# Selecting only wy WiFi interface for network metric does not seem to work

**URL:** <https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 4, 2024, 9:35pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486 "2024-12-04T21:35:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 4, 2024, 9:35pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/1 "2024-12-04T21:35:02Z")

</div>

Hello,

I tried multiple variations of WiFi to only log network metrics for my WiFi adapter and not for all the rest:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/9/498badb2780a591fd9540f46102553962337079b.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8fc9208927aebf632f493f9089baaf95b3ed8eb1.png)

But whatever I try it keeps indexing metrics for all my interfaces. Anyone got an idea what I'm doing wrong? The docsonly show a Linux example. is it even possible with Windows to select the interface?

Tried:

WiFi  
"WiFi"  
[WiFi]  
["WiFi"]

Willem

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 4, 2024, 10:57pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/2 "2024-12-04T22:57:29Z")

</div>

Hi @willemdh

First which integration is that... just the system network integration?

If so, I don't think those names are what the integration is looking for...

I would run and let it collect all the networks

Then look at `system.network.name` values then use that value to filter on....

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 5, 2024, 6:43pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/3 "2024-12-05T18:43:46Z")

</div>

Indeed just the system network integration. I actually did exactly as you suggested. The system.network.name is WiFi..

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 6, 2024, 6:20am UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/4 "2024-12-06T06:20:12Z")

</div>

Interesting I see the same behavior on my linux box... seems like perhaps a bug...

BUT as a workaround I just put in a drop\_event processor

```auto
- drop_event.when.not.equals:
    system.network.name: docker0

```

Worked.

 ![Screenshot 2024-12-05 at 10.19.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e1bf4f53e57dcd1807ea09acba9ad1f227cf714.png)

Interesting I inspected the agent... the manifest looks correct when setting the interfaces value.

```auto
$ sudo /opt/Elastic/Agent/elastic-agent inspect
...
  - data_stream:
      dataset: system.network
      type: metrics
    id: system/metrics-system.network-bfbbe64e-818c-4e66-86f2-ff9a0b6d004b
    metricsets:
    - network
    network:
      interfaces:
      - docker0 << HERE LOOKS correct not sure why not working... 
    period: 10s
...

```

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [December 6, 2024, 5:05pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/5 "2024-12-06T17:05:17Z")

</div>

Hi @stephenb

I can confirm setting:

```auto
- drop_event.when.not.equals:
    system.network.name: WiFi

```

Works.

Tx

Willem

---

<div class="post-metadata">

**Author:** ![SteveJR1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stevejr1/32/137049_2.png) [@SteveJR1](https://discuss.elastic.co/u/SteveJR1)\
**Post date:** [February 22, 2026, 3:44pm UTC](https://discuss.elastic.co/t/selecting-only-wy-wifi-interface-for-network-metric-does-not-seem-to-work/371486/6 "2026-02-22T15:44:58Z")

</div>

On Windows, the `system.network` metricset in Metricbeat doesn’t filter by interface name the same way the Linux examples show. That’s why trying things like `WiFi`, `"WiFi"` or `["WiFi"]` isn’t working — it just keeps collecting all interfaces. The correct way on Windows is to use the exact interface name as shown by the OS. First, run this in PowerShell:

```auto
Get-NetAdapter

```

Check the **Name** column and copy it exactly (for example: **[`Wi-Fi`](https://router-19216811.com/)**, not **`WiFi`** ).

Then in your `metricbeat.yml`:

```auto
- module: system
  metricsets: ["network"]
  interfaces: ["Wi-Fi"]

```

Make sure the name matches exactly, including dash and capitalization. If that still doesn’t filter, another reliable workaround is to collect all interfaces and then drop the ones you don’t want using a processor:

```auto
processors:
  - drop_event:
      when:
        not:
          equals:
            system.network.name: "Wi-Fi"

```

That way only your Wi-Fi adapter gets indexed.
