# Metricbeat doesnt create event when service is down

**URL:** <https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 16, 2021, 4:59pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424 "2021-09-16T16:59:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deny7](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Post date:** [September 16, 2021, 4:59pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424/1 "2021-09-16T16:59:36Z")

</div>

Hi,

Hi, Im using Metricbeat 7.9 and Elastalert for filesystem usage for each mountpoint. I also want to add alerting when linux service is stopped, so I enabled "- service" and "-process" in metricbeat.reference.yml. When I look to metricbeat index, it works and I see entries like "nginx - sleeping". I tried to test the alert so I stopped the nginx service, but when I look to the metricbeat index I dont see any new entries for nginx, it just stopped logging new entries for nginx, so my alert cant be activated because its set to send alert when the entry for service status is "dead". Can anybody help me with this please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2021, 4:59pm UTC](https://discuss.elastic.co/t/metricbeat-doesnt-create-event-when-service-is-down/284424/2 "2021-10-14T16:59:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
