Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "state": "running",
- "memory": {
- "size": 19501056,
- "rss": {
- "bytes": 23101440,
- "pct": 0.0013
- },
- "share": 0
- },
- "cpu": {
- "start_time": "2018-02-19T04:01:51.265Z",
- "total": {
- "norm": {
- "pct": 0
- },
- "pct": 0
- }
- },
- "ppid": 508
- }
- },
- "metricset": {
- "name": "process",
- "rtt": 93750,
- "module": "system"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.457465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pid": 752,
- "ppid": 556,
- "pgid": 0,
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "size": 2949120,
- "rss": {
- "bytes": 5894144,
- "pct": 0.0003
- },
- "share": 0
- },
- "name": "vmacthlp.exe",
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:51.390Z"
- }
- }
- },
- "metricset": {
- "name": "process",
- "rtt": 93750,
- "module": "system"
- },
- "beat": {
- "hostname": "pon258",
- "version": "6.0.0",
- "name": "pon258"
- }
- }
- 2018/02/22 16:09:55.457465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "rtt": 109375,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "username": "NT AUTHORITY\\SYSTEM",
- "pgid": 0,
- "name": "svchost.exe",
- "state": "running",
- "memory": {
- "size": 3149824,
- "rss": {
- "bytes": 6762496,
- "pct": 0.0004
- },
- "share": 0
- },
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:51.437Z"
- },
- "pid": 808,
- "ppid": 556
- }
- }
- }
- 2018/02/22 16:09:55.473090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:51.640Z"
- },
- "pid": 908,
- "ppid": 556,
- "pgid": 0,
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "size": 218714112,
- "rss": {
- "bytes": 235208704,
- "pct": 0.0137
- },
- "share": 0
- },
- "name": "svchost.exe"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 109375
- },
- "beat": {
- "hostname": "pon258",
- "version": "6.0.0",
- "name": "pon258"
- }
- }
- 2018/02/22 16:09:55.473090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "memory": {
- "share": 0,
- "size": 11702272,
- "rss": {
- "bytes": 17047552,
- "pct": 0.001
- }
- },
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:57.796Z"
- },
- "pid": 1136,
- "ppid": 556,
- "pgid": 0,
- "name": "spoolsv.exe",
- "state": "running"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 109375
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.473090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "rtt": 125000,
- "module": "system",
- "name": "process"
- },
- "system": {
- "process": {
- "pgid": 0,
- "name": "VProSvc.exe",
- "state": "running",
- "ppid": 556,
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "rss": {
- "bytes": 9662464,
- "pct": 0.0006
- },
- "share": 0,
- "size": 24129536
- },
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:57.937Z"
- },
- "pid": 1268
- }
- },
- "beat": {
- "version": "6.0.0",
- "name": "pon258",
- "hostname": "pon258"
- }
- }
- 2018/02/22 16:09:55.488715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pid": 4112,
- "pgid": 0,
- "name": "ChristiesAppraisalsManagement.exe",
- "username": "CHRISTIES\\crepp",
- "memory": {
- "size": 236867584,
- "rss": {
- "pct": 0.0154,
- "bytes": 265142272
- },
- "share": 0
- },
- "cpu": {
- "total": {
- "norm": {
- "pct": 0
- },
- "pct": 0
- },
- "start_time": "2018-02-22T09:33:52.815Z"
- },
- "state": "running",
- "ppid": 7280
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 125000
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.488715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "start_time": "2018-02-19T04:31:56.782Z",
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- }
- },
- "pid": 3232,
- "pgid": 0,
- "name": "CcmExec.exe",
- "state": "running",
- "memory": {
- "share": 0,
- "size": 31961088,
- "rss": {
- "bytes": 59658240,
