# How to get the all disks(Drive) via metricbeat?

**URL:** <https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 28, 2019, 3:12am UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927 "2019-01-28T03:12:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vinit\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinit_kumar/32/74784_2.png) [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Post date:** [January 28, 2019, 3:12am UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/1 "2019-01-28T03:12:08Z")

</div>

Hi all,

I have three disks, want to get three disks in kibana but I am able to get only one disk. I have added the name of those disk in system.yml configuration file but still, only one`/dev/xvda1` is getting in kibana.

My Disks are:

```
[vinit@ip-XXX-XX-X-XXX modules.d]$ df -h
Filesystem Size Used Avail Use% Mounted on
/dev/xvda1 99G 30G 69G 31% /
devtmpfs 2.0G 56K 2.0G 1% /dev
tmpfs 2.0G 0 2.0G 0% /dev/shm

```

System.yml configuration is:

```
# Module: system
# Docs: https://www.elastic.co/guide/en/beats/metricbeat/6.5/metricbeat-module-system.html

- module: system
  period: 10s
  metricsets:
    - cpu
    #- load
    - memory
    #- network
    #- process
    #- process_summary
    #- core
    #- diskio
    #- socket
  process.include_top_n:
    by_cpu: 5 # include top 5 processes by CPU
    by_memory: 5 # include top 5 processes by memory

- module: system
  period: 1m
  metricsets:
    - filesystem
    - fsstat
  processors:
  - drop_event.when.regexp:
      system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|devtmpfs|tmpfs|host|lib)($|/)'

- module: system
  period: 15m
  metricsets:
    - uptime

#- module: system
# period: 5m
# metricsets:
# - raid
# raid.mount_point: '/'

```

And I'm getting in kibana is: ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/33026f7f2ae1864801f2ab86f2acbc4db5cb488b.png)

Does anyone have any idea how to get these disks using metricbeat to logstash to kibana?

Thanks in advance for suggestions.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 30, 2019, 1:04pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/2 "2019-01-30T13:04:20Z")

</div>

Hi @Vinit_Kumar,

Notice that default configuration drops events from mountpoints that are usually virtual filesystems, this includes `devtmpfs` and `tmpfs`:

```auto
  processors:
  - drop_event.when.regexp:
      system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|devtmpfs|tmpfs|host|lib)($|/)'

```

There is also a [`filebeat.ignore_types`](https://www.elastic.co/guide/en/beats/metricbeat/6.6/metricbeat-metricset-system-filesystem.html#_configuration_5) option that in Linux defaults to ignore all filesystem types marked as `nodev` in `/proc/filesystems`. You can override this option by setting an specific set of filesystem types to ignore. The list of ingored types is logged at the info level on metricbeat startup, with a line starting by `Ignoring filesystem types:...`.

---

<div class="post-metadata">

**Author:** ![cchenna](https://avatars.discourse-cdn.com/v4/letter/c/db5fbb/32.png) [@cchenna](https://discuss.elastic.co/u/cchenna)\
**Post date:** [February 4, 2019, 6:00pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/4 "2019-02-04T18:00:52Z")

</div>

Hi Jamie,

I am having the same issue as well. Don't see all filesystems being exported. I am using the "filesystem.ignore\_types" option in the config.

- module: system  
period: 1m  
metricsets:  
- filesystem  
#- fsstat  
#filesystem.ignore\_types: [devpts,sysfs,cgroup,tmpfs,proc,tmpfs,autofs,mqueue,binfmt\_misc]  
filesystem.ignore\_types: [sysfs, proc, devtmpfs, securityfs, tmpfs, devpts, cgroup, pstore, configfs, systemd-1, hugetlbfs, mqueue, debugfs, binfmt\_misc, sunrpc]  
fields:  
env: sandbox  
beat\_type: metricbeat  
fields\_under\_root: true  
processors:  
- include\_fields:  
fields: ["metricset.module", "metricset.name", "env", "beat\_type", "system.filesystem.device\_name", "system.filesystem.mount\_point", "system.filesystem.used.pct", "system.filesystem.type"]  
- drop\_fields:  
fields: ["host"]

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [February 5, 2019, 2:00pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/5 "2019-02-05T14:00:19Z")

</div>

Hi @cchenna,

Could you give more details about the filesystems you cannot see?

---

<div class="post-metadata">

**Author:** ![cchenna](https://avatars.discourse-cdn.com/v4/letter/c/db5fbb/32.png) [@cchenna](https://discuss.elastic.co/u/cchenna)\
**Post date:** [February 5, 2019, 4:01pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/6 "2019-02-05T16:01:10Z")

</div>

Hi Jaime,

I don't see the nfs filesystem and few local filesystem disks.

Thanks,  
Chenna.

---

<div class="post-metadata">

**Author:** ![Vinit\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinit_kumar/32/74784_2.png) [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Post date:** [February 6, 2019, 6:01am UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/7 "2019-02-06T06:01:19Z")

</div>

Hi @cchenna,

I commented this below processor completely then only I was able to see all the disks.

```
#processors:
  #- drop_event.when.regexp:
      #system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|devtmpfs|tmpfs|host|lib)($|/)'

```

Try this also.

---

<div class="post-metadata">

**Author:** ![cchenna](https://avatars.discourse-cdn.com/v4/letter/c/db5fbb/32.png) [@cchenna](https://discuss.elastic.co/u/cchenna)\
**Post date:** [February 6, 2019, 5:18pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/8 "2019-02-06T17:18:52Z")

</div>

Hi Vinit,

I tried this and it didn't work, below is the config i am using.

- module: system  
period: 1m  
metricsets:  
- filesystem  
#- fsstat  
#filesystem.ignore\_types: [devpts,sysfs,cgroup,tmpfs,proc,tmpfs,autofs,mqueue,binfmt\_misc]  
filesystem.ignore\_types: [sysfs, proc, devtmpfs, securityfs, tmpfs, devpts, cgroup, pstore, configfs, systemd-1, hugetlbfs, mqueue, debugfs, binfmt\_misc, sunrpc]  
fields:  
env: sandbox  
beat\_type: metricbeat  
fields\_under\_root: true  
processors:  
#- drop\_event.when.regexp:  
#system.filesystem.mount\_point: '^/(sys|cgroup|proc|dev|etc|host|lib)($|/)'  
- include\_fields:  
fields: ["metricset.module", "metricset.name", "env", "beat\_type", "system.filesystem.device\_name", "system.filesystem.mount\_point", "system.filesystem.used.pct", "system.filesystem.type"]  
- drop\_fields:  
fields: ["host"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 5:18pm UTC](https://discuss.elastic.co/t/how-to-get-the-all-disks-drive-via-metricbeat/165927/9 "2019-03-06T17:18:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
