# Metricbeat in Kubernetes only get processes from the container and not the host (Windows)

**URL:** <https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [May 5, 2021, 12:56am UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128 "2021-05-05T00:56:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jproulx](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jproulx](https://discuss.elastic.co/u/jproulx)\
**Post date:** [May 5, 2021, 12:56am UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128/1 "2021-05-05T00:56:04Z")

</div>

**Context**  
I am trying to setup metricbeat 7.12 as a DaemonSet in an Azure Kubernetes Cluster on a Nano Windows Server host. I based my Kubernetes config of metricbeat on this [document](https://raw.githubusercontent.com/elastic/beats/7.12/deploy/kubernetes/metricbeat-kubernetes.yaml).

In this document, the ConfigMap named "metricbeat-daemonset-modules" contains the configuration for the module system. The metricset "process" is enabled (among others).

**Expected behavior**  
From what I understood with this config, I would have expected metricbeat to look at all the processes on the Host and give me the ones with highest CPU/memory.

**Observed behavior**  
What I see instead is that metricbeat only seems to look at the processes on the container where metricbeat is currently running on.

**Question**  
What is the expected behavior? Is there a way for metricbeat to look at all the process from the Host perspective?

**Details**  
Please note that:

- Metribeat pods are running in an "elasticsearch" namespace and not in "kube-system"
- I have metricbeat configured as a DaemonSet for a Linux host and another one for Windows Nano server host. The problem seems only related to Windows host.

Here is my system module's config:

```auto
    apiVersion: v1
    kind: ConfigMap
    metadata:
      name: metricbeat-daemonset-modules
      labels:
        k8s-app: metricbeat
    data:
      system.yml: |-
        - module: system
          period: 10s
          metricsets:
            - cpu
            - load
            - memory
            - network
            - process
            - process_summary
            #- core
            #- diskio
            #- socket
          processes: ['*']
          process.include_top_n:
            by_cpu: 20 # include top 5 processes by CPU
            by_memory: 20 # include top 5 processes by memory

        - module: system
          period: 1m
          metricsets:
            - filesystem
            - fsstat
          processors:
          - drop_event.when.regexp:
              system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|host|lib)($|/)'
      kubernetes.yml: |-
        - module: kubernetes
          metricsets:
            - node
            - system
            - pod
            - container
            - volume
          period: 10s
          host: ${NODE_NAME}
          hosts: ["https://${HOSTNAME}:10250"]
          bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
          ssl.certificate_authorities:
            - /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
          ssl.verification_mode: "none"
        - module: kubernetes
          metricsets:
            - proxy
          period: 10s
          host: ${NODE_NAME}
          hosts: ["localhost:10249"]

```

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 6, 2021, 8:23am UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128/3 "2021-05-06T08:23:03Z")

</div>

Hi!

I think the `-system.hostfs=/hostfs` at [beats/metricbeat-kubernetes.yaml at a0d3c74c445187936802c5f87d3bdc19e6955e04 · elastic/beats · GitHub](https://github.com/elastic/beats/blob/a0d3c74c445187936802c5f87d3bdc19e6955e04/deploy/kubernetes/metricbeat-kubernetes.yaml#L154) should do the trick. Do you start metricbeat like this?  
Also make sure that you mount the underlying fs into the container like at [beats/metricbeat-kubernetes.yaml at master · elastic/beats · GitHub](https://github.com/elastic/beats/blob/master/deploy/kubernetes/metricbeat-kubernetes.yaml#L193-L205).

Find more info at [Run Metricbeat on Docker | Metricbeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-docker.html#monitoring-host)

---

<div class="post-metadata">

**Author:** ![jproulx](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jproulx](https://discuss.elastic.co/u/jproulx)\
**Post date:** [May 6, 2021, 1:22pm UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128/4 "2021-05-06T13:22:14Z")

</div>

Hey Chris,  
Thanks for the reply. The yaml you are referring to seems to be only working for a DaemonSet deployed on a **Linux** host. In my case, it is deployed on a **Windows** host as mentioned in my previous post.

I understand now that metricbeat gets the processes info from `/proc` on a Linux host. I guess that won't work on a Windows host.

Do you know if metricbeat running on a Windows Host in a Kubernetes cluster was ever tested? Should there be a mention maybe in the documentation about certain features not supported on Windows Host?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 3:22pm UTC](https://discuss.elastic.co/t/metricbeat-in-kubernetes-only-get-processes-from-the-container-and-not-the-host-windows/272128/5 "2021-06-03T15:22:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
