
              • Logging
              • Map/Reduce integration
              • Apache Hive integration
              • Apache Spark support
              • Mapping and types
              • Error handlers
              • Kerberos
              • Hadoop metrics
              • Performance considerations
              • Cloud or restricted environments
            • Resources
            • License
          • Elastic Serverless Forwarder for AWS
            • Deploy serverless forwarder
            • Configuration options
      • Data storage and lifecycle
        • The Elasticsearch data store
          • Index basics
            • Index settings reference
            • Index lifecycle management actions
          • Near real-time search
          • Data streams
            • Set up a data stream
            • Use a data stream
            • Modify a data stream
            • Manage a data stream
            • Time series data stream (TSDS)
              • Quickstart
              • Set up TSDS
              • Downsampling
                • Downsampling concepts
                • Run downsampling
                • Query downsampled data
              • Advanced topics
                • Time-bound TSDS
                • Reindex TSDS
                • TSDS ingest OTLP
            • Logs data stream
              • Configure
              • Integrations
            • Failure store
              • Recipes
          • Mapping
            • Mapping reference
            • Dynamic mapping
              • Dynamic field mapping
              • Dynamic templates
            • Explicit mapping
            • Runtime fields
              • Map a runtime field
              • Define in search request
              • Override values at query time
              • Retrieve a runtime field
              • Index a runtime field
              • Explore data with runtime fields
            • Removal of mapping types
            • Update mappings examples
          • Text analysis
            • Text analysis components
            • Concepts
              • Anatomy of an analyzer
              • Index and search analysis
              • Stemming
              • Token graphs
            • Configure text analysis
              • Test an analyzer
              • Configuring built-in analyzers
              • Create custom analyzer
              • Specify an analyzer
          • Templates
            • Simulate multi-component templates
            • Ignore missing component templates
          • Aliases
          • Perform index operations
            • Index operations reference
          • Manage data from the command line
        • Data lifecycle
          • Data tiers: hot warm cold frozen
          • Index lifecycle management (ILM)
            • Index lifecycle
            • Rollover
              • Skip rollover
            • Configure lifecycle policy
            • Apply policy
            • View policy status
            • Manage integrations data
            • Policy updates
            • Start and stop ILM
            • Restore managed index
            • ILM tutorials
              • Time series with data streams
              • Time series without data streams
              • General content with data streams
              • Customize built-in policies
            • Migrate ILM
              • Migrate index management
              • Manage existing indices
              • Migrate allocation filters to node roles
          • Data stream lifecycle
            • Tutorial: Create with lifecycle
            • Tutorial: Update existing
            • Tutorial: Retention
            • Tutorial: Migrate from ILM
          • Elasticsearch Curator
          • Rollup
            • Getting started (API)
            • Getting started (Kibana)
            • Understanding groups
            • Aggregation limitations
            • Search limitations
            • Migrating to downsampling
        • Use case: time series data management
      • Transform and enrich data
        • Data pipelines
          • Managed pipelines (mOTLP)
          • Elasticsearch ingest pipelines
            • Example: Parse logs
            • Readable maintainable pipelines
            • Error handling
          • Logstash pipelines
        • Data enrichment
          • Set up an enrich processor
          • Example: Enrich by geolocation
          • Example: Enrich by exact values
          • Example: Enrich by matching value to range
        • Index mapping and text analysis
        • Calculate ingest lag metadata
    • Search, visualize and analyze
      • Search and query
        • Get started with search
          • Quickstarts
            • Index basics
            • Keyword search with Python
            • Semantic search
        • Search approaches
          • Full-text search
            • How full-text search works
            • Text analysis during search
            • Search relevance
              • Mix exact search with stemming
              • Consistent scoring
              • Static scoring signals
            • Synonyms
              • Create and update synonyms via API
          • Vector search
            • Dense vector search
              • k-nearest neighbor (kNN)
              • Bring your own vectors
            • Sparse vector search
            • Dense vs sparse ingest pipelines
            • Semantic search
              • Semantic search with semantic_text
              • Semantic search with the inference API
              • Semantic search with ELSER
              • Semantic search with Cohere
            • Using OpenAI-compatible models
          • Hybrid search
            • Hybrid search with semantic_text
          • Ranking and reranking
            • Semantic reranking
            • Learning to rank
              • Train an LTR model
              • Use LTR in search
        • Ingest for search
          • Search pipelines
        • Build search queries
          • The search API
            • Search templates
            • Aggregations
              • Tutorial — analyze e-commerce data
          • Retrievers
          • ES|QL for search
          • Async search
          • Query languages
            • Query DSL
            • KQL
            • EQL
              • Detect threats with EQL
            • SQL
            • Lucene query syntax
          • Query languages
            • Query DSL
              • Get started
              • Query and filter context
              • Compound queries
                • Boolean
                • Boosting
                • Constant score
                • Disjunction max
                • Function score
              • Full text queries
                • Intervals
                • Match
                • Match boolean prefix
                • Match phrase
                • Match phrase prefix
                • Combined fields
