# Totally exclude "CD-ROM Disc" metrics

**URL:** <https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265>\
**Category:** Metrics\
**Created:** [June 17, 2025, 8:04pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265 "2025-06-17T20:04:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [June 17, 2025, 8:04pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265/1 "2025-06-17T20:04:26Z")

</div>

I'm unable to determine how to fully exclude alerting on CD-ROM metrics. I've gone into the system integrations and added ignore of unknown and unavailable, along with Unknown and Unavailable, and I still get alerts on metric thresholds that the drive utilization is at 100% (set to alert over 95%).

I've seen mention of setting a query to not send out alerts, but I don't even want these showing up in the Observability -\> Alert listing as Active as they are invalid.

Can anybody point me to a reliable reference on achieving this that works with 8.15.1? (We are at the whim of our MSP and are going to be moving forward at some point, but not yet.)

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [June 17, 2025, 9:46pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265/2 "2025-06-17T21:46:56Z")

</div>

Look at this : [Diskstat Windows - Could not return any performance counter - #3 by dot-mike](https://discuss.elastic.co/t/diskstat-windows-could-not-return-any-performance-counter/378033/3)

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [June 17, 2025, 9:54pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265/3 "2025-06-17T21:54:12Z")

</div>

Thanks, but I already put those two types in my 'system' integrations as filesystems to ignore (mentioned in the post), and no difference. Out of desperation, I even tried uppercase versions as that is how they show up in OSquery.

 ![Screenshot 2025-06-17 at 4.57.32 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f7a99497935cdae9b7957ecb076861f09ab6781.png)

---

<div class="post-metadata">

**Author:** ![dot-mike](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dot-mike/32/143339_2.png) [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Post date:** [June 22, 2025, 9:15pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265/4 "2025-06-22T21:15:04Z")

</div>

I believe you are using fleets right, if so could go to Integration Overview dashboard and copy the exact error message seen for this specific integration? If there is any?

Or maybe you could add a processor handler blow filesystem metrics like...

replace `D` with your drive letter.

```auto
  processors:
  - drop_event.when.regexp:
      system.filesystem.mount_point: 'D:'

```

Can't confirm if this will work or not.

---

<div class="post-metadata">

**Author:** ![taprove](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taprove/32/146825_2.png) [@taprove](https://discuss.elastic.co/u/taprove)\
**Post date:** [June 24, 2025, 4:40pm UTC](https://discuss.elastic.co/t/totally-exclude-cd-rom-disc-metrics/379265/5 "2025-06-24T16:40:07Z")

</div>

Appreciate that recommendation, but I'm not sure if it was the upgrade to 8.18.x or my putting another ignore line in of type "udf", but we no longer receive alerts on CD-ROM drives now.

Thanks,  
Tim
