# Stream's total incoming messages metric

**URL:** <https://community.graylog.org/t/streams-total-incoming-messages-metric/14649>\
**Category:** Graylog Central (peer support)\
**Created:** [March 25, 2020, 4:34pm UTC](https://community.graylog.org/t/streams-total-incoming-messages-metric/14649 "2020-03-25T16:34:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [March 25, 2020, 4:34pm UTC](https://community.graylog.org/t/streams-total-incoming-messages-metric/14649/1 "2020-03-25T16:34:31Z")

</div>

I would like to read streams’ input messages for performance monitoring.  
(4 nodes, GL v3.1.2 or 2 nodes with GL v3.2.2)

If I check the browser’s traffic when I check the streams menu, I got an api/cluster/metrics/multiple request (POST), and a json answer with the numbers by node.

If I try to check the API browser, I can ask the previous metric also.  
Or I can use api/system/metrics/multiple, but it shows the metric of the current node, not the full system (answer is the same under api/cluster/metric’s by node id.)  
And it is tha same if I try to ask from api/system/metrics/org.graylog2.plugin.streams.Stream.\_ID.incomingMessages

So is there one metric when I can get the sum stream messages count (eg total, or last 1 min avg), or I have to sum it manually after a request?  
Or any fast way to request the all messages number in a stream?  
I don’t want to overload the system with the requests, but it could be helpful if I want to know who start to send messages storm.

Sometimes I use this, but not for full time monitoring.

```auto
time curl -XGET -u $USER 'https://IP/api/search/universal/relative/stats?field=source&query=*&range=300&filter=streams%3A_ID_&pretty=true' 2>/dev/null | jq '.count'
2988975

real 0m1.467s
user 0m0.091s
sys 0m0.066s

```

But for the last 5 min it takes more then 1 sec (for last day 14 sec). I have more than 50 streams, so it needs about 2 minutes. I don’t want to run it every 5/10 minutes.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 27, 2020, 3:57pm UTC](https://community.graylog.org/t/streams-total-incoming-messages-metric/14649/2 "2020-03-27T15:57:21Z")

</div>

I did something like this in the past:

```auto
export RANGE=360; http GET https://graylog.local.lan/api/sources?range=$RANGE | jq --argjson r1 "$RANGE" ' .sources | to_entries|map("\(.key)=\(.value/$r1)")|.[]'

```

It uses httpie and jq and is kind of accurate.

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [March 30, 2020, 10:04am UTC](https://community.graylog.org/t/streams-total-incoming-messages-metric/14649/3 "2020-03-30T10:04:51Z")

</div>

thanks, its so fast.  
about 0,4s for last 5 mins  
But we have too much sources, so it need too much work to monitor it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 13, 2020, 10:04am UTC](https://community.graylog.org/t/streams-total-incoming-messages-metric/14649/4 "2020-04-13T10:04:54Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