                • Multi-match
                • Query string
                • Simple query string
                • KQL
              • Geo queries
                • Geo-bounding box
                • Geo-distance
                • Geo-grid
                • Geo-polygon
                • Geoshape
              • Shape queries
                • Shape
              • Joining queries
                • Nested
                • Has child
                • Has parent
                • Parent ID
              • Match all
              • Span queries
                • Span containing
                • Span field masking
                • Span first
                • Span multi-term
                • Span near
                • Span not
                • Span or
                • Span term
                • Span within
              • Vector queries
                • Knn
                • Dense vector
                • Sparse vector
                • Semantic
                • Text expansion
                • Weighted tokens
              • Specialized queries
                • Distance feature
                • more_like_this
                • Percolate
                • Rank feature
                • Script
                • Script score
                • Wrapper
                • Pinned query
                • Rule
              • Term-level queries
                • Exists
                • Fuzzy
                • IDs
                • Prefix
                • Range
                • Regexp
                • Term
                • Terms
                • Terms set
                • Wildcard
              • minimum_should_match parameter
              • rewrite parameter
              • Regular expression syntax
            • ES|QL
              • Get started
              • Use cases
                • ES|QL for search
                • ES|QL for cybersecurity
              • REST API
              • Syntax reference
                • Basic syntax
                • Query directives
                  • SET
                • Commands
                  • Source commands
                    • FROM
                    • PROMQL
                    • ROW
                    • SHOW
                    • TS
                  • Processing commands
                    • CHANGE_POINT
                    • COMPLETION
                    • DISSECT
                    • DROP
                    • ENRICH
                    • EVAL
                    • FORK
                    • FUSE
                    • GROK
                    • INLINE STATS
                    • IP_LOCATION
                    • KEEP
                    • LIMIT
                    • LOOKUP JOIN
                    • METRICS_INFO
                    • MMR
                    • MV_EXPAND
                    • REGISTERED_DOMAIN
                    • RENAME
                    • RERANK
                    • SAMPLE
                    • SORT
                    • STATS
                    • TS_INFO
                    • TS_COLLAPSE
                    • USER_AGENT
                    • URI_PARTS
                    • WHERE
                • Functions and operators
                  • Aggregation functions
                    • ABSENT
                    • AVG
                    • COUNT
                    • COUNT_DISTINCT
                    • EARLIEST
                    • FIRST
                    • LAST
                    • LATEST
                    • MAX
                    • MEDIAN
                    • MEDIAN_ABSOLUTE_DEVIATION
                    • MIN
                    • PERCENTILE
                    • PRESENT
                    • SAMPLE
                    • SPARKLINE
                    • ST_CENTROID_AGG
                    • ST_EXTENT_AGG
                    • STD_DEV
                    • SUM
                    • TOP
                    • VALUES
                    • VARIANCE
                    • WEIGHTED_AVG
                  • Time series aggregation functions
                    • ABSENT_OVER_TIME
                    • AVG_OVER_TIME
                    • COUNT_OVER_TIME
                    • COUNT_DISTINCT_OVER_TIME
                    • DELTA
                    • DERIV
                    • FIRST_OVER_TIME
                    • IDELTA
                    • INCREASE
                    • IRATE
                    • LAST_OVER_TIME
                    • MAX_OVER_TIME
                    • MIN_OVER_TIME
                    • PERCENTILE_OVER_TIME
                    • PRESENT_OVER_TIME
                    • RATE
                    • STDDEV_OVER_TIME
                    • VARIANCE_OVER_TIME
                    • SUM_OVER_TIME
                  • Grouping functions
                    • BUCKET
                    • TBUCKET
                    • CATEGORIZE
                    • WITHOUT
                  • Conditional functions and expressions
                    • CASE
                    • COALESCE
                    • GREATEST
                    • LEAST
                    • CLAMP
                    • CLAMP_MIN
                    • CLAMP_MAX
                  • Date-time functions
                    • DATE_DIFF
                    • DATE_EXTRACT
                    • DATE_FORMAT
                    • DATE_PARSE
                    • DATE_TRUNC
                    • DAY_NAME
                    • MONTH_NAME
                    • NOW
                    • RANGE_MAX
                    • RANGE_MIN
                    • RANGE_WITHIN
                    • RANGE_CONTAINS
                    • RANGE_INTERSECTS
                    • TRANGE
                  • IP functions
                    • CIDR_MATCH
                    • IP_PREFIX
                  • Math functions
                    • ABS
                    • ACOS
                    • ACOSH
                    • ASIN
                    • ASINH
                    • ATAN
                    • ATAN2
                    • ATANH
                    • CBRT
                    • CEIL
                    • COPY_SIGN
                    • COS
                    • COSH
                    • E
                    • EXP
                    • FLOOR
                    • HYPOT
                    • LOG
                    • LOG10
                    • PI
                    • POW
                    • ROUND
                    • ROUND_TO
                    • SCALB
                    • SIGNUM
                    • SIN
                    • SINH
                    • SQRT
                    • TAN
                    • TANH
                    • TAU
                  • Search functions
                    • DECAY
                    • KQL
                    • MATCH
                    • MATCH_PHRASE
                    • QSTR
                    • SCORE
                    • TOP_SNIPPETS
                  • Spatial functions
                    • ST_DISTANCE
