# Unable to limit records using process.include\_top\_n

**URL:** <https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [October 27, 2017, 11:35am UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558 "2017-10-27T11:35:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![safehouse](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@safehouse](https://discuss.elastic.co/u/safehouse)\
**Post date:** [October 27, 2017, 11:35am UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/1 "2017-10-27T11:35:49Z")

</div>

I want to limit the records sent from metricbeat using the process.include\_top\_n set of options. However, wither I can't figure out the correct setup (likely) or it's not working as expected on my systems. Any help or guidance would be greatly appreciated.

here is part of the metricbeat yml file. Let me know if you would like to see more or different data:

```
#========================== Modules configuration ============================
metricbeat.modules:
- module: system
  period: 30s
  metricsets:
    - cpu
    - load
    - memory
    - network
    - process
    #- process_summary
    #- core
    #- diskio
    #- socket
  processes: ['.*']
  process.include_top_n:
    by_cpu: 5 # include top 5 processes by CPU
    by_memory: 5 # include top 5 processes by memory

- module: system
  period: 5m
  metricsets:
    - filesystem
    - fsstat
  processors:
  - drop_event.when.regexp:
      system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|host|lib)($|/)'

#- module: system
# period: 15m
# metricsets:
# - uptime

  # If false, cmdline of a process is not cached.
  #process.cmdline.cache.enabled: true

  # Enable collection of cgroup metrics from processes on Linux.
  #process.cgroups.enabled: true

  # A list of regular expressions used to whitelist environment variables
  # reported with the process metricset's events. Defaults to empty.
  #process.env.whitelist: []

  # Include the cumulative CPU tick values with the process metrics. Defaults
  # to false.
  #process.include_cpu_ticks: false

  # Configure reverse DNS lookup on remote IP addresses in the socket metricset.
  #socket.reverse_lookup.enabled: false
  #socket.reverse_lookup.success_ttl: 60s
  #socket.reverse_lookup.failure_ttl: 60s

```

What I'm getting is all process data (or that's what it looks like to me)

 ![Metricbeat processes Kibana](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c836f3d43c43fa9a0480b983bf7bec99a11236e.png)

I was expecting to see just 5 - 10 processes listed. Maybe these would grow over time as the top 5 changed and are recorded - but this data is from 15 minutes.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 27, 2017, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/2 "2017-10-27T14:03:19Z")

</div>

Which version of metricbeat are you using?

---

<div class="post-metadata">

**Author:** ![safehouse](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@safehouse](https://discuss.elastic.co/u/safehouse)\
**Post date:** [October 27, 2017, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/3 "2017-10-27T14:23:21Z")

</div>

@steffens - good point. I forgot to mention I was testing with Metricbeat 5.6.2 and then also updated to 5.6.3-1 to test the latest version.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 27, 2017, 3:08pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/4 "2017-10-27T15:08:30Z")

</div>

`process.include_top_n` is a 6.0 feature. You'll see that it's only present in the [6.0 documentation](https://www.elastic.co/guide/en/beats/metricbeat/6.0/metricbeat-metricset-system-process.html). You can try the feature by downloading [6.0.0-rc1](https://www.elastic.co/downloads/beats/metricbeat#preview-release).

---

<div class="post-metadata">

**Author:** ![safehouse](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@safehouse](https://discuss.elastic.co/u/safehouse)\
**Post date:** [October 27, 2017, 3:10pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/5 "2017-10-27T15:10:30Z")

</div>

Well, that would explain it! 🙂 Thanks @andrewkroh

I'll update and report back here (hopefully with success).

---

<div class="post-metadata">

**Author:** ![safehouse](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@safehouse](https://discuss.elastic.co/u/safehouse)\
**Post date:** [October 27, 2017, 7:18pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/6 "2017-10-27T19:18:40Z")

</div>

After updating to 6.0.0-rc1 it's working as expected - and that is awesome. Saving me tons of disk space and helping me focus on just the data I need. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2017, 7:18pm UTC](https://discuss.elastic.co/t/unable-to-limit-records-using-process-include-top-n/105558/7 "2017-11-24T19:18:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
