# Topbeat sometimes returns an invalid value for cpu.system\_p on Windows

**URL:** <https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706>\
**Category:** Beats\
**Created:** [March 7, 2016, 9:02pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706 "2016-03-07T21:02:12Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcoPonton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcoponton/32/8333_2.png) [@MarcoPonton](https://discuss.elastic.co/u/MarcoPonton)\
**Post date:** [March 7, 2016, 9:02pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/1 "2016-03-07T21:02:12Z")

</div>

Hi,

I've been running Topbeats on servers for a PoC at a client for about 3 weeks. Every now and then, Topbeat returns an invalid `cpu.system_p` value. This of course does not look very good on a graph... So far I've seen it happen only 3 times on a single host (out of 3 hosts).

Here's the last example:

```auto
          "cpu": {
            "user": 18150,
            "user_p": 0,
            "nice": 0,
            "system": 20409,
            "system_p": 970881267037344770,
            "idle": 4365624,
            "iowait": 0,
            "irq": 0,
            "softirq": 0,
            "steal": 0
          },

```

I am unsure if an issue with `topbeat.go` calculations, `sigar_windows.go`, the system itself returning invalid values or cosmic rays 🙂 ...

Some info:

Beat version: **1.1.0**  
Operating System: **Windows 2012 R2 with up-to-date patches**  
Configuration:

```auto
input:
  period: 10

  procs: [".*"]

  stats:
    system: true
    proc: true
    filesystem: true
    cpu_per_core: true

```

Beats sent directly to ElasticSearch, not to LogStash.

Any ideas/suggestions to investigate further?

Thanks and regards,

Marco

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2016, 1:36pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/2 "2016-03-08T13:36:39Z")

</div>

Hi @MarcoPonton, can you post the immediately preceding cpu stat document to the one you already posted? This way we can look at the delta between the two and see if we can try and figure out where the calculation went wrong.

---

<div class="post-metadata">

**Author:** ![MarcoPonton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcoponton/32/8333_2.png) [@MarcoPonton](https://discuss.elastic.co/u/MarcoPonton)\
**Post date:** [March 8, 2016, 1:52pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/3 "2016-03-08T13:52:32Z")

</div>

Hi Andrew,

Here are the 3 records (the invalid one, and the ones before and after it):

```auto
    "hits": [
      {
        "_index": "topbeat-2016.03.07",
        "_type": "system",
        "_id": "AVNRK6pt8UEWGpsSjr2O",
        "_score": 3.6366284,
        "_source": {
          "@timestamp": "2016-03-07T13:02:08.907Z",
          "beat": {
            "hostname": "_REMOVED_",
            "name": "_REMOVED_"
          },
          "count": 1,
          "cpu": {
            "user": 18150,
            "user_p": 0,
            "nice": 0,
            "system": 20410,
            "system_p": 0.05,
            "idle": 4365604,
            "iowait": 0,
            "irq": 0,
            "softirq": 0,
            "steal": 0
          },
          "cpus": {},
          "load": {
            "load1": 0,
            "load5": 0,
            "load15": 0
          },
          "mem": {
            "total": 4294496256,
            "used": 1564626944,
            "free": 2729869312,
            "used_p": 0.36,
            "actual_used": 895258624,
            "actual_free": 1252093952,
            "actual_used_p": 0.21
          },
          "swap": {
            "total": 0,
            "used": 0,
            "free": 0,
            "used_p": 0
          },
          "type": "system"
        }
      },
      {
        "_index": "topbeat-2016.03.07",
        "_type": "system",
        "_id": "AVNRK9UW8UEWGpsSjsAa",
        "_score": 3.6360867,
        "_source": {
          "@timestamp": "2016-03-07T13:02:18.907Z",
          "beat": {
            "hostname": "_REMOVED_",
            "name": "_REMOVED_"
          },
          "count": 1,
          "cpu": {
            "user": 18150,
            "user_p": 0,
            "nice": 0,
            "system": 20409,
            "system_p": 970881267037344770,
            "idle": 4365624,
            "iowait": 0,
            "irq": 0,
            "softirq": 0,
            "steal": 0
          },
          "cpus": {},
          "load": {
            "load1": 0,
            "load5": 0,
            "load15": 0
          },
          "mem": {
            "total": 4294496256,
            "used": 1562251264,
            "free": 2732244992,
            "used_p": 0.36,
            "actual_used": 895258624,
            "actual_free": 1252093952,
            "actual_used_p": 0.21
          },
          "swap": {
            "total": 0,
            "used": 0,
            "free": 0,
            "used_p": 0
          },
          "type": "system"
        }
      },
      {
        "_index": "topbeat-2016.03.07",
        "_type": "system",
        "_id": "AVNRK_wm8UEWGpsSjsKX",
        "_score": 3.6337204,
        "_source": {
          "@timestamp": "2016-03-07T13:02:28.908Z",
          "beat": {
            "hostname": "_REMOVED_",
            "name": "_REMOVED_"
          },
          "count": 1,
          "cpu": {
            "user": 18150,
            "user_p": 0,
            "nice": 0,
            "system": 20410,
            "system_p": 0.05,
            "idle": 4365644,
            "iowait": 0,
            "irq": 0,
            "softirq": 0,
            "steal": 0
          },
          "cpus": {},
          "load": {
            "load1": 0,
            "load5": 0,
            "load15": 0
          },
          "mem": {
            "total": 4294496256,
            "used": 1561849856,
            "free": 2732646400,
            "used_p": 0.36,
            "actual_used": 895258624,
            "actual_free": 1252093952,
            "actual_used_p": 0.21
          },
          "swap": {
            "total": 0,
            "used": 0,
            "free": 0,
            "used_p": 0
          },
          "type": "system"
        }
      }
    ]

