I have a problem with the Metricbeat Windows module, I only want to monitor 5 specific services in the service monitoring. But it always transfers all events to Elasticsearch.
I've tried filtering like this in the example:
processors: - drop_event.when.not.equals: windows.service.display_name: Windows Firewall
and like this one:
processors: -drop_event: when: or: not: equals: windows.service.name: XXX6 not: equals: windows.service.name: XXX5 not: equals: windows.service.name: XXX3 not: equals: windows.service.name: XXX2 not: equals: windows.service.name: XXXX1
What must be different for me to only receive events for the listed services?
and I have a second problem, I can't see on the dashboard how much space is left on the Windows partitions. Do I have to configure it in the Windows module or system and if so how?
The Metrictset filesystem and fsstat are active by default, but I still don't see how full/empty the partitions are in the dashboard. Seems that the information is missing.