                    • ST_INTERSECTS
                    • ST_DISJOINT
                    • ST_CONTAINS
                    • ST_WITHIN
                    • ST_X
                    • ST_Y
                    • ST_NPOINTS
                    • ST_BUFFER
                    • ST_SIMPLIFY
                    • ST_SIMPLIFYPRESERVETOPOLOGY
                    • ST_GEOMETRYTYPE
                    • ST_DIMENSION
                    • ST_ISEMPTY
                    • ST_UNION
                    • ST_INTERSECTION
                    • ST_DIFFERENCE
                    • ST_SYMDIFFERENCE
                    • ST_ENVELOPE
                    • ST_XMAX
                    • ST_XMIN
                    • ST_YMAX
                    • ST_YMIN
                    • ST_GEOTILE
                    • ST_GEOHEX
                    • ST_GEOHASH
                  • String functions
                    • BIT_LENGTH
                    • BYTE_LENGTH
                    • CHUNK
                    • CONCAT
                    • CONTAINS
                    • ENDS_WITH
                    • FIELD_EXTRACT
                    • FROM_BASE64
                    • HASH
                    • JSON_EXTRACT
                    • LEFT
                    • LENGTH
                    • LOCATE
                    • LTRIM
                    • MD5
                    • REPEAT
                    • REPLACE
                    • REVERSE
                    • RIGHT
                    • RTRIM
                    • SHA1
                    • SHA256
                    • SPACE
                    • SPLIT
                    • STARTS_WITH
                    • SUBSTRING
                    • TO_BASE64
                    • TO_LOWER
                    • TO_UPPER
                    • TRIM
                    • URL_ENCODE
                    • URL_ENCODE_COMPONENT
                    • URL_DECODE
                  • Dense vector functions
                    • EMBEDDING
                    • KNN
                    • TEXT_EMBEDDING
                    • V_COSINE
                    • V_DOT_PRODUCT
                    • V_HAMMING
                    • V_L1_NORM
                    • V_L2_NORM
                  • Type conversion functions
                    • TO_AGGREGATE_METRIC_DOUBLE
                    • TO_BOOLEAN
                    • TO_CARTESIANPOINT
                    • TO_CARTESIANSHAPE
                    • TO_COUNTER
                    • TO_DATEPERIOD
                    • TO_DATETIME
                    • TO_DATE_NANOS
                    • TO_DATE_RANGE
                    • TO_DEGREES
                    • TO_DENSE_VECTOR
                    • TO_DOUBLE
                    • TO_EXPONENTIAL_HISTOGRAM
                    • TO_GAUGE
                    • TO_GEOHASH
                    • TO_GEOHEX
                    • TO_GEOPOINT
                    • TO_GEOSHAPE
                    • TO_GEOTILE
                    • TO_INTEGER
                    • TO_IP
                    • TO_LONG
                    • TO_RADIANS
                    • TO_RANGE
                    • TO_STRING
                    • TO_TDIGEST
                    • TO_TEXT
                    • TO_TIMEDURATION
                    • TO_UNSIGNED_LONG
                    • TO_VERSION
                  • Multivalue functions
                    • MV_APPEND
                    • MV_AVG
                    • MV_CONCAT
                    • MV_CONTAINS
                    • MV_COUNT
                    • MV_DEDUPE
                    • MV_DIFFERENCE
                    • MV_FIRST
                    • MV_IN_RANGE
                    • MV_INTERSECTION
                    • MV_INTERSECTS
                    • MV_LAST
                    • MV_LIKE
                    • MV_MAX
                    • MV_MEDIAN
                    • MV_MEDIAN_ABSOLUTE_DEVIATION
                    • MV_MIN
                    • MV_PERCENTILE
                    • MV_PSERIES_WEIGHTED_SUM
                    • MV_RLIKE
                    • MV_SLICE
                    • MV_SORT
                    • MV_SUM
                    • MV_UNION
                    • MV_ZIP
                  • Operators
              • Optimize query performance
                • Approximate STATS queries
              • Query multiple sources
                • Query multiple indices
                • Query across clusters
                • Query across serverless projects
                • Use subqueries in a FROM command
                • Define virtual indices using ES|QL views
              • Data Federation
                • Quickstart
                • Connect data sources
                  • AWS federated identity
                  • AWS static credentials
                • Add datasets
                • Query datasets
                • Manage access
                • Cluster settings
              • Advanced workflows
                • Extract data with DISSECT and GROK
                • Combine data with ENRICH
                • Join data with LOOKUP JOIN
                • Use IN subqueries in a WHERE command
              • Types and fields
                • Implicit casting
                • Time spans
                • Metadata fields
                • NULL values
                • Multivalued fields
                • Unmapped fields
              • Tutorials
                • ES|QL for search
                • ES|QL for threat hunting
              • Troubleshooting
                • Query log
                • List running queries
              • Limitations
            • PromQL
              • HTTP API
              • Functions
                • Range vector functions
                • Aggregation functions
                • Histogram functions
                • Math functions
                • Date and time functions
                • Conversion functions
              • Operators
                • Arithmetic operators
                • Comparison operators
                • Logical/set operators
                • Unary operators
                • Label matching operators
              • Prometheus data source in Grafana
              • Limitations
            • SQL
              • Getting started
              • Conventions
              • Security
              • SQL REST API
                • Overview
                • Response data formats
                • Paginating through a large response
                • Filtering using Elasticsearch Query DSL
                • Columnar results
                • Passing parameters to a query
                • Use runtime fields
                • Run an async SQL search
              • SQL Translate API
              • SQL CLI
              • SQL JDBC
                • API usage
              • SQL ODBC
                • Driver installation
                • Configuration
              • SQL client applications
