# Metricbeat - 'system' -\> 'filesystem' metrics does not include network drives

**URL:** <https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 23, 2019, 1:45pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420 "2019-01-23T13:45:12Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [January 23, 2019, 1:45pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/1 "2019-01-23T13:45:12Z")

</div>

Hi all,  
I am using system module in Metricbeat in order to monitor my computer's drives and I don't see any metrics on network drives, just on local drives.  
I am using 'filesystem' metricset.

Thanks for your help,  
Yuval.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 24, 2019, 2:49pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/2 "2019-01-24T14:49:51Z")

</div>

Hi @yuval_yellin and welcome 🙂

The focus on the `system` module is to collect metrics from the system where metricbeat is running, for the `filesystem` metricset it means that the defaults may collect data only from local disks.  
But said that, the truth is that sometimes both local and remote stores appear in the operating system as the same thing, but it depends on the operating system and the type of drive.

If you are using linux, you can try to customize the [`filesystem.ignore_types`](https://www.elastic.co/guide/en/beats/metricbeat/6.5/metricbeat-metricset-system-filesystem.html#_configuration_5) setting, all filesystems not using a physical device are ignored by default, but you can override this to include for example metrics of `nfs` or `smbfs`.

If you are using Windows, you may benefit from [this recent change](https://github.com/elastic/beats/pull/10196) that aims to collect volumes in a more generic way, this will be included in Metricbeat 6.7.0.

What operating system and what kind of network drive are you using?

---

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [January 27, 2019, 9:23am UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/3 "2019-01-27T09:23:32Z")

</div>

Hi Jaime,

I am using Metricbeat on windows and on linux computers, can you please show me how exactly to add the field `[filesystem.ignore_type](https://www.elastic.co/guide/en/beats/metricbeat/6.5/metricbeat-metricset-system-filesystem.html#_configuration_5)s`in order to get metrics on network drives in Linux computers?

And on windows, I will have to wait until version 6.7.0 will be released?

Thanks,

Yuval

‫בתאריך יום ה׳, 24 בינו׳ 2019 ב-16:59 מאת ‪Jaime Soriano via Discuss the Elastic Stack‬‏ \<‪elastic@discoursemail.com‬‏\>:‬

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 28, 2019, 1:14pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/4 "2019-01-28T13:14:11Z")

</div>

@yuval_yellin what kind of network volumes are you using?

---

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [January 31, 2019, 11:52am UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/5 "2019-01-31T11:52:26Z")

</div>

NFS drives.  
Thanks

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 31, 2019, 12:34pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/6 "2019-01-31T12:34:24Z")

</div>

Then linux is surely ignoring them with `filesystem.ignore_type`. When metricbeat starts, it logs the list of ignored filesystems with a line starting with `Ignoring filesystem types...`. You can use the list logged there as a base to build your own custom `filesystem.ignore_type` with the types that make sense in your case, something like this for example:

```auto
filesystem.ignore_types: [sysfs, proc, cpuset, cgroup, cgroup2, tmpfs, devtmpfs, configfs, debugfs, tracefs, securityfs, sockfs, dax, bpf, pipefs, hugetlbfs, devpts, ecryptfs, fuse, fusectl, pstore, efivarfs, mqueue, autofs, overlay, aufs, binfmt_misc, rpc_pipefs]

```

For Windows, how do you access NFS? Does it have an assigned letter or access path?

---

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [January 31, 2019, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/7 "2019-01-31T13:03:27Z")

</div>

So in linux, for example, if I want to get metrics on 'nfs' I just need to remove 'nfs' from filesystem.ignore\_types list?  
And in Windows we add a mapping to an NFS address, so we have a 'N:' drive which points to a network path.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 31, 2019, 7:02pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/8 "2019-01-31T19:02:16Z")

</div>

> [@yuval\_yellin](#):
>
> So in linux, for example, if I want to get metrics on 'nfs' I just need to remove 'nfs' from filesystem.ignore\_types list?

Correct, you may also need to remove `nfs4`.

> [@yuval\_yellin](#):
>
> And in Windows we add a mapping to an NFS address, so we have a 'N:' drive which points to a network path.

Then it may work with the changes introduced in 6.7.0.

To confirm that, if you have the chance you can try to download the source code of [gosigar](https://github.com/elastic/gosigar) and run `go run examples/df/df.go` (requires [go](https://golang.org/doc/install)). `gosigar` is a library we use to collect system information, this command lists the filesystem this library (and thus metricbeat) is able to detect.

---

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [February 4, 2019, 11:35am UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/9 "2019-02-04T11:35:07Z")

</div>

OK, so in Linux it works and I see all mounted devices.

In windows, I downloaded and started metricbeat 7.0.0-alpha2 but unfortunately I still don't see any network drive.. Is there any other option?  
The changes that you have mentioned above to be introduced in 6.7.0 are in 7.0.0-alpha2 ?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [February 5, 2019, 1:42pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/10 "2019-02-05T13:42:08Z")

</div>

@yuval_yellin no, sorry, the change is not in 7.0.0-alpha2, but it will be in next 7.0 build.

It'd be great if you could do the test of running the gosigar example if you have the option to do it in Windows.

---

<div class="post-metadata">

**Author:** ![yuval\_yellin](https://avatars.discourse-cdn.com/v4/letter/y/97f17d/32.png) [@yuval\_yellin](https://discuss.elastic.co/u/yuval_yellin)\
**Post date:** [February 6, 2019, 11:08am UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/11 "2019-02-06T11:08:04Z")

</div>

I tried the gosigar example on windows and unfortunately I still get only local drives..

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [February 6, 2019, 1:15pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/12 "2019-02-06T13:15:12Z")

</div>

Ok, then we are still missing something ☹

Could you please [open an enhancement request](https://github.com/elastic/beats/issues/new?template=feature-request.md) asking for support of network drives in Windows?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 1:20pm UTC](https://discuss.elastic.co/t/metricbeat-system-filesystem-metrics-does-not-include-network-drives/165420/13 "2019-03-06T13:20:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
