# Metricbeat Windows Module 6.0.0-alpha2, Output question

**URL:** <https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 3, 2017, 9:15am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676 "2017-08-03T09:15:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [August 3, 2017, 9:15am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/1 "2017-08-03T09:15:24Z")

</div>

Hi Everyone,

was since yesterday starting to test the alpha of the new windows module to use perfmon data to get a better overview of our .Net applications within IIS.

Now is only one big remaining question mark over my head 😃

in the config i provide different names to separate each query from perfmon:

> - module: windows  
> metricsets: ["perfmon"]  
> period: 10s  
> perfmon.counters:
> - instance\_label: "[example.com](http://example.com) cache api entries"  
> instance\_name: "LM\_W3SVC\_2\_ROOT"  
> measurement\_label: "cache.api.entries"  
> alias: "cache.api.entries"  
> query: '\ASP.NET Apps v4.0.30319(\_LM\_W3SVC\_2\_ROOT)\Cache API Entries'
> - instance\_label: "[example.com](http://example.com) cache api hit ratio"  
> instance\_name: "LM\_W3SVC\_2\_ROOT"  
> measurement\_label: "cache.api.hit.ratio"  
> alias: "cache.api.hit.ratio"  
> query: '\ASP.NET Apps v4.0.30319(\_LM\_W3SVC\_2\_ROOT)\Cache API Hit Ratio'
> - instance\_label: "[example.com](http://example.com) cache api hits"  
> instance\_name: "LM\_W3SVC\_2\_ROOT"  
> measurement\_label: "cache.api.hits"  
> alias: "cache.api.hits"  
> query: '\ASP.NET Apps v4.0.30319(\_LM\_W3SVC\_2\_ROOT)\Cache API Hits'

and this will give me the output like this:

> 2017-08-03T10:50:06+02:00 DBG Publish: {  
> "@timestamp": "2017-08-03T08:50:06.525Z",  
> "beat": {  
> "hostname": "server1",  
> "name": "server1",  
> "version": "6.0.0-alpha2"  
> },  
> "metricset": {  
> "module": "windows",  
> "name": "perfmon"  
> },  
> "windows": {  
> "perfmon": {  
> "cache": {  
> "api": {  
> "entries": xx,  
> "hit": {  
> "ratio": xx  
> },  
> "hits": xx  
> }  
> }  
> }  
> }  
> }

but now there are all the other things? ☹

> ```
> - instance_label: "example.com cache api hits"
> instance_name: "LM_W3SVC_2_ROOT"
> measurement_label: "cache.api.hits"
> alias: "cache.api.hits"
> 
> ```

in ES i dont have any way to separate the instances, in above example im only using 1 instance, but later i use 4.

Thanks in advance for any advice!

Cheers,  
Dirk

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [August 3, 2017, 11:04am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/2 "2017-08-03T11:04:52Z")

</div>

@lueneburger, please try the following config. `alias` is no longer an option. `instance_label` must be separate by `.`'s

```auto
-instance_label: "cache.api.entries.name"
 instance_name: "LM_W3SVC_2_ROOT"
 measurement_label: "cache.api.entries.total"
 query: ‘\ASP.NET Apps v4.0.30319(_LM_W3SVC_2_ROOT)\Cache API Entries’
-instance_label: "cache.api.hitratio.name"
 instance_name: "LM_W3SVC_2_ROOT"
 measurement_label: "cache.api.hitratio.total"
 query: ‘\ASP.NET Apps v4.0.30319(_LM_W3SVC_2_ROOT)\Cache API Hit Ratio’

```

With this you should get an output like this

```auto
cache: {
    api: {
        entries: {
            name: "LM_W3SVC_2_ROOT",
            total: xxxx
         },
        hitratio: {
            name: "LM_W3SVC_2_ROOT",
            total: xxxx
         }              
    }
}

```

I hope this makes it a little bit clearer how to separate the counters.

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [August 3, 2017, 11:28am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/3 "2017-08-03T11:28:16Z")

</div>

Important is that `instance_label` and `measurement_label` are named differently.

```auto
instance_label: cache.api.entries.name
measurement_label: cache.api.entries.total

```

Of course you can do something like in your config

```auto
instance_label: "example.com cache api entries"
measurement_label: "cache.api.entries"

```

@andrewkroh, do we have the new config option in 6.0.0-alpha2? @lueneburger, can you try to build from the latest source? I think this is the problem.

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [August 3, 2017, 1:53pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/4 "2017-08-03T13:53:14Z")

</div>

Hi maddin2016,

great that explains it and this is also working, was testing before and added tags: in the config, that also works.

> - module: windows  
> metricsets: ["perfmon"]  
> tags: "cnx-api02\_ota2012b.carhire-solutions.com" #here ☀  
> enabled: true  
> period: 10s  
> perfmon.counters:  
> - instance\_label: "[example.com](http://example.com) cache api entries"  
> instance\_name: "LM\_W3SVC\_3\_ROOT"  
> measurement\_label: "cache.api.entries"  
> alias: "cache.api.entries"  
> query: '\ASP.NET Apps v4.0.30319(\_LM\_W3SVC\_3\_ROOT)\Cache API Entries'

then is the outpout is:

> 2017-08-03T12:33:19+02:00 DBG Publish: {  
> "@timestamp": "2017-08-03T10:33:19.268Z",  
> "beat": {  
> "hostname": "server01",  
> "name": "server01",  
> "version": "6.0.0-alpha2"  
> },  
> "metricset": {  
> "module": "windows",  
> "name": "perfmon"  
> },  
> "tags": [  
> "server01\_example.com"  
> ],  
> "windows": {  
> "perfmon": {  
> "cache": {  
> "api": {  
> "entries": xx,  
> "hit": {  
> "ratio": xx  
> },  
> "hits": xx,  
> "misses": xx,  
> "trims": xx,  
> "turnover": {  
> "rate": xx  
> }  
> },  
> "total": {  
> "entries": xx,  
> "hit": {  
> "ratio": xx  
> },  
> "hits": xx,  
> "misses": xx,  
> "trims": xx,  
> "turnover": {  
> "rate": xx  
> }  
> }  
> }  
> }  
> }  
> }

but will also try your advice, thanks for the help 🙂 and have a great day

Cheers,  
Dirk

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 3, 2017, 2:44pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/5 "2017-08-03T14:44:28Z")

</div>

@maddin2016 Based on the little labels shown on the [commit page](https://github.com/elastic/beats/commit/4a927b49bfd82713d255169682c2907b74effb80) the change is only in master. Can you open a PR to add this to the 6.0 branch. That will get the change included in 6.0.0-beta2 (I think beta1 is already frozen).

We have a tool to automate it.

`./dev-tools/cherrypick_pr --create_pr 6.0 4655 4a927b49bfd82713d255169682c2907b74effb80`

---

<div class="post-metadata">

**Author:** ![maddin2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddin2016/32/16599_2.png) [@maddin2016](https://discuss.elastic.co/u/maddin2016)\
**Post date:** [August 3, 2017, 4:17pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/6 "2017-08-03T16:17:25Z")

</div>

@lueneburger, great to hear that it works 🙂 Feel free to report any suggestions you have to improve this module. @andrewkroh, thanks for the script. I will open a PR.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2017, 4:17pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-6-0-0-alpha2-output-question/95676/7 "2017-08-31T16:17:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
