# Metricbeat process\_summary on windows

**URL:** <https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [November 7, 2019, 2:25am UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879 "2019-11-07T02:25:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomr/32/48260_2.png) [@tomr](https://discuss.elastic.co/u/tomr)\
**Post date:** [November 7, 2019, 2:25am UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879/1 "2019-11-07T02:25:49Z")

</div>

I'm using metricbeat (7.3.2) on Windows, and trying to figure out what the various `process_summary` metrics mean.

```auto
	t metricset.name process_summary
	t service.type system
	# system.process.summary.dead 0
	# system.process.summary.idle 0
	# system.process.summary.running 70
	# system.process.summary.sleeping 0
	# system.process.summary.stopped 0
	# system.process.summary.total 72
	# system.process.summary.unknown 2
	# system.process.summary.zombie 0

```

Primarily I would like to know what `unknown` might indicate, in a windows context.

Next to that, I would like to know which of the other statuses are relevant on windows. In the data I've collected so far, I haven't seen any `dead` / `idle` / `stopped` / `zombie` (I have seen `sleeping`).

---

<div class="post-metadata">

**Author:** ![tomr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomr/32/48260_2.png) [@tomr](https://discuss.elastic.co/u/tomr)\
**Post date:** [November 12, 2019, 1:24am UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879/2 "2019-11-12T01:24:37Z")

</div>

Is this question better asked on Github?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 13, 2019, 2:44pm UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879/3 "2019-11-13T14:44:02Z")

</div>

Hi @tomr,

You guessed correctly, only possible states in Windows are running, sleeping and unknown. Unknown means there was an error retrieving this info. An error should show up in Metricbeat logs for latest case. Some more details on the implementation can be found here:

> <https://github.com/elastic/gosigar/blob/7aef3366157f2bfdf3e068f73ce7193573e88e0c/sigar_windows.go#L216>

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2019, 2:44pm UTC](https://discuss.elastic.co/t/metricbeat-process-summary-on-windows/206879/4 "2019-12-11T14:44:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