- "pct": 0.0035
- }
- },
- "ppid": 556
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 125000
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.488715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:02:04.296Z"
- },
- "pid": 2488,
- "name": "beremote.exe",
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "size": 37179392,
- "rss": {
- "pct": 0.0032,
- "bytes": 55414784
- },
- "share": 0
- },
- "ppid": 556,
- "pgid": 0,
- "state": "running"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 140625
- },
- "beat": {
- "version": "6.0.0",
- "name": "pon258",
- "hostname": "pon258"
- }
- }
- 2018/02/22 16:09:55.519965 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "ppid": 2860,
- "pgid": 0,
- "state": "running",
- "username": "NT AUTHORITY\\NETWORK SERVICE",
- "memory": {
- "share": 0,
- "size": 46141440,
- "rss": {
- "bytes": 53858304,
- "pct": 0.0031
- }
- },
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-22T16:07:52.863Z"
- },
- "pid": 788,
- "name": "w3wp.exe"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 140625
- }
- }
- 2018/02/22 16:09:55.535590 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:02:02.781Z"
- },
- "ppid": 556,
- "pgid": 0,
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "name": "vmware-converter-a.exe",
- "memory": {
- "size": 32411648,
- "rss": {
- "pct": 0.0026,
- "bytes": 45416448
- },
- "share": 0
- },
- "pid": 2320
- }
- },
- "metricset": {
- "rtt": 140625,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.535590 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "memory": {
- "size": 60563456,
- "rss": {
- "bytes": 37138432,
- "pct": 0.0022
- },
- "share": 0
- },
- "pid": 1552,
- "name": "HealthService.exe",
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:01:59.078Z"
- },
- "ppid": 556,
- "pgid": 0
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 171875
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.535590 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "rss": {
- "bytes": 36696064,
- "pct": 0.0021
- },
- "share": 0,
- "size": 92635136
- },
- "pid": 1920,
- "ppid": 556,
- "pgid": 0,
- "name": "metricbeat.exe",
- "cpu": {
- "total": {
- "norm": {
- "pct": 0
- },
- "pct": 0
- },
- "start_time": "2018-02-19T04:01:59.218Z"
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 187500
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.551215 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:09:55.348Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "ppid": 9060,
- "username": "CHRISTIES\\ynilajkar",
- "memory": {
- "size": 90963968,
- "rss": {
- "bytes": 31174656,
- "pct": 0.0018
- },
- "share": 0
- },
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-22T16:08:45.316Z"
- },
- "pid": 7092,
- "pgid": 0,
- "name": "metricbeat.exe",
- "state": "running"
- }
- },
- "metricset": {
- "rtt": 187500,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:09:55.723090 async.go:143: DBG 20 events out of 20 events sent to logstash. Continue sending
- 2018/02/22 16:09:55.801215 logger.go:29: DBG ackloop: receive ack [3: 0, 20]
- 2018/02/22 16:09:55.801215 logger.go:29: DBG broker ACK events: count=20, start-seq=5, end-seq=24
- 2018/02/22 16:09:55.801215 logger.go:18: DBG ackloop: return ack to broker loop:20
- 2018/02/22 16:09:55.801215 logger.go:18: DBG ackloop: done send ack
- 2018/02/22 16:10:16.457465 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.memstats.gc_next=7345472 beat.memstats.memory_alloc=3691024 beat.memstats.memory_total=11669192 libbeat.config.module.running=2 libbeat.config.module.starts=2 libbeat.config.reloads=1 libbeat.output.events.acked=26
