On This Page

Home / Stream/ Monitor Health and Metrics/ Internal Logs/metrics.log

metrics.log ​

Each Worker Process writes metrics.log under $CRIBL_HOME/log/worker/<N>/. Cribl Stream creates the file the first time that process records metrics for a Source, Destination, or persistent queue.

Use metrics.log when a Source, Destination, or persistent queue looks unhealthy in Monitoring but you need request counts or latency detail in the log file.

See Map Log Files to Built-in Datasets for information about the Dataset that includes a Worker Process metrics.log on the Leader.

Example Event ​

The following example shows a typical event in metrics.log. Event fields may vary depending on the process or action that generated the event.

{
  "time": "2026-03-03T19:37:55.764Z",
  "cid": "w0",
  "channel": "output:my_splunk_hec",
  "level": "info",
  "message": "stats",
  "output": "splunk_hec:my_splunk_hec",
  "output_type": "splunk_hec",
  "total_requests": 1420,
  "failed_requests": 3,
  "p95_duration_millis": 184,
  "p99_duration_millis": 412
}

Event Fields ​

The following table describes fields that may be included in events in this log. Event fields may vary depending on the process or action that generated the event.

FieldDescription
timeUTC time when Cribl Stream wrote the event.
cidWorker Process that wrote the event.
channelLogger channel for the Source or Destination.
levelLog level for the event, typically info.
messageEvent category. Request summaries use stats. Other values appear for different metric reports.
outputDestination ID for a Destination event, in the form type:id. Omitted for Source events.
output_typeDestination type. Omitted for Source events.
inputSource ID for a Source event, in the form type:id. Omitted for Destination events.
input_typeSource type. Omitted for Destination events.
total_requestsNumber of requests in the reporting interval. Cribl Stream includes this field when the Source or Destination metrics level is Basic or higher.
failed_requestsNumber of failed requests in the reporting interval. Compare against total_requests to judge whether that Source or Destination is degraded.
p95_duration_millis95th percentile request duration in milliseconds. Use with p99_duration_millis to distinguish slow responses from outright failures.
p99_duration_millis99th percentile request duration in milliseconds. Use with p95_duration_millis to distinguish slow responses from outright failures.