# Old old Windows Server 2008 vs filebeat v.x

**URL:** https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343
**Category:** Beats
**Tags:** filebeat, metricbeat
**Created:** [July 2, 2024, 6:55am UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343 "2024-07-02T06:55:45Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)
#### Post date: [July 2, 2024, 6:55am UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/1 "2024-07-02T06:55:45Z")

</div>

I know it's very old, but for various legacy purposes we still have a few old Windows Server 2008 in the back of our data center, running on their last breath, meanwhile we want to monitoring a legacy App's log files, only our ES cluster is currently at 8.12.2, and attempting to use filebeat or metricbeat v.8.12.2 we get the error that kernel32.dll does support PssCaptureSnapShot. tried with monitoring disabled, but using multiline in filebeat.

So any change of using older beat version might work for this?

According to the support matrix we've tried v.7.17.22 with the same result though.

```auto
...
{"log.level":"info","@timestamp":"2024-07-02T08:33:58.741+0200","log.logger":"crawler","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/beater.(*crawler).Start","file.name":"beater/crawler.go","file.line":106},"message":"Loading and starting Inputs completed. Enabled inputs: 2","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-07-02T08:33:58.741+0200","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/cfgfile.(*Reloader).Run","file.name":"cfgfile/reload.go","file.line":163},"message":"Config reloader started","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-07-02T08:33:58.741+0200","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/cfgfile.(*Reloader).Run","file.name":"cfgfile/reload.go","file.line":223},"message":"Loading of config files completed.","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-07-02T08:34:28.765+0200","log.logger":"monitoring","log.origin":{"function":"runtime.gopanic","file.name":"runtime/panic.go","file.line":884},"message":"Stopping metrics logging.","service.name":"filebeat","ecs.version":"1.6.0"}
panic: Failed to find PssCaptureSnapshot procedure in kernel32.dll: The specified procedure could not be found.
	panic: Failed to find PssCaptureSnapshot procedure in kernel32.dll: The specified procedure could not be found.

goroutine 99 [running]:
golang.org/x/sys/windows.(*LazyProc).mustFind(...)
	golang.org/x/sys@v0.15.0/windows/dll_windows.go:325
golang.org/x/sys/windows.(*LazyProc).Addr(...)
	golang.org/x/sys@v0.15.0/windows/dll_windows.go:333
github.com/elastic/elastic-agent-system-metrics/metric/system/process.PssCaptureSnapshot(0x400?, 0x80, 0x0, 0x103?)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/zsyscall_windows.go:66 +0xf0
github.com/elastic/elastic-agent-system-metrics/metric/system/process.FetchNumThreads(0x292c)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process_windows.go:102 +0x27b
github.com/elastic/elastic-agent-system-metrics/metric/system/process.FillMetricsRequiringMoreAccess(_, {{0xc000615b63, 0x10}, {0x471f4e8, 0x7}, {0xc00060a0d8, 0x13}, {0x1, 0x292c}, {0x1, ...}, ...})
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process_windows.go:163 +0x6b
github.com/elastic/elastic-agent-system-metrics/metric/system/process.(*Stats).pidFill(_, _, _)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process.go:265 +0x6e5
github.com/elastic/elastic-agent-system-metrics/metric/system/process.(*Stats).GetSelf(_)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process.go:158 +0x8e
github.com/elastic/elastic-agent-system-metrics/report.MemStatsReporter.func1(0x1, {0x4f9c018, 0xc000596540})
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/report/report.go:52 +0x1e5
github.com/elastic/elastic-agent-libs/monitoring.(*Func).Visit(0xc000e83b18?, 0xe2?, {0x4f9c018?, 0xc000596540?})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/metrics.go:258 +0x2e
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).doVisit(0xc0003f3a80, 0x1, {0x4f9c018, 0xc000596540})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:83 +0x1c3
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).Visit(0xc000e83c28?, 0x23?, {0x4f9c018?, 0xc000596540?})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:65 +0x25
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).doVisit(0xc0000a7000, 0x1, {0x4f9c018, 0xc000596540})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:83 +0x1c3
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).Visit(...)
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:65
github.com/elastic/elastic-agent-libs/monitoring.CollectFlatSnapshot(0x2a?, 0x2b?, 0x0)
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/snapshot.go:63 +0x109
github.com/elastic/beats/v7/libbeat/monitoring/report/log.makeSnapshot(...)
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:201
github.com/elastic/beats/v7/libbeat/monitoring/report/log.(*reporter).snapshotLoop.func1()
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:150 +0x113
panic({0x40f4880, 0xc0005996e0})
	runtime/panic.go:884 +0x213
golang.org/x/sys/windows.(*LazyProc).mustFind(...)
	golang.org/x/sys@v0.15.0/windows/dll_windows.go:325
golang.org/x/sys/windows.(*LazyProc).Addr(...)
	golang.org/x/sys@v0.15.0/windows/dll_windows.go:333
github.com/elastic/elastic-agent-system-metrics/metric/system/process.PssCaptureSnapshot(0x400?, 0x80, 0x0, 0x103?)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/zsyscall_windows.go:66 +0xf0
github.com/elastic/elastic-agent-system-metrics/metric/system/process.FetchNumThreads(0x292c)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process_windows.go:102 +0x27b
github.com/elastic/elastic-agent-system-metrics/metric/system/process.FillMetricsRequiringMoreAccess(_, {{0xc00006f2f3, 0x10}, {0x471f4e8, 0x7}, {0xc00152b398, 0x13}, {0x1, 0x292c}, {0x1, ...}, ...})
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process_windows.go:163 +0x6b
github.com/elastic/elastic-agent-system-metrics/metric/system/process.(*Stats).pidFill(_, _, _)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process.go:265 +0x6e5
github.com/elastic/elastic-agent-system-metrics/metric/system/process.(*Stats).GetSelf(_)
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/metric/system/process/process.go:158 +0x8e
github.com/elastic/elastic-agent-system-metrics/report.MemStatsReporter.func1(0x1, {0x4f9c018, 0xc00102e400})
	github.com/elastic/elastic-agent-system-metrics@v0.9.1/report/report.go:52 +0x1e5
github.com/elastic/elastic-agent-libs/monitoring.(*Func).Visit(0xc001677748?, 0xe2?, {0x4f9c018?, 0xc00102e400?})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/metrics.go:258 +0x2e
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).doVisit(0xc0003f3a80, 0x1, {0x4f9c018, 0xc00102e400})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:83 +0x1c3
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).Visit(0xc001677858?, 0x23?, {0x4f9c018?, 0xc00102e400?})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:65 +0x25
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).doVisit(0xc0000a7000, 0x1, {0x4f9c018, 0xc00102e400})
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:83 +0x1c3
github.com/elastic/elastic-agent-libs/monitoring.(*Registry).Visit(...)
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/registry.go:65
github.com/elastic/elastic-agent-libs/monitoring.CollectFlatSnapshot(0xc001677a38?, 0xd0?, 0x0)
	github.com/elastic/elastic-agent-libs@v0.7.3/monitoring/snapshot.go:63 +0x109
github.com/elastic/beats/v7/libbeat/monitoring/report/log.makeSnapshot(...)
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:201
github.com/elastic/beats/v7/libbeat/monitoring/report/log.(*reporter).snapshotLoop(0xc00154c2d0)
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:169 +0x3b5
github.com/elastic/beats/v7/libbeat/monitoring/report/log.MakeReporter.func1()
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:134 +0x5a
created by github.com/elastic/beats/v7/libbeat/monitoring/report/log.MakeReporter
	github.com/elastic/beats/v7/libbeat/monitoring/report/log/log.go:132 +0x310