- libbeat.output.events.batches=4 libbeat.output.events.total=26 libbeat.output.read.bytes=24 libbeat.output.write.bytes=3257 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=0 libbeat.pipeline.events.published=26 libbeat.pipeline.events.retry=2 libbeat.pipeline.events.total=26 libbeat.pipel
- ine.queue.acked=26 metricbeat.system.cpu.events=1 metricbeat.system.cpu.success=1 metricbeat.system.diskio.events=1 metricbeat.system.diskio.success=1 metricbeat.system.filesystem.events=1 metricbeat.system.filesystem.success=1 metricbeat.system.fsstat.events=1 metricbeat.system.fsstat.success=1 met
- ricbeat.system.memory.events=1 metricbeat.system.memory.success=1 metricbeat.system.network.events=2 metricbeat.system.network.success=2 metricbeat.system.process.events=18 metricbeat.system.process.success=18 metricbeat.system.process_summary.events=1 metricbeat.system.process_summary.success=1
- 2018/02/22 16:10:46.457465 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.memstats.gc_next=7345472 beat.memstats.memory_alloc=3735152 beat.memstats.memory_total=11713320 libbeat.config.module.running=2 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=0
- 2018/02/22 16:10:46.519965 reload.go:152: DBG Scan for new config files
- 2018/02/22 16:10:46.519965 cfgfile.go:143: DBG Load config from file: C:\metricbeat\modules.d\system.yml
- 2018/02/22 16:10:46.519965 reload.go:171: DBG Number of module configs found: 2
- 2018/02/22 16:10:46.519965 reload.go:199: DBG Remove module from stoplist: 10310018093630389728
- 2018/02/22 16:10:46.519965 reload.go:199: DBG Remove module from stoplist: 17766349570693032427
- 2018/02/22 16:11:16.457465 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.memstats.gc_next=7345472 beat.memstats.memory_alloc=3810320 beat.memstats.memory_total=11788488 libbeat.config.module.running=2 libbeat.config.reloads=1 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=0
- 2018/02/22 16:11:46.457465 metrics.go:39: INFO Non-zero metrics in the last 30s: beat.memstats.gc_next=7345472 beat.memstats.memory_alloc=3819728 beat.memstats.memory_total=11797896 libbeat.config.module.running=2 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=0
- 2018/02/22 16:11:46.519965 reload.go:152: DBG Scan for new config files
- 2018/02/22 16:11:46.519965 cfgfile.go:143: DBG Load config from file: C:\metricbeat\modules.d\system.yml
- 2018/02/22 16:11:46.519965 reload.go:171: DBG Number of module configs found: 2
- 2018/02/22 16:11:46.519965 reload.go:199: DBG Remove module from stoplist: 10310018093630389728
- 2018/02/22 16:11:46.519965 reload.go:199: DBG Remove module from stoplist: 17766349570693032427
- 2018/02/22 16:11:51.519965 filesystem.go:57: DBG error getting filesystem stats for 'A:\': GetDiskFreeSpaceEx failed: The device is not ready.
- 2018/02/22 16:11:51.519965 filesystem.go:57: DBG error getting filesystem stats for 'D:\': GetDiskFreeSpaceEx failed: The device is not ready.
- 2018/02/22 16:11:51.519965 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:50.519Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "rtt": 1000000,
- "module": "system",
- "name": "filesystem"
- },
- "system": {
- "filesystem": {
- "type": "fixed",
- "free": 95943278592,
- "available": 95943278592,
- "total": 146682146816,
- "files": 0,
- "free_files": 0,
- "used": {
- "pct": 0.3459,
- "bytes": 50738868224
- },
- "mount_point": "C:\\",
- "device_name": "C:\\"
- }
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:51.519965 fsstat.go:61: DBG error fetching filesystem stats for 'A:\': GetDiskFreeSpaceEx failed: The device is not ready.
- 2018/02/22 16:11:51.519965 fsstat.go:64: DBG filesystem: C:\ total=146682146816, used=50738868224, free=95943278592
- 2018/02/22 16:11:51.519965 fsstat.go:61: DBG error fetching filesystem stats for 'D:\': GetDiskFreeSpaceEx failed: The device is not ready.
