# CPU and Memory Usage on Selected Processes

**URL:** <https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453>\
**Category:** Beats\
**Created:** [April 5, 2016, 8:48pm UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453 "2016-04-05T20:48:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 5, 2016, 8:48pm UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/1 "2016-04-05T20:48:53Z")

</div>

How can i get CPU and Memory for the selected(RED) processes only ?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/be82583edde1c1b2c9e140eb40588edd4d6c07aa.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 6, 2016, 3:19am UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/2 "2016-04-06T03:19:32Z")

</div>

I think this should match the three processes in red in a case insensitive manner.

```auto
input:
  procs:
    - '(?i)^devenv.exe$'
    - '(?i)^outlook.exe$'
    - '(?i)^explorer.exe$'

```

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 6, 2016, 4:13am UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/3 "2016-04-06T04:13:40Z")

</div>

Thanks for the reply.

Which field will return me those Memory related value i.e. 724,860, 93,280, etc. Will there be any conversion required for this?

Also, I wanted to set a visualization for these 3 processes (x-axis -\> devenv.exe, outlook.exe and explorer.exe) and y-axis(memory).

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 6, 2016, 4:40am UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/4 "2016-04-06T04:40:15Z")

</div>

I can't see what the rest of that memory column says but I think that data would map to the [`proc.mem.rss`](https://www.elastic.co/guide/en/beats/topbeat/master/exported-fields-process.html#_proc_mem_rss) field which will be reported in bytes.

In Kibana, the `proc.mem.rss` field can be marked as [Bytes](https://www.elastic.co/guide/en/kibana/current/managing-fields.html#_numeric_field_formatters) and will be formatted appropriately.

For the visualization, you could use a vertical bar chart.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/79cb92466e9edf287b6ee91dac7c067e2af5834c.png)

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 6, 2016, 12:46pm UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/5 "2016-04-06T12:46:04Z")

</div>

Thanks Andrew. I will give a try today and vl let u know if i face any issues.

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 18, 2016, 4:24am UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/6 "2016-04-18T04:24:19Z")

</div>

Hey Andrew, Thanks for the above things.

Can you please tell me how can I get information about the server Hard Disk Space utilized and Free Space ? Which field provides this info ? Also I am using Windows Server 2012

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 18, 2016, 1:59pm UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/7 "2016-04-18T13:59:41Z")

</div>

Filesystem stats are enabled by default so as long as you have not disabled them, they will be reported. [https://www.elastic.co/guide/en/beats/topbeat/current/configuration-input.html#\_stats](https://www.elastic.co/guide/en/beats/topbeat/current/configuration-input.html#_stats)

The reported filesystem data is described here: [https://www.elastic.co/guide/en/beats/topbeat/current/exported-fields-filesystem.html](https://www.elastic.co/guide/en/beats/topbeat/current/exported-fields-filesystem.html)

The data is collected by [calling](https://github.com/elastic/gosigar/blob/master/sigar_windows.go#L482) [GetDiskFreeSpaceEx](https://msdn.microsoft.com/en-us/library/windows/desktop/aa364937%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396) on Windows.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:53pm UTC](https://discuss.elastic.co/t/cpu-and-memory-usage-on-selected-processes/46453/8 "2017-07-05T21:53:06Z")

</div>


