metrics.log
Each Worker Process writes metrics.log under $CRIBL_HOME/log/worker/<N>/. Cribl Stream creates the file the first time that process records metrics for a Source, Destination, or persistent queue.
Use metrics.log when a Source, Destination, or persistent queue looks unhealthy in Monitoring but you need request counts or latency detail in the log file.
See Map Log Files to Built-in Datasets for information about the Dataset that includes a Worker Process metrics.log on the Leader.
Example Event
The following example shows a typical event in metrics.log. Event fields may vary depending on the process or action that generated the event.
{
"time": "2026-03-03T19:37:55.764Z",
"cid": "w0",
"channel": "output:my_splunk_hec",
"level": "info",
"message": "stats",
"output": "splunk_hec:my_splunk_hec",
"output_type": "splunk_hec",
"total_requests": 1420,
"failed_requests": 3,
"p95_duration_millis": 184,
"p99_duration_millis": 412
}Event Fields
The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.
| Field | Description |
|---|---|
time | UTC time when Cribl Stream wrote the event. |
cid | Worker Process that wrote the event. |
channel | Logger channel for the Source or Destination. |
level | Log level for the event, typically info. |
message | Event category. Request summaries use stats. Other values appear for different metric reports. |
output | Destination ID for a Destination event, in the form type:id. Omitted for Source events. |
output_type | Destination type. Omitted for Source events. |
input | Source ID for a Source event, in the form type:id. Omitted for Destination events. |
input_type | Source type. Omitted for Destination events. |
total_requests | Number of requests in the reporting interval. Cribl Stream includes this field when the Source or Destination metrics level is Basic or higher. |
failed_requests | Number of failed requests in the reporting interval. Compare against total_requests to judge whether that Source or Destination is degraded. |
p95_duration_millis | 95th percentile request duration in milliseconds. Use with p99_duration_millis to distinguish slow responses from outright failures. |
p99_duration_millis | 99th percentile request duration in milliseconds. Use with p95_duration_millis to distinguish slow responses from outright failures. |