- 2018/02/22 16:11:51.519965 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:50.519Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "fsstat": {
- "total_files": 0,
- "total_size": {
- "used": 50738868224,
- "total": 146682146816,
- "free": 95943278592
- },
- "count": 1
- }
- },
- "metricset": {
- "rtt": 1000000,
- "module": "system",
- "name": "fsstat"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:51.613715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:51.613Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "memory": {
- "total": 17179041792,
- "used": {
- "pct": 0.1866,
- "bytes": 3205341184
- },
- "free": 13973700608,
- "actual": {
- "free": 13973700608,
- "used": {
- "bytes": 3205341184,
- "pct": 0.1866
- }
- },
- "swap": {
- "total": 42306588672,
- "used": {
- "bytes": 2630193152,
- "pct": 0.0622
- },
- "free": 39676395520
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "memory"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:52.160590 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:52.129Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "diskio": {
- "io": {
- "time": 0
- },
- "name": "C:",
- "read": {
- "count": 0,
- "time": 0,
- "bytes": 0
- },
- "write": {
- "bytes": 0,
- "count": 0,
- "time": 0
- }
- }
- },
- "metricset": {
- "rtt": 31250,
- "module": "system",
- "name": "diskio"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:52.519965 async.go:143: DBG 4 events out of 4 events sent to logstash. Continue sending
- 2018/02/22 16:11:52.598090 logger.go:29: DBG ackloop: receive ack [4: 0, 4]
- 2018/02/22 16:11:52.598090 logger.go:29: DBG broker ACK events: count=2, start-seq=25, end-seq=26
- 2018/02/22 16:11:52.598090 logger.go:29: DBG broker ACK events: count=2, start-seq=3, end-seq=4
- 2018/02/22 16:11:52.598090 logger.go:18: DBG ackloop: return ack to broker loop:4
- 2018/02/22 16:11:52.598090 logger.go:18: DBG ackloop: done send ack
- 2018/02/22 16:11:52.973090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:52.973Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "network": {
- "out": {
- "errors": 0,
- "dropped": 0,
- "packets": 29649506,
- "bytes": 481574526
- },
- "name": "Local Area Connection 3",
- "in": {
- "errors": 0,
- "dropped": 0,
- "bytes": 2504200646,
- "packets": 41463734
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "network"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:52.973090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:52.973Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "network": {
- "name": "MS TCP Loopback interface",
- "in": {
- "bytes": 456166,
- "packets": 4636,
- "errors": 0,
- "dropped": 0
- },
- "out": {
- "errors": 0,
- "dropped": 0,
- "packets": 4636,
- "bytes": 456166
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "network"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:53.988715 async.go:143: DBG 2 events out of 2 events sent to logstash. Continue sending
- 2018/02/22 16:11:54.051215 logger.go:29: DBG ackloop: receive ack [5: 0, 2]
- 2018/02/22 16:11:54.051215 logger.go:29: DBG broker ACK events: count=2, start-seq=27, end-seq=28
- 2018/02/22 16:11:54.051215 logger.go:18: DBG ackloop: return ack to broker loop:2
- 2018/02/22 16:11:54.051215 logger.go:18: DBG ackloop: done send ack
- 2018/02/22 16:11:54.723090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:54.723Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "cpu": {
- "steal": {
- "pct": 0
- },
- "user": {
- "pct": 0.1245
- },
- "cores": 4,
- "softirq": {
- "pct": 0
- },
- "total": {
- "pct": 0.331
- },
- "idle": {
- "pct": 3.669
- },
- "irq": {
- "pct": 0
- },
- "nice": {
- "pct": 0
- },
- "system": {
- "pct": 0.2064
- },
- "iowait": {
- "pct": 0
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "cpu"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.285590 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.238Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "namespace": "process.summary",
- "module": "system",
- "name": "process_summary",
- "rtt": 46875
- },
- "system": {
- "process": {
- "summary": {
- "stopped": 0,
- "zombie": 0,
- "unknown": 63,
- "total": 137,
- "sleeping": 0,
- "running": 74,
- "idle": 0
- }
- }
- },
- "beat": {
- "hostname": "pon258",
- "version": "6.0.0",
- "name": "pon258"
- }
- }
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=0: error getting process state for pid=0: getProcName failed: OpenProcess failed for pid=0: The parameter is incorrect.; getProcStatus failed: OpenProcess failed for pid=0: The parameter is incorrect.; getParentPid failed: OpenProcess fa
- iled for pid=0: The parameter is incorrect.; getProcCredName failed: OpenProcess failed for pid=0: The parameter is incorrect.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=4: error getting process state for pid=4: getProcName failed: GetProcessImageFileName failed for pid=4: GetProcessImageFileName failed: invalid argument; getProcCredName failed: OpenProcessToken failed for pid=4: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=864: error getting process state for pid=864: getProcCredName failed: OpenProcessToken failed for pid=864: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=952: error getting process state for pid=952: getProcCredName failed: OpenProcessToken failed for pid=952: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=992: error getting process state for pid=992: getProcCredName failed: OpenProcessToken failed for pid=992: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=1176: error getting process state for pid=1176: getProcCredName failed: OpenProcessToken failed for pid=1176: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=1360: error getting process state for pid=1360: getProcCredName failed: OpenProcessToken failed for pid=1360: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=1396: error getting process state for pid=1396: getProcCredName failed: OpenProcessToken failed for pid=1396: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=1492: error getting process state for pid=1492: getProcCredName failed: OpenProcessToken failed for pid=1492: Access is denied.