```

TIA

---

<div class="post-metadata">

### Author: ![Jokke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jokke/32/45973_2.png) [@Jokke](https://discuss.elastic.co/u/Jokke)
#### Post date: [August 22, 2024, 9:52am UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/2 "2024-08-22T09:52:34Z")

</div>

I'm in the same spot. Did you get it to work?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 22, 2024, 12:58pm UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/3 "2024-08-22T12:58:42Z")

</div>

> [@stefws](#):
>
> According to the support matrix we've tried v.7.17.22 with the same result though.

7.17.22 does not support Windows Server 2008.

There is this note in the Support Matrix page:

> From 7.17.19 onwards, 7.17.x releases do not support MacOS 10.14, 10.15, CentOS 8, Debian 9, Windows 7, Windows 8 and Windows Server 2008 & 2012 which have reached end of life.

You may try to use an older version of 7.17.

---

<div class="post-metadata">

### Author: ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)
#### Post date: [September 9, 2024, 9:14am UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/4 "2024-09-09T09:14:29Z")

</div>

Sorry for the delay, no gave up for now, working on other things. But maybe try a version \< 7.17.19 as next step...

---

<div class="post-metadata">

### Author: ![Jokke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jokke/32/45973_2.png) [@Jokke](https://discuss.elastic.co/u/Jokke)
#### Post date: [September 9, 2024, 9:30am UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/5 "2024-09-09T09:30:10Z")

</div>

That's okay. I configured a fluentd instance which converts some fields to be compatible with the new ECS fields in ES 8.12.0.

So I never upgraded and is still running Filebeat 6.8. Have worked quite okay now for some weeks.

---

<div class="post-metadata">

### Author: ![johncollaros](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johncollaros/32/7613_2.png) [@johncollaros](https://discuss.elastic.co/u/johncollaros)
#### Post date: [October 15, 2024, 3:05pm UTC](https://discuss.elastic.co/t/old-old-windows-server-2008-vs-filebeat-v-x/362343/6 "2024-10-15T15:05:19Z")

</div>

For anyone having this issue with older windows releases, I have had to chase up this very issue.

Golang 1.20 is the last version which supports windows 7, 8.1, Server 2008 and Server 2012.

The last versions of beats which use golang 1.20 are:  
8.12.2  
7.17.18

Additionally, a change was made to a library in beats elastic-agent-system-metrics which means it doesn't run on Windows 7/2008 (this is the issue you are experiencing).  
Commit here: [add the number of threads on the information collected per process](https://github.com/elastic/elastic-agent-system-metrics/commit/8630a5d99fbe4b4012370b4806d43b45fceb9804)  
This is affecting 8.11.0 onwards.

I have found that beats 8.10.4 is the last version which can run on older Win7/2008 kernels.

Hope this helps.
