Been playing with the ELK stack pretty heavily the last week or so running on a Windows platform. I'd like to collect per CPU metrics and have them display on a time series. This is what I have in the windows.yml module config for 8 cores:
- instance_label: "core.0"
instance_name: "Core 0"
query: '\Processor Information(0,0)% Processor Time'
In Kibana, after refreshing my index, I see windows.perfmon.core.0 and windows.perfmon.core.0.keyword. In the Discover tab, I see those as selectable fields but they're all empty. Question:
- I don't want both core.0 and core.0.keyword, how do I get rid of one of them?
a. Would it be recommended to keep the one that is aggregatable?
- What else needs to be done to get the data that is collected to properly display?