- 2018/02/22 16:11:55.551215 helper.go:371: DBG Skip process pid=2100: error getting process state for pid=2100: getProcCredName failed: OpenProcessToken failed for pid=2100: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=2628: error getting process state for pid=2628: getProcCredName failed: OpenProcessToken failed for pid=2628: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=2648: error getting process state for pid=2648: getProcCredName failed: OpenProcessToken failed for pid=2648: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=2676: error getting process state for pid=2676: getProcCredName failed: OpenProcessToken failed for pid=2676: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=2712: error getting process state for pid=2712: getProcCredName failed: OpenProcessToken failed for pid=2712: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=2736: error getting process state for pid=2736: getProcCredName failed: OpenProcessToken failed for pid=2736: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=688: error getting process state for pid=688: getProcCredName failed: OpenProcessToken failed for pid=688: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=3140: error getting process state for pid=3140: getProcCredName failed: OpenProcessToken failed for pid=3140: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=3552: error getting process state for pid=3552: getProcCredName failed: OpenProcessToken failed for pid=3552: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=3856: error getting process state for pid=3856: getProcCredName failed: OpenProcessToken failed for pid=3856: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=4448: error getting process state for pid=4448: getProcCredName failed: OpenProcessToken failed for pid=4448: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=4104: error getting process state for pid=4104: getProcCredName failed: OpenProcessToken failed for pid=4104: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=4532: error getting process state for pid=4532: getProcCredName failed: OpenProcessToken failed for pid=4532: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=9052: error getting process state for pid=9052: getProcCredName failed: OpenProcessToken failed for pid=9052: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=7472: error getting process state for pid=7472: getProcCredName failed: OpenProcessToken failed for pid=7472: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=3956: error getting process state for pid=3956: getProcCredName failed: OpenProcessToken failed for pid=3956: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=8236: error getting process state for pid=8236: getProcCredName failed: OpenProcessToken failed for pid=8236: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=8508: error getting process state for pid=8508: getProcCredName failed: OpenProcessToken failed for pid=8508: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=6864: error getting process state for pid=6864: getProcCredName failed: OpenProcessToken failed for pid=6864: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=4384: error getting process state for pid=4384: getProcCredName failed: OpenProcessToken failed for pid=4384: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=6836: error getting process state for pid=6836: getProcCredName failed: OpenProcessToken failed for pid=6836: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=3448: error getting process state for pid=3448: getProcCredName failed: OpenProcessToken failed for pid=3448: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=9100: error getting process state for pid=9100: getProcCredName failed: OpenProcessToken failed for pid=9100: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=7636: error getting process state for pid=7636: getProcCredName failed: OpenProcessToken failed for pid=7636: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=6716: error getting process state for pid=6716: getProcCredName failed: OpenProcessToken failed for pid=6716: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=10164: error getting process state for pid=10164: getProcCredName failed: OpenProcessToken failed for pid=10164: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=1548: error getting process state for pid=1548: getProcCredName failed: OpenProcessToken failed for pid=1548: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=6740: error getting process state for pid=6740: getProcCredName failed: OpenProcessToken failed for pid=6740: Access is denied.