                • DBeaver
                • DbVisualizer
                • Microsoft Excel
                • Microsoft Power BI Desktop
                • Microsoft PowerShell
                • MicroStrategy Desktop
                • Qlik Sense Desktop
                • SQuirreL SQL
                • SQL Workbench/J
                • Tableau Desktop
                • Tableau Server
              • SQL language
                • Lexical structure
                • SQL commands
                • DESCRIBE TABLE
                • SELECT
                • SHOW CATALOGS
                • SHOW COLUMNS
                • SHOW FUNCTIONS
                • SHOW TABLES
                • Data types
                • Index patterns
                • Frozen indices
              • Functions and operators
                • Comparison operators
                • Logical operators
                • Math operators
                • Cast operators
                • LIKE and RLIKE operators
                • Aggregate functions
                • Grouping functions
                • Date/time and interval functions and operators
                • Full-text search functions
                • Mathematical functions
                • String functions
                • Type conversion functions
                • Geo functions
                • Conditional functions and expressions
                • System functions
              • Reserved keywords
              • SQL limitations
            • EQL
              • Syntax reference
              • Function reference
              • Pipe reference
            • Kibana Query Language
          • Developer tools
            • Console
            • Search Profiler
            • Saved queries
        • Cross-cluster search
          • Using the resolve cluster endpoint
        • Cross-project search
          • Link projects
          • Search across projects
          • Using tags to control search
          • Project routing
        • Integrate with your app
          • Client libraries
          • Search UI
          • APIs and tools
      • Explore and visualize
        • Learn data exploration and visualization
        • Discover
          • Explore fields and data with Discover
          • Customize the Discover view
          • Search for relevance
          • Save a search for reuse
          • View field statistics
          • Run a pattern analysis on your log data
          • Run queries in the background
          • Using ES|QL
        • Dashboards
          • Exploring dashboards
          • Building dashboards
            • Create a dashboard
            • Edit a dashboard
            • Add filter controls
            • Add drilldowns
            • Organize dashboard panels
            • Duplicate a dashboard
            • Import a dashboard
          • Managing dashboards
          • Sharing dashboards
          • Tutorials
            • Create a simple dashboard to monitor website logs
            • Create a dashboard with time series charts
        • Panels and visualizations
          • Visualize Library
          • Manage panels
          • Lens
            • Area charts
            • Bar charts
            • Heat map charts
            • Gauge charts
            • Line charts
            • Metric charts
            • Mosaic charts
            • Pie charts
            • Region map charts
            • Tables
            • Waffle charts
            • Tag cloud charts
            • Treemap charts
          • ES|QL
          • Custom visualizations with Vega
          • Text panels
          • Image panels
          • Link panels
          • Alert panels
          • Canvas
            • Edit workpads
            • Present your workpad
            • Tutorial: Create a workpad for monitoring sales
            • Canvas function reference
              • TinyMath functions
          • Maps
            • Build a map to compare metrics by country or region
            • Track, visualize, and alert on assets in real time
            • Map custom regions with reverse geocoding
            • Heat map layer
            • Tile layer
            • Vector layer
              • Vector styling
              • Vector style properties
              • Vector tooltips
            • Map aggregations
              • Clusters
              • Display the most relevant documents per entity
              • Point to point
              • Term join
            • Search and filter maps
              • Create filters from a map
              • Filter a single layer
              • Search across multiple indices
            • Configure map settings
            • Connect to Elastic Maps Service
            • Import geospatial data
              • Clean your data
              • Tutorial: Index GeoJSON data
            • Troubleshoot
          • Graph
            • Configure Graph
            • Troubleshooting and limitations
          • Legacy editors
            • Aggregation-based
            • TSVB
            • Timelion
        • Find and organize content
          • Data views
          • Saved objects
          • Files
          • Reports
          • Tags
          • Find apps and objects
      • Track and respond
        • Reporting and sharing
          • Automatically generate reports
          • Reporting troubleshooting
            • CSV
            • PDF/PNG
        • Alerting
          • Alerts
            • Getting started with alerts
            • Set up
            • Create and manage rules
            • View and manage alerts
            • Query alert indices
            • Rule types
              • Index threshold
              • Elasticsearch query
              • Tracking containment
            • Rule action variables
            • Notifications domain allowlist
            • Alerting troubleshooting
              • Common issues
              • Event log index
              • Test connectors
            • Maintenance windows
          • Watcher
            • Getting started with Watcher
            • How Watcher works
            • Enable Watcher
            • Watcher UI
            • Encrypting sensitive data in Watcher
            • Input
              • Simple input
              • Search input
              • HTTP input
              • Chain input
            • Trigger
              • Schedule trigger
              • Throttling
              • Schedule Types
            • Condition
              • Always condition
              • Never condition
              • Compare condition
              • Array compare condition
              • Script condition
            • Actions
              • Running an action for each element in an array
              • Adding conditions to actions
              • Email action
              • Webhook action
              • Index action
              • Logging action
              • Slack action
