# Metricbeat 6.0.0 modules.d\\windows.yml - missing counter failure to start service

**URL:** <https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 6, 2017, 7:43pm UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569 "2017-12-06T19:43:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [December 6, 2017, 7:43pm UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569/1 "2017-12-06T19:43:44Z")

</div>

Hi,

If you have a defined perfmon counter in here and it does not exist on the machine the agent fails to start. Is this intentional or a bug?

Example -  
2017-12-06T14:21:06-05:00 CRIT Exiting: 1 error: 1 error: initialization failed: failed to add counter (path="\System\Processor Queue Length"): The specified object was not found on the computer.

Thanks!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 8, 2017, 2:38am UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569/2 "2017-12-08T02:38:18Z")

</div>

I wonder if it is possible that such a counter does not exist when start the beat but would show up later on the machine?

Perhaps @[maddin2016](https://discuss.elastic.co/u/maddin2016) can share some thoughts here?

---

<div class="post-metadata">

**Author:** ![KRasekhi](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@KRasekhi](https://discuss.elastic.co/u/KRasekhi)\
**Post date:** [December 8, 2017, 6:49pm UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569/3 "2017-12-08T18:49:47Z")

</div>

A couple of concerns that come to mind if this is the case -

1. Having to run multiple configurations for specific counters instead of one configuration that ships the data regardless if the counter is there by leaving the value null.

For example if a machine is brokered through Citrix XENDesktop and has Citrix Reciever installed it will create the ICA Session counter that we would like to capture but we have to use a different configuration. Or if we later decide to broker a machine and install Citrix receiver after the Metricbeat was installed then we have to change the config to add the new counter.

1. The other issue is if a machine is running beats configured to pick up a specific counter but later that counter becomes corrupted and no longer exists then Metricbeat will fail to start.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 12, 2017, 2:32am UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569/4 "2017-12-12T02:32:56Z")

</div>

I think these are valid points. I wonder what your expected behaviour is if you configured a counter and it does not exist. Do you expect winlogbeat to report this as an error? Could you open an issue on Github with this for further discussions? I think we have a feature request here 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 7:43pm UTC](https://discuss.elastic.co/t/metricbeat-6-0-0-modules-d-windows-yml-missing-counter-failure-to-start-service/110569/5 "2017-12-27T19:43:47Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
