Status of stopped process

(Henrique) #1

how to capture the status of the process when it is stopped? I only have the status when it is running.

Metricbeat 7.0.0 (Windows Server 2008 R2)
Elasticsearch 7.0.0 (Ubuntu Server 18.04 LTS)

(Jaime Soriano) #2

Hi @holiveira and welcome to discuss :slight_smile:

Metricbeat only collects information from things that are there, it cannot monitor things that are not there. For processes it only gets information from running processes, as top would do. It can at some moments get a process in stopped state if it has just been stopped but is still in the process table, but this is quite rare.

If you don't want to miss that a process has stopped, you can use the Auditbeat system module, that sends events when processes start or stop.

(Henrique) #3

Hmmm, right. Thanks for the feedback. :slight_smile: