# Metricbeat - filesystem metrics does not include remote network drives

**URL:** <https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346>\
**Category:** Beats\
**Tags:** windows, metricbeat\
**Created:** [October 16, 2020, 12:58pm UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346 "2020-10-16T12:58:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![qwinkler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qwinkler/32/77367_2.png) [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Post date:** [October 16, 2020, 12:58pm UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/1 "2020-10-16T12:58:14Z")

</div>

Hello!  
I attached a few S3 buckets via TntDrive ([https://tntdrive.com/](https://tntdrive.com/)) as a network device. They have a "remote" type in the old metricbeat:

```json
{
  "_index": "metricbeat-6.3.0-2020.10",
  "_type": "_doc",
  "_id": "k-8OMXUBmeNgQXQabOTu",
  "_version": 1,
  "_score": null,
  "_source": {
    "beat": {
      "version": "6.3.0"
    },
    "metricset": {
      "module": "system",
      "name": "filesystem",
      "rtt": 311999
    },
    "system": {
      "filesystem": {
        "free_files": 0,
        "available": 17592186044416,
        "mount_point": "U:\\",
        "used": {
          "pct": 0,
          "bytes": 0
        },
        "files": 0,
        "device_name": "U:\\",
        "total": 17592186044416,
        "type": "remote",
        "free": 17592186044416
      }
    }
  }
}

```

In the newer versions of metricbeat, there are no "remote" devices. How can I fix it? I saw on this topic ([Metricbeat - 'system' -\> 'filesystem' metrics does not include network drives](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420)) that I probably have to change the `filesystem.ignore_types`. It doesn't work, unfortunately.  
Here is my config file:

```auto
metricbeat.modules:
- module: system
  enabled: true
  period: 60s
  processes: ['.*']
  filesystem.ignore_types: []
  metricsets:
    - process
    - filesystem
  processors:
    - drop_event.when.regexp.mount_point: '^/(sys|cgroup|proc|dev|etc|host)($|/)'

```

With metricbeat 6.3.0 it works like a charm.

---

<div class="post-metadata">

**Author:** ![qwinkler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qwinkler/32/77367_2.png) [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Post date:** [October 19, 2020, 8:16am UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/2 "2020-10-19T08:16:41Z")

</div>

**UPD:** I downloaded the latest version of [https://github.com/elastic/gosigar](https://github.com/elastic/gosigar), compiled examples/df/df.go, and ran. I don't see the network devices in the output:

```auto
C:\Users\Administrator\Desktop>df.exe
Filesystem Size Used Avail Use% Mounted on
C:\ 75G 49G 26G 66% C:\

C:\Users\Administrator\Desktop>

```

 ![Screenshot 2020-10-19 at 11.13.44](https://us1.discourse-cdn.com/elastic/original/3X/7/1/7162fedf387b8ab7de800fbd7b77814915ad34cc.jpeg)

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [October 19, 2020, 3:39pm UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/3 "2020-10-19T15:39:19Z")

</div>

So, my windows knowledge is pretty limited, but this is the API we're using to get network volumes: [https://docs.microsoft.com/es-es/windows/win32/api/fileapi/nf-fileapi-findfirstvolumew](https://docs.microsoft.com/es-es/windows/win32/api/fileapi/nf-fileapi-findfirstvolumew)

And this is how we're using it: [https://github.com/elastic/gosigar/commits/master/sys/windows/syscall\_windows.go](https://github.com/elastic/gosigar/commits/master/sys/windows/syscall_windows.go) Previously, (I think under 6.3) we used a different API: [https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-getlogicaldrivestringsw](https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-getlogicaldrivestringsw)

Not currently sure if there's a workaround, I'll keep investigating.

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [October 19, 2020, 3:45pm UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/4 "2020-10-19T15:45:29Z")

</div>

It looks like this is a known issue, we may want to re-open: [https://github.com/elastic/beats/issues/10664](https://github.com/elastic/beats/issues/10664)

---

<div class="post-metadata">

**Author:** ![qwinkler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qwinkler/32/77367_2.png) [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Post date:** [October 20, 2020, 6:01am UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/5 "2020-10-20T06:01:09Z")

</div>

Yeah, will be great! I could attach this discussion URL to the issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2020, 8:01am UTC](https://discuss.elastic.co/t/metricbeat-filesystem-metrics-does-not-include-remote-network-drives/252346/6 "2020-11-17T08:01:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
