# Add\_field per instance of permon metricset

**URL:** <https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 22, 2019, 2:31pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670 "2019-10-22T14:31:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 22, 2019, 2:31pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/1 "2019-10-22T14:31:35Z")

</div>

Hello,

The following does not seem to work?

```
- module: windows
  metricsets: [perfmon]
  period: 10s
  perfmon.ignore_non_existent_counters: true
  perfmon.group_measurements_by_instance: true
  perfmon.counters:
    - instance_label: processor.name
      instance_name: total
      measurement_label: processor.time.total.pct
      query: '\Processor Information(_Total)\% Processor Time'
    
    - instance_label: logical_disk.name
      measurement_label: logical_disk.disk_time.pct
      query: '\LogicalDisk(*)\% Disk Time'
      processors:
      - add_fields:
          fields:
            metricset.counter: logical_disk
              
    - instance_label: logical_disk.name
      measurement_label: logical_disk.avg_disk_queue_length
      query: '\LogicalDisk(*)\Avg. Disk Queue Length'
      processors:
      - add_fields:
          fields:
            metricset.counter: logical_disk

```

Is there a way to use the add\_field processor per instance in the perfmon module? We would like to monitor some mssql performance counters and add the name of the database in a custom field. That way we can aggregate counters per host per database. If this is not possible, should I make a feature request?

Tx!

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [October 23, 2019, 7:29am UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/2 "2019-10-23T07:29:40Z")

</div>

It looks like processors allow conditions:  
[https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html)  
[https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions)

can you add conditions based on the data you are receiving?

---

<div class="post-metadata">

**Author:** ![PeterDK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peterdk/32/49432_2.png) [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Post date:** [October 23, 2019, 1:45pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/3 "2019-10-23T13:45:13Z")

</div>

Hi,

as a colleague of Willem I'm also investigating this and I tried the following

```
- module: windows
  metricsets: [perfmon]
  period: 10s
  perfmon.ignore_non_existent_counters: true
  perfmon.group_measurements_by_instance: true
  perfmon.counters:
    - instance_label: processor.name
      instance_name: total
      measurement_label: processor.time.total.pct
      query: '\Processor Information(_Total)\% Processor Time'
    
    - instance_label: logical_disk.name
      measurement_label: logical_disk.disk_time.pct
      query: '\LogicalDisk(*)\% Disk Time'
              
    - instance_label: logical_disk.name
      measurement_label: logical_disk.avg_disk_queue_length
      query: '\LogicalDisk(*)\Avg. Disk Queue Length'
  processors:
    - add_fields:
        when.equals:
          instance_label: logical_disk.name
        fields:
          metricset.counter: testfield

```

I also tried with perfmon.counters.instance\_label or putting the logical\_disk.name between quotes but that doesn't work.  
FYI, without the when.equals part "fields.metricset.counter" is added with value "testfield".

We think the issue we have is that the condition needs to meet the key instead of the value.  
The field actually results in "windows.perfmon.logical\_disk.name".  
I think we need something like:

```
when.exists:
  windows.perfmon.logical_disk.name

```

Kind regards,  
Peter

---

<div class="post-metadata">

**Author:** ![PeterDK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peterdk/32/49432_2.png) [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Post date:** [October 23, 2019, 1:53pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/4 "2019-10-23T13:53:56Z")

</div>

Ok, we found this, tested it and it works:

```
- module: windows
  metricsets: [perfmon]
  period: 10s
  perfmon.ignore_non_existent_counters: true
  perfmon.group_measurements_by_instance: true
  perfmon.counters:
    - instance_label: processor.name
      instance_name: total
      measurement_label: processor.time.total.pct
      query: '\Processor Information(_Total)\% Processor Time'
    
    - instance_label: logical_disk.name
      measurement_label: logical_disk.disk_time.pct
      query: '\LogicalDisk(*)\% Disk Time'
              
    - instance_label: logical_disk.name
      measurement_label: logical_disk.avg_disk_queue_length
      query: '\LogicalDisk(*)\Avg. Disk Queue Length'
  processors:
    - add_fields:
        when.has_fields:
          ['windows.perfmon.logical_disk.name']
        fields:
          metricset.counter: logical_disk
```

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [October 23, 2019, 2:03pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/5 "2019-10-23T14:03:05Z")

</div>

@pmercado Just a small question =\> Any idea when the perfmon module would come out of beta? We are a bit reluctant to use beta features on a large scale. But perfmon is such an important part for Windows monitoring, we kind of really need it. . Tx!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2019, 2:03pm UTC](https://discuss.elastic.co/t/add-field-per-instance-of-permon-metricset/204670/6 "2019-11-20T14:03:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