```

Thanks!

Marco

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2016, 3:05pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/4 "2016-03-08T15:05:27Z")

</div>

The root cause of the high `system_p` value is that the `cpu.system` value decreases by 1.

`sys_delta = cpu_2.system - cpu_1.system = 20409 - 20410 = -1`

Since Topbeat was not expecting a negative delta [it uses](https://github.com/elastic/beats/blob/master/topbeat/beater/topbeat.go#L439) an `uint64` variable type to store the sys\_delta value. Since this is an unsigned variable, the value becomes `18446744073709551615` instead of `-1`. This is why the `system_p` value is really large.

If I change the variable type used to store the "`sys_delta`" value then the resulting `system_p` value becomes `-0.06`. It doesn't make sense, but at least it's representative of the values used in the calculation.

I pasted the relevant code and your values into the Golang playground for [demonstration](https://play.golang.org/p/S3vnQU1Du4).

So what's causing the `cpu.system` value to decrease? It's either Windows or the [elastic/gosigar](https://github.com/elastic/gosigar/blob/master/sigar_windows.go#L117) library. I suspect it's the library. There is some floating point arithmetic being used to calculate the values. Instead of using floating point I think it should use this [method](https://github.com/elastic/beats/blob/491cf95a02fa697d265c800218a9d48dd50dd780/vendor/golang.org/x/sys/windows/ztypes_windows.go#L348).

Sorry for the long post. Would you be able to test a [development build](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=topbeat/) if I make a change?

---

<div class="post-metadata">

**Author:** ![MarcoPonton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcoponton/32/8333_2.png) [@MarcoPonton](https://discuss.elastic.co/u/MarcoPonton)\
**Post date:** [March 8, 2016, 5:00pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/5 "2016-03-08T17:00:41Z")

</div>

I'd be happy to test a development/instrumented build to help pinpoint the issue or simply confirm the issue is not recurring anymore.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2016, 5:19pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/6 "2016-03-08T17:19:58Z")

</div>

Great. I will post an update once a development build is available. Here's the [pull request](https://github.com/elastic/beats/pull/1128) with the changes; it just needs reviewed before it can merge. See the my comment in the PR.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 8, 2016, 9:24pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/7 "2016-03-08T21:24:18Z")

</div>

The dev build with my changes is now ready. Download topbeat-5.0.0-nightlylatest-windows.zip from [S3](https://beats-nightlies.s3.amazonaws.com/index.html?prefix=topbeat/) and give it a try. Thanks

---

<div class="post-metadata">

**Author:** ![MarcoPonton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcoponton/32/8333_2.png) [@MarcoPonton](https://discuss.elastic.co/u/MarcoPonton)\
**Post date:** [March 9, 2016, 1:42pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/8 "2016-03-09T13:42:51Z")

</div>

I will update all servers today and will get back to you in a few days to let you know how things look. Thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 15, 2016, 6:01am UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/9 "2016-03-15T06:01:16Z")

</div>

@MarcoPonton What's the verdict on the change? 👍 or 👎

---

<div class="post-metadata">

**Author:** ![MarcoPonton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcoponton/32/8333_2.png) [@MarcoPonton](https://discuss.elastic.co/u/MarcoPonton)\
**Post date:** [March 17, 2016, 3:29pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/10 "2016-03-17T15:29:21Z")

</div>

@andrewkroh,

Sorry for the delay! It's been running on all servers (7) for over a week now without any issue. So it looks like 👍!

I'm keeping an eye on it, will report again next week just to confirm, but if all good next week I would consider the matter closed.

Thanks for your help with this!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:54pm UTC](https://discuss.elastic.co/t/topbeat-sometimes-returns-an-invalid-value-for-cpu-system-p-on-windows/43706/11 "2017-07-05T21:54:35Z")

</div>