              • PagerDuty action
              • Jira action
            • Transform
              • Search payload transform
              • Script payload transform
              • Chain payload transform
            • Managing watches
            • Example watches
              • Watching the status of an Elasticsearch cluster
              • Execute a watch
            • Limitations
        • Cases
          • Control access
          • Create cases
          • Manage cases
          • Attach objects
          • Search and share
          • Configure settings
          • Cases as data
    • Automate
      • Workflows
        • Set up workflows
        • Get started with workflows
        • Core components
          • Triggers
            • Manual triggers
            • Scheduled triggers
            • Alert triggers
          • Steps
            • Action steps
              • Elasticsearch
              • Kibana
              • External systems and apps
            • Flow control steps
              • If
              • Foreach
              • Wait
            • AI steps
        • Data and error handling
          • Templating engine
        • Author workflows
        • Monitor and troubleshoot workflows
        • Manage workflows
        • Workflow templates
    • AI and machine learning
      • Machine Learning and NLP
        • Setup and security
        • Anomaly detection
          • Finding anomalies
            • Plan your analysis
            • Run a job
            • View the results
            • Forecast future behavior
          • Tutorial
          • Concepts
            • Anomaly detection algorithms
            • Anomaly score explanation
            • Job types
            • Working with anomaly detection at scale
            • Handling delayed data
          • API quick reference
          • How-tos
            • Generating alerts for anomaly detection jobs
            • Aggregating data for faster performance
            • Altering data in your datafeed with runtime fields
            • Customizing detectors with custom rules
            • Detecting anomalous categories of data
            • Performing population analysis
            • Reverting to a model snapshot
            • Detecting anomalous locations in geographic data
            • Mapping anomalies by location
            • Adding custom URLs to machine learning results
            • Anomaly detection jobs from visualizations
          • Resources
            • Limitations
            • Analysis function reference
            • Supplied configurations
            • Troubleshooting and FAQ
        • Data frame analytics
          • Overview
          • Finding outliers
          • Predicting numerical values with regression
          • Predicting classes with classification
          • Concepts
            • How data frame analytics jobs work
            • Working with data frame analytics at scale
            • Adding custom URLs to data frame analytics jobs
            • Feature encoding
            • Feature processors
            • Feature importance
            • Loss functions for regression analyses
            • Hyperparameter optimization
            • Trained models
          • API quick reference
          • Resources
            • Limitations
        • NLP
          • Overview
            • Extract information
            • Classify text
            • Search and compare text
          • Deploy models
            • Select a trained model
            • Import the trained model and vocabulary
            • Deploy the model in your cluster
            • Try it out
          • Add NLP inference to ingest pipelines
          • API quick reference
          • Built-in models
            • ELSER
            • Jina
            • Elastic Rerank
            • E5
            • Language identification
          • Compatible third party models
          • Examples
            • End-to-end tutorial
            • Named entity recognition
            • Text embedding and semantic search
          • Limitations
        • Machine learning in Kibana
          • AIOps Labs
          • Inference processing
      • Agent builder
        • Get started
        • Models
        • Chat
          • Chat UI modes
        • Agents
          • Custom agents
          • Built-in agents
          • Prompting best practices
          • Call agents from workflows
        • Tools
          • Built-in tools
          • Custom tools
            • ES|QL tools
            • Index search tools
            • MCP tools
            • Workflow tools
        • Programmatic access
          • Kibana API
            • Kibana API tutorial
          • A2A server
          • MCP server
        • Monitor token usage
        • Permissions
        • Troubleshooting
          • Context length exceeded
          • 403 Forbidden
        • Limitations
      • Elastic Inference Service
        • Elastic Inference Service
          • EIS for self-managed clusters
        • Inference integrations
      • AI chat and LLM configuration
        • AI chat experiences
          • Compare Agent Builder and AI Assistant
          • AI assistants
        • LLM providers
          • Connect to Azure OpenAI
          • Connect to Amazon Bedrock
          • Connect to OpenAI
          • Connect to Google Vertex
          • Local LLMs
            • Connect to LM Studio for Observability
            • Connect to LM Studio for Elastic Security
            • Connect to vLLM for Elastic Security
        • Manage access to AI features
      • AI agent skills for Elastic
  • Solutions and project types
    • Solutions overview
    • Elasticsearch solution
      • Get started
        • Find connection details
      • Playground
        • Optimize model context
        • View and modify queries
        • Troubleshooting
      • AI Assistant
      • Query rules UI
      • Search Applications
        • Search API and templates
        • Security
        • Search Application client guide
      • Add-ons
    • Observability solution
      • Get started
        • Elastic Observability quickstarts
          • Quickstart: Monitor hosts with OpenTelemetry
          • Quickstart: Monitor your application performance
          • Quickstart: Unified Kubernetes Observability with Elastic Distributions of OpenTelemetry (EDOT)
          • Quickstart: Send OTLP data to Elastic Serverless or Elastic Cloud Hosted
          • Quickstart: Create a Synthetic Monitor
          • Quickstart: Monitor hosts with Elastic Agent
          • Quickstart: Monitor your Kubernetes cluster with Elastic Agent
          • Quickstart: Collect data with AWS Firehose
        • OpenTelemetry quickstarts
          • Ingest custom metrics with EDOT
          • Self-managed
            • Kubernetes
            • Hosts / VMs
            • Docker
          • Elastic Cloud Serverless
