Metricbeat 7.0.1 Windows Module Services

(Michael) #1

I have a problem with the Metricbeat Windows module, I only want to monitor 5 specific services in the service monitoring. But it always transfers all events to Elasticsearch.
I've tried filtering like this in the example:
https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-metricset-windows-service.html

processors:
    - drop_event.when.not.equals:
  windows.service.display_name: Windows Firewall

and like this one:

processors:
 -drop_event:
 when:
or: 
  not:
    equals:
       windows.service.name: XXX6
  not:
    equals:
      windows.service.name: XXX5
  not:
    equals:
      windows.service.name: XXX3
  not:
    equals:
      windows.service.name: XXX2
  not:
    equals:
      windows.service.name: XXXX1

What must be different for me to only receive events for the listed services?

and I have a second problem, I can't see on the dashboard how much space is left on the Windows partitions. Do I have to configure it in the Windows module or system and if so how?
The Metrictset filesystem and fsstat are active by default, but I still don't see how full/empty the partitions are in the dashboard. Seems that the information is missing.