# System.fsstat filtering / processors

**URL:** <https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 14, 2016, 2:51pm UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029 "2016-12-14T14:51:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![slalomnut](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@slalomnut](https://discuss.elastic.co/u/slalomnut)\
**Post date:** [December 14, 2016, 2:51pm UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029/1 "2016-12-14T14:51:22Z")

</div>

More questions surrounding [All numbers reported by Metricbeat too high (bug?)](https://discuss.elastic.co/t/all-numbers-reported-by-metricbeat-too-high-bug/56094/6) and [https://github.com/elastic/beats/issues/2079](https://github.com/elastic/beats/issues/2079)

Is there a way to use filters or processors to limit metricbeat's collection of file systems? I need the ability to exclude non-user type mounts. (e.g. df -at ext4 -t ext3 -t xfs -t zfs -t btrfs --total)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [December 16, 2016, 7:33am UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029/2 "2016-12-16T07:33:26Z")

</div>

I think this should definitively possible with processors: [https://www.elastic.co/guide/en/beats/metricbeat/5.1/configuration-processors.html](https://www.elastic.co/guide/en/beats/metricbeat/5.1/configuration-processors.html)

---

<div class="post-metadata">

**Author:** ![slalomnut](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@slalomnut](https://discuss.elastic.co/u/slalomnut)\
**Post date:** [December 20, 2016, 2:25pm UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029/3 "2016-12-20T14:25:14Z")

</div>

I've tried the below processor with no success. I based the regex off df -a names but have no idea what or how fsstat is querying.

processors:

- drop\_event:  
when:  
regexp:  
system.fsstat:  
equals: '^(cgroup|tmpfs|rootfs|devpts|pstore|configfs|debugfs|mqueue|hugetlbfs|nfsd|sunrpc|/etc/auto.home|binfmt\_misc)'

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 20, 2016, 5:11pm UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029/4 "2016-12-20T17:11:29Z")

</div>

You can filter the events produced by the system.filesystem metricset (see [example](https://www.elastic.co/guide/en/beats/metricbeat/5.1/metricbeat-metricset-system-filesystem.html#_filtering)). But you cannot configure the filesystems types that are summed by the system.fsstat module. It will sum them all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2017, 5:11pm UTC](https://discuss.elastic.co/t/system-fsstat-filtering-processors/69029/5 "2017-01-17T17:11:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