            • Kubernetes
            • Hosts and VMs
            • Docker
          • Elastic Cloud Hosted
            • Kubernetes
            • Hosts and VMs
            • Docker
        • OpenTelemetry use cases
          • Kubernetes observability
            • Prerequisites and compatibility
            • Components description
            • Deployment
            • Instrumenting Applications
            • Upgrade
            • Customization
          • LLM observability
        • Other Observability tutorials
          • Tutorial: Monitor a Java application
        • Logs Essentials
      • Applications and services
        • Application performance monitoring (APM)
          • Get started with traces and APM
          • Application data types
            • Spans
            • Transactions
              • Transaction sampling
            • Traces
            • Errors
            • Metrics
            • Metadata
          • Collect application data
            • OpenTelemetry
              • Contrib OpenTelemetry Collectors and language SDKs
              • Collect metrics
              • Create APM agent key for EDOT SDKs
              • Centrally configure EDOT SDKs
              • Limitations
              • Attributes and labels
              • Data stream routing
            • APM agents
              • Centrally configure APM agents
              • Real User Monitoring (RUM)
              • Create and upload source maps (RUM)
            • Kubernetes
            • AWS Lambda Functions
            • Jaeger (deprecated)
          • View and analyze data
            • Overviews
              • Services
              • Traces UI
              • Dependencies
              • Service Map
              • Service overview
              • Mobile service overview
            • Drill down into data
              • Transactions UI
              • Trace sample timeline
              • Errors UI
              • Metrics UI
              • Infrastructure
              • Logs
            • Discover traces
            • Filter and search data
              • Filters
              • Advanced queries
              • Cross-cluster search
            • Interpret data
              • Find transaction latency and failure correlations
              • Track deployments with annotations
              • Explore mobile sessions with Discover
              • Observe Lambda functions
            • Integrate with machine learning
            • APM Agent explorer
            • Settings
          • Act on data
            • Create rules and alerts
            • Create custom links
          • Use APM securely
            • Secure data
              • Control access to APM data
              • Built-in data filters
              • Custom filters
              • Delete sensitive data
            • Secure communication with APM agents
              • APM agent TLS communication
              • API keys
              • Secret token
              • Anonymous authentication
            • Secure communication with the Elastic Stack
              • Use feature roles
              • Grant access using API keys
            • Secure access to the Applications UI
              • Create an APM reader user
              • Create an annotation user
              • Create an API user
              • Create a central config user
              • Create a storage explorer user
          • Manage storage
            • Storage Explorer
            • Data streams
            • Index lifecycle management
            • View the Elasticsearch index template
            • Parse data using ingest pipelines
            • Storage and sizing guide
            • Reduce storage
            • Explore data in Elasticsearch
          • Work with APM Server
            • Set up
              • Fleet-managed APM Server
              • APM Server binary
            • Configure
              • General configuration options
              • Anonymous authentication
              • APM agent authorization
              • Configure APM Agent Central Configuration
              • Instrumentation
              • Kibana endpoint
              • Logging
              • Output
                • Elastic Cloud Hosted
                • Elasticsearch
                • Logstash
                • Kafka
                • Redis
                • Console
              • Project paths
              • Real User Monitoring (RUM)
              • SSL/TLS settings
                • SSL/TLS output settings
                • SSL/TLS input settings
              • Tail-based sampling
              • Use environment variables in the configuration
              • Advanced setup
                • Installation layout
                • Secrets keystore
                • Command reference
                • Tune data ingestion
                • High Availability
                • APM Server and systemd
            • Monitor
              • Fleet-managed
              • APM Server binary
                • Use internal collection
                • Use Metricbeat collection
                • Use local collection
          • APM APIs
            • APM UI API
            • APM Server API
              • APM Server information API
              • Elastic APM events intake API
              • Elastic APM agent configuration API
              • OpenTelemetry intake API
              • Jaeger event intake
            • Managed intake service event API
          • Upgrade
            • APM agent compatibility
            • Upgrade to version 9.0 [apm-upgrading-to-9.0]
              • Self-installation standalone
              • Self-installation APM integration
              • Elastic Cloud standalone
              • Elastic Cloud APM integration
            • Switch to the Elastic APM integration
              • Switch a self-installation
              • Switch an Elastic Cloud cluster
        • Synthetic monitoring
          • Get started
            • Use a Synthetics project
            • Use the Synthetics UI
          • Scripting browser monitors
            • Write a synthetic test
            • Configure individual monitors
            • Use the Synthetics Recorder
          • Configure lightweight monitors
          • Manage monitors
          • Work with params and secrets
          • Analyze monitor data
          • Monitor resources on private networks
          • Use the CLI
          • Configure a Synthetics project
          • Multi-factor Authentication
          • Configure Synthetics settings
          • Grant users access to secured resources
            • Setup role
            • Writer role
            • Reader role
          • Manage data retention
          • Use Synthetics with network security
          • Migrate from the Elastic Synthetics integration
          • Scale and architect a deployment
          • Synthetics support matrix
          • Synthetics Encryption and Security
        • Real user monitoring
          • OpenTelemetry for Real User Monitoring (RUM)
        • LLM and agentic AI observability
        • Uptime monitoring (deprecated)
          • Get started
          • Analyze
            • View monitor status
            • Analyze monitors
            • Inspect uptime duration anomalies
          • Configure settings
        • Visualize OpenTelemetry data
      • CI/CD
      • Cloud
        • AWS
          • Ingestion options
          • Monitor AWS with Elastic Agent
            • EC2
            • Kinesis data streams
            • S3
            • SQS
          • Monitor AWS with Beats
          • Monitor AWS with Amazon Data Firehose
            • VPC Flow Logs
            • CloudTrail logs
            • Network Firewall logs
            • WAF logs
            • CloudWatch logs
          • Monitor AWS with Elastic Serverless Forwarder
        • Azure
          • Monitor Microsoft Azure with Elastic Agent
          • Monitor Microsoft Azure with Beats
          • Ingest multi-tenant Azure Event Hub logs with Filebeat
          • Monitor Microsoft Azure with the Azure Native ISV Service
          • Monitor Microsoft Azure OpenAI
        • GCP
          • GCP Dataflow templates
      • Infrastructure and hosts
        • Analyze infrastructure and host metrics
          • Get started with system metrics
          • View infrastructure metrics by resource type
          • Explore metrics data with Discover in Kibana
          • Explore infrastructure metrics over time
          • Analyze and compare hosts
          • Detect metric anomalies
          • Configure settings
        • Universal Profiling
          • Get started
          • Manage data storage
            • Index lifecycle management
            • Configure probabilistic profiling
          • Advanced configuration
            • Tag data for querying
            • Add symbols for native frames
            • Use a proxy
            • Override kernel version check
            • Environment variables to configure the Universal Profiling Agent
            • Configuration file of the Universal Profiling Agent
          • Upgrade
          • Self-hosted infrastructure
          • Install the backend
            • Step 1: Update the stack
            • Step 2: Enable Universal Profiling in Kibana
            • Step 3: Set up Universal Profiling in Kibana
            • Step 4: Run the backend applications
            • Step 5: Next steps
          • Operate the backend
        • Tutorial: Observe your Kubernetes deployments
        • Tutorial: Observe your nginx instances
          • Understanding "no results found" message
        • Collect NGINX data with OpenTelemetry integrations (Fleet-managed)
        • Collect NGINX data with OpenTelemetry integrations (standalone)
      • Logs
        • Get started with system logs
        • Send any log file using Elastic Agent
        • Send any log file using OTel Collector
        • Send application log data
          • Plaintext application logs
          • ECS formatted application logs
          • APM agent log sending
        • Parse and route logs using ingest pipelines
        • Filter and aggregate logs
        • Explore logs
          • Explore logs in Discover
          • Categorize log entries
          • Inspect log anomalies
        • Run a pattern analysis on log data
        • Configure log data sources
        • Configure log data retention
        • Add a service name to logs
        • Logs index template reference
          • Default `logs` index template
      • Streams
      • Manage data retention
      • Process documents
        • Drop document processor
        • Remove processor
        • Date processor
        • Convert processor
        • Replace processor
        • Dissect processor
        • Grok processor
        • Set processor
        • Math processor
        • Rename processor
        • Append processor
        • Concat processor
        • Join processor
        • Lowercase processor
        • Uppercase processor
        • Trim processor
        • Redact processor
        • Network direction processor
        • Manual pipeline configuration
      • Streamlang
      • Partition data into child streams
      • Map fields
      • Manage data quality
      • Configure advanced settings
      • Wired streams
      • Incident management
        • Alerting
          • Create and manage rules
            • Anomaly detection
            • APM anomaly
            • Custom threshold
            • Degraded docs
            • Elasticsearch query
            • Error count threshold
            • Failed transaction rate threshold
            • Failed docs
            • Inventory
            • Latency threshold
            • Log threshold
            • Metric threshold
            • Monitor Status
            • TLS certificate
            • Uptime duration anomaly
            • SLO burn rate
          • Aggregation options
            • Rate aggregation
          • View and manage alerts
            • SLO burn rate breaches
            • Threshold breaches
        • Cases
        • Service-level objectives (SLOs)
          • Configure SLO access
          • Create an SLO
          • View and manage SLOs
          • Configure SLOs settings
      • Data set quality
      • AI for Observability
        • AI Assistant
        • Agent Builder for Observability
        • Large language model performance matrix
      • Serverless feature tiers
      • APIs
    • Security solution
      • Get started
        • Elastic Security quickstarts
          • Detect and respond to threats with SIEM
          • Protect your hosts with endpoint security
          • Secure your cloud assets with cloud security posture management
        • Elastic Security requirements
        • Elastic Security UI
        • Ingest data to Elastic Security
          • Enable threat intelligence integrations
          • Automatic migration
          • Automatic import
          • Content connectors
        • Spaces and Elastic Security
          • Spaces and Elastic Defend FAQ
        • Data views and Elastic Security
        • Create runtime fields in Elastic Security
        • Configure advanced settings
      • ES|QL for security
        • Tutorial: Threat hunting with ES|QL
      • AI for security
        • Elastic AI SOC Engine
          • Triage alerts
          • Upgrade from EASE to Elastic Security
        • AI Assistant for Security
          • AI Assistant Knowledge Base
          • Use AI Assistant's Knowledge Base to improve response quality
        • Agent Builder for Elastic Security
        • Attack Discovery
        • Large language model performance matrix
        • AI use cases
          • Triage alerts
          • Identify, investigate, and document threats
