# Services metrics

**URL:** <https://discuss.elastic.co/t/services-metrics/89807>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [June 17, 2017, 10:23am UTC](https://discuss.elastic.co/t/services-metrics/89807 "2017-06-17T10:23:00Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 17, 2017, 10:23am UTC](https://discuss.elastic.co/t/services-metrics/89807/1 "2017-06-17T10:23:00Z")

</div>

Hey, I want to get metrics of windows services (like get-services command data) .  
I have not seen any metric module that doing so.  
Does someone know any?

Thanks

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 17, 2017, 5:24pm UTC](https://discuss.elastic.co/t/services-metrics/89807/2 "2017-06-17T17:24:00Z")

</div>

Is it something specific to `get-services` command that you want to monitor, like the running state of a specific service? Or are you really interested in knowing the running state of all services of a host?

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 17, 2017, 5:40pm UTC](https://discuss.elastic.co/t/services-metrics/89807/3 "2017-06-17T17:40:58Z")

</div>

A state of specific service ..

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 17, 2017, 5:56pm UTC](https://discuss.elastic.co/t/services-metrics/89807/4 "2017-06-17T17:56:59Z")

</div>

Does this services responds in a specific tcp port?

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 17, 2017, 8:17pm UTC](https://discuss.elastic.co/t/services-metrics/89807/5 "2017-06-17T20:17:29Z")

</div>

I want to illustrate the Get-services "service name" command to get his status - running or not, thats all.

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 17, 2017, 8:24pm UTC](https://discuss.elastic.co/t/services-metrics/89807/6 "2017-06-17T20:24:47Z")

</div>

Yes, I understand. I don't think there is a way of invoking that command using metricbeat. The reason I asked about the open port is because if your final objective is to monitor if a service is running or not then I recommend that you use [heartbeat](https://www.elastic.co/products/beats/heartbeat) instead. But heartbeat will require that the target service responds in an open port.

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 17, 2017, 11:40pm UTC](https://discuss.elastic.co/t/services-metrics/89807/7 "2017-06-17T23:40:26Z")

</div>

I really prefer to monitor specific service by metricbeat.  
My only option is to develop a new metricsuite for that ?  
Or there is an opensource for a module or something..

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 17, 2017, 11:53pm UTC](https://discuss.elastic.co/t/services-metrics/89807/8 "2017-06-17T23:53:14Z")

</div>

Yes, I think you will need to develop one. But IMO what you are trying to collect is not really suitable as a metricset.

Have you looked into [execbeat](https://github.com/christiangalsterer/execbeat)? It allows running commands and collect output. I don't if it works with Windows commands thought...

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 18, 2017, 12:09am UTC](https://discuss.elastic.co/t/services-metrics/89807/9 "2017-06-18T00:09:07Z")

</div>

The thing is I want to make just 1 "agent" that is collecting metrics from servers, and not to split it...

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 18, 2017, 12:12am UTC](https://discuss.elastic.co/t/services-metrics/89807/10 "2017-06-18T00:12:18Z")

</div>

You mean that you are already running metricbeat and would not like to run another beat?

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 18, 2017, 12:25am UTC](https://discuss.elastic.co/t/services-metrics/89807/11 "2017-06-18T00:25:54Z")

</div>

Yes. I want it to be by 1 service, "1 agent ", modulary and agily. I thought that this is kind of obvious that if the System module collects metrics on processes anf cpu, it might be option to collect metrics on services status ...

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 18, 2017, 12:28am UTC](https://discuss.elastic.co/t/services-metrics/89807/12 "2017-06-18T00:28:36Z")

</div>

The thing is that everything related to uptime goes into heartbeat. Metricbeat is used for collecting counters, gauges, etc...

---

<div class="post-metadata">

**Author:** ![Quardo](https://avatars.discourse-cdn.com/v4/letter/q/919ad9/32.png) [@Quardo](https://discuss.elastic.co/u/Quardo)\
**Post date:** [June 18, 2017, 4:36am UTC](https://discuss.elastic.co/t/services-metrics/89807/13 "2017-06-18T04:36:01Z")

</div>

As I saw and used, there are modules that are collecting status, like apache in generally.  
In my opinion, the system module should have the option to collect metrics - status from a services.  
There is a way to offer this idea to be developed by elastic team?

---

<div class="post-metadata">

**Author:** ![geekpete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geekpete/32/20409_2.png) [@geekpete](https://discuss.elastic.co/u/geekpete)\
**Post date:** [June 19, 2017, 12:52am UTC](https://discuss.elastic.co/t/services-metrics/89807/14 "2017-06-19T00:52:54Z")

</div>

This doesn't directly solve your requirement but I thought that I'd mention that in a future version of Metricbeat there will be a Windows Module:  
[https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-module-windows.html](https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-module-windows.html)

which will start with a PerfMon metricset initially:  
[https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-metricset-windows-perfmon.html](https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-metricset-windows-perfmon.html)

So what you could do is have your own script poke a metric into a counter visible to PerfMon and have MetricBeat read that value out with the Windows Module using PerfMon metricset.

For example:  
(Get-Service | Where-Object -Property Status -eq Running | Measure).count

Though a native metricset for the Windows Module that's able to measure service status would be a much better solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 12:53am UTC](https://discuss.elastic.co/t/services-metrics/89807/15 "2017-07-17T00:53:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
