# Empty String on windows.service.start\_type field while using Metricbeat 7.8.0

**URL:** https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056
**Category:** Beats
**Tags:** metricbeat
**Created:** [June 22, 2020, 9:42am UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056 "2020-06-22T09:42:02Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Jamaluddin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamaluddin/32/70800_2.png) [@Jamaluddin](https://discuss.elastic.co/u/Jamaluddin)
#### Post date: [June 22, 2020, 9:42am UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056/1 "2020-06-22T09:42:02Z")

</div>

Hi Dear Friends and Master of ELK Stack,

I want to ask/report about missing value on **windows.service.start\_type** field while using **Metricbeat 7.8.0**.  
While using **Metricbeat 7.7.1** the values of **windows.service.start\_type** field are **Automatic, Manual** , etc. But when I was using Metricbeat 7.8.0 the value of **windows.service.start\_type** field is **empty string**.  
Here I attached the screenshoot.

 ![metricbeat 7.7.1](https://us1.discourse-cdn.com/elastic/original/3X/1/9/1903dddb1ae7d5328490762e7587b55974fb093e.jpeg) ![metricbeat 7.8.0](https://us1.discourse-cdn.com/elastic/original/3X/8/6/86b527a59da24113e874b6a14117d4c5d09495cf.jpeg)

Can somebody help me?

---

<div class="post-metadata">

### Author: ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)
#### Post date: [June 22, 2020, 9:53am UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056/2 "2020-06-22T09:53:48Z")

</div>

Perhaps Beats team need to verify the module before released, as per my [posting](https://discuss.elastic.co/t/heartbeat-problem-in-7-7-x/237250/5) for heartbeat fields. Fortunately in the heartbeat fields, still have the data and just add processor copy\_fields, this metricbeat module break a lots of dashboard, I'm afraid.

I wish it will rectified in next minor release...

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

### Author: ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)
#### Post date: [June 30, 2020, 12:05pm UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056/3 "2020-06-30T12:05:05Z")

</div>

hi @Jamaluddin , are there any configuration changes in the config file between the 2 versions?  
If not, can you create an issue in the beats repo, this looks like a regression [https://github.com/elastic/beats](https://github.com/elastic/beats)

---

<div class="post-metadata">

### Author: ![MarianaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marianad/32/42687_2.png) [@MarianaD](https://discuss.elastic.co/u/MarianaD)
#### Post date: [July 1, 2020, 1:41pm UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056/4 "2020-07-01T13:41:17Z")

</div>

@Jamaluddin ,

thanks for bringing this to our attention , a PR with the fix has been created [https://github.com/elastic/beats/pull/19551](https://github.com/elastic/beats/pull/19551) , unfortunately for now you will have to use the older version of Metricbeat.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 29, 2020, 3:53pm UTC](https://discuss.elastic.co/t/empty-string-on-windows-service-start-type-field-while-using-metricbeat-7-8-0/238056/5 "2020-07-29T15:53:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