          • Generate, customize, and learn about ES|QL queries
        • Value report
      • Detections and alerts
        • Before you begin
          • Turn on detections
          • Detections privileges
          • Detection rule concepts
          • Advanced data source configuration
            • Cross-cluster search and detection rules
            • Using logsdb index mode with Elastic Security
        • MITRE ATT&CK coverage
        • Prebuilt rules
          • Prebuilt rule components
          • Install prebuilt rules
          • Update prebuilt rules
          • Prebuilt rules in air-gapped environments
          • Customize prebuilt rules
        • Author rules
          • Choose the right rule type
            • About building block rules
          • Rule type guides
            • ES|QL rules
            • Custom query rules
            • Event correlation (EQL) rules
            • Indicator match rules
            • Threshold rules
            • Machine learning rules
            • New terms rules
          • Using the UI
          • Using the API
          • Common rule settings
          • Set rule data sources
          • Write investigation guides
          • Validate and test rules
        • Manage detection rules
        • Monitor rule executions
          • Fill rule execution gaps
        • Reduce noise and false positives
          • Tune detection rules
          • Rule exceptions
            • Create and manage value lists
            • Add and manage exceptions
            • Create and manage shared exception lists
          • Suppress detection alerts
        • Manage detection alerts
          • Visualize detection alerts
          • View detection alert details
          • Query alert indices
      • Configure endpoint protection with Elastic Defend
        • Elastic Defend requirements
        • Install Elastic Defend
          • Enable access on macOS
          • Deploy on macOS with MDM
          • Prevent Elastic Agent uninstallation
        • Elastic Defend feature privileges
        • Configure an integration policy for Elastic Defend
          • Configure updates for protection artifacts
          • Turn off diagnostic data for Elastic Defend
          • Configure self-healing rollback for Windows endpoints
          • Configure Linux file system monitoring
          • Configure data volume
          • Create an Elastic Defend policy using API
        • Configure offline endpoints and air-gapped environments
        • Uninstall Elastic Agent
      • Manage Elastic Defend
        • Endpoints
        • Policies
        • Trusted applications
        • Trusted devices
        • Event filters
        • Host isolation exceptions
        • Blocklist
        • Optimize Elastic Defend
        • Event capture and Elastic Defend
        • Endpoint protection rules
        • Automatic troubleshooting
        • Allowlist Elastic Endpoint in third-party antivirus apps
        • Elastic Endpoint self-protection features
      • Endpoint response actions
        • Automated response actions
        • Isolate a host
        • Response actions history
        • Third-party response actions
        • Configure third-party response actions
      • Cloud Security
        • Security posture management overview
        • Enable cloud security features in Serverless
        • Cloud security posture management
          • Get started with CSPM for AWS
          • Get started with CSPM for GCP
          • Get started with CSPM for Azure
          • CSPM privilege requirements
          • CSPM Findings
          • CSPM benchmarks
          • Cloud Security Posture dashboard
          • Frequently asked questions (FAQ)
        • Kubernetes security posture management
          • Get started with KSPM
          • KSPM Findings
          • KSPM benchmarks
          • Cloud Security Posture dashboard
          • Frequently asked questions (FAQ)
        • Cloud Asset Discovery
          • Set up Cloud Asset Discovery for AWS
          • Set up Cloud Asset Discovery for GCP
          • Set up Cloud Asset Discovery for Azure
        • Cloud native vulnerability management
          • Get started with CNVM
          • CNVM privilege requirements
          • CNVM Findings
          • CNVM dashboard
          • Frequently asked questions (FAQ)
        • Cloud workload protection for VMs
          • Capture environment variables
        • Cloud workload protection for Kubernetes
          • Get started with Defend for Containers for Kubernetes
          • Container workload protection policies
          • Kubernetes dashboard
      • Ingest third-party security data
        • AWS Config
        • AWS Inspector
        • AWS Security Hub
        • AWS Security Hub CSPM
        • CNCF Falco
        • Google Security Command Center
        • Microsoft Defender for Cloud
        • Microsoft Defender for Endpoint
        • Microsoft Defender XDR
        • Prisma Cloud
        • Qualys VMDR
        • Rapid7 InsightVM
        • Tenable VM
        • Wiz
      • Investigation tools
        • Timeline
          • Timeline templates
        • Visual event analyzer
        • Session View
        • Osquery
          • Osquery manager integration
          • Osquery FAQ
          • Add Osquery Response Actions
          • Run Osquery from investigation guides
          • Run Osquery from alerts
          • Examine Osquery results
          • Use placeholder fields in Osquery queries
        • Notes
        • Indicators of compromise
        • Cases
      • Dashboards
        • Overview dashboard
        • Detection & Response dashboard
        • Cloud Security Posture dashboard
        • Kubernetes dashboard
        • Entity Analytics dashboard
        • Data Quality dashboard
        • Cloud Native Vulnerability Management Dashboard
        • Detection rule monitoring dashboard
        • Endpoint Detection and Response dashboard
      • Entity analytics
        • Entity analytics overview
        • Entity risk scoring
          • Entity risk scoring requirements
          • Turn on the risk scoring engine
          • View entity details
          • Asset criticality
          • Entity store
          • View and analyze risk score data
        • Advanced behavioral detections
          • Machine learning job and rule requirements
          • Anomaly detection
          • Optimizing anomaly results
          • Behavioral detection use cases
        • Privileged user monitoring
          • Privileged user monitoring requirements
          • Set up privileged user monitoring
          • Monitor privileged user activities
        • Explore
          • Hosts page
          • Network page
            • Configure network map data
            • Configure the DNS histogram
          • Users page
      • Serverless feature tiers
      • APIs
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.