# Missing documents

**URL:** <https://discuss.elastic.co/t/missing-documents/380946>\
**Category:** Elasticsearch\
**Created:** [August 11, 2025, 4:02pm UTC](https://discuss.elastic.co/t/missing-documents/380946 "2025-08-11T16:02:29Z")\
**Posts on this page:** 1\
**Showing post:** 30

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 15, 2025, 8:50pm UTC](https://discuss.elastic.co/t/missing-documents/380946/30 "2025-08-15T20:50:04Z")

</div>

@elasticforme

Glad you found it...

> [@stephenb](#):
>
> Example of the Top 5 Process Changes, tagged by name, if that process is in / then out of top 5 processes you can get data that looks like this...

This is often confused... I have helped many others with this functionality is not always clear ...

> [@elasticforme](#):
>
> will monitor for a week as I have thousands of metric per min, if all good then Architecture is good and in working as expected.

Turning on ALL the process can significantly increase the number of metrics you collect

I suggest you look _ **CLOSELY** _ at these settings as they are easily miss-understood

> **[System process metricset | Beats](https://www.elastic.co/docs/reference/beats/metricbeat/metricbeat-metricset-system-process)**
>
> The System process metricset provides process statistics. One document is provided for each process. This metricset is available on: FreeBSD, Linux, macOS,...

Example

> **`process.include_top_n.enabled`**  
> Set to false to disable the top N feature and include all processes, regardless of the other options. The default is `true`, but nothing is filtered unless one of the other options (`by_cpu` or `by_memory`) is set to a non-zero value.

You removed the two lines that disable filtering, but the Top N feature is still enabled without filtering—this is a minor distinction. I use this setting when I want to include the filter while being able to toggle the Top N feature on or off.

There are whitelist options and other methods for filtering available.

Additionally, you can actually apply more than one metricset definition, allowing you to have both Top N and a specific named set at the same time. Please refer to this thread for more information: [Metricbeat doesn't recognize the process - #4 by stephenb](https://discuss.elastic.co/t/metricbeat-doesnt-recognize-the-process/263176/4).

Example

```auto
- module: system
  period: 10s
  metricsets: ['process']
  process.include_top_n:
    by_cpu: 5 # include top 5 processes by CPU
    by_memory: 5 # include top 5 processes by memory

- module: system
  period: 10s
  metricsets: ['process']
  processes: ['^sysmon*']

```

So, take some time to think about what you really need, and we can likely help you customize it to your requirements.

---

_[View the full topic](https://discuss.elastic.co/t/missing-documents/380946)._