- 2018/02/22 16:11:55.566840 helper.go:371: DBG Skip process pid=4440: error getting process state for pid=4440: getProcCredName failed: OpenProcessToken failed for pid=4440: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=8468: error getting process state for pid=8468: getProcCredName failed: OpenProcessToken failed for pid=8468: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=9024: error getting process state for pid=9024: getProcCredName failed: OpenProcessToken failed for pid=9024: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=9664: error getting process state for pid=9664: getProcCredName failed: OpenProcessToken failed for pid=9664: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=4524: error getting process state for pid=4524: getProcCredName failed: OpenProcessToken failed for pid=4524: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=9812: error getting process state for pid=9812: getProcCredName failed: OpenProcessToken failed for pid=9812: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=6348: error getting process state for pid=6348: getProcCredName failed: OpenProcessToken failed for pid=6348: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=5932: error getting process state for pid=5932: getProcCredName failed: OpenProcessToken failed for pid=5932: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=4260: error getting process state for pid=4260: getProcCredName failed: OpenProcessToken failed for pid=4260: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=4680: error getting process state for pid=4680: getProcCredName failed: OpenProcessToken failed for pid=4680: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=3928: error getting process state for pid=3928: getProcCredName failed: OpenProcessToken failed for pid=3928: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=8656: error getting process state for pid=8656: getProcCredName failed: OpenProcessToken failed for pid=8656: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=9128: error getting process state for pid=9128: getProcCredName failed: OpenProcessToken failed for pid=9128: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=4120: error getting process state for pid=4120: getProcCredName failed: OpenProcessToken failed for pid=4120: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=6808: error getting process state for pid=6808: getProcCredName failed: OpenProcessToken failed for pid=6808: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=804: error getting process state for pid=804: getProcCredName failed: OpenProcessToken failed for pid=804: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=1228: error getting process state for pid=1228: getProcCredName failed: OpenProcessToken failed for pid=1228: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=9864: error getting process state for pid=9864: getProcCredName failed: OpenProcessToken failed for pid=9864: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=3432: error getting process state for pid=3432: getProcCredName failed: OpenProcessToken failed for pid=3432: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=1144: error getting process state for pid=1144: getProcCredName failed: OpenProcessToken failed for pid=1144: Access is denied.
- 2018/02/22 16:11:55.582465 helper.go:371: DBG Skip process pid=648: error getting process state for pid=648: getProcCredName failed: OpenProcessToken failed for pid=648: Access is denied.
- 2018/02/22 16:11:55.598090 helper.go:371: DBG Skip process pid=4352: error getting process state for pid=4352: getProcCredName failed: OpenProcessToken failed for pid=4352: Access is denied.
- 2018/02/22 16:11:55.598090 helper.go:371: DBG Skip process pid=8500: error getting process state for pid=8500: getProcCredName failed: OpenProcessToken failed for pid=8500: Access is denied.
- 2018/02/22 16:11:55.676215 helper.go:371: DBG Skip process pid=5220: error getting process state for pid=5220: getProcCredName failed: OpenProcessToken failed for pid=5220: Access is denied.
- 2018/02/22 16:11:55.676215 helper.go:371: DBG Skip process pid=9384: error getting process state for pid=9384: getProcCredName failed: OpenProcessToken failed for pid=9384: Access is denied.
- 2018/02/22 16:11:55.676215 helper.go:371: DBG Skip process pid=4696: error getting process state for pid=4696: getProcCredName failed: OpenProcessToken failed for pid=4696: Access is denied.
- 2018/02/22 16:11:55.691840 helper.go:391: DBG Filtered top processes down to 17 processes
- 2018/02/22 16:11:55.691840 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 156250
- },
- "beat": {
- "version": "6.0.0",
- "name": "pon258",
- "hostname": "pon258"
- },
- "system": {
- "process": {
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "share": 0,
- "size": 217784320,
- "rss": {
- "pct": 0.0137,
- "bytes": 234643456
- }
- },
- "cpu": {
- "total": {
- "norm": {
- "pct": 0.0024
- },
- "pct": 0.0095
- },
- "start_time": "2018-02-19T04:01:51.640Z"
- },
- "pgid": 0,
- "name": "svchost.exe",
- "pid": 908,
- "ppid": 556,
- "state": "running"
- }
- }
- }
- 2018/02/22 16:11:55.691840 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "size": 15237120,
- "rss": {
- "bytes": 11087872,
- "pct": 0.0006
- },
- "share": 0
- },
- "cpu": {
- "total": {
- "pct": 0.0043,
- "norm": {
- "pct": 0.0011
- }
- },
- "start_time": "2018-02-22T09:00:26.018Z"
- },
- "ppid": 432,
- "pgid": 0,
- "state": "running",
- "name": "winlogon.exe",
- "pid": 6184
- }
- },
- "metricset": {
- "rtt": 156250,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.691840 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "ppid": 432,
- "name": "winlogon.exe",
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "share": 0,
- "size": 15392768,
- "rss": {
- "bytes": 10620928,
- "pct": 0.0006
- }
- },
- "cpu": {
- "total": {
- "pct": 0.0036,
- "norm": {
- "pct": 0.0009
- }
- },
- "start_time": "2018-02-22T09:33:07.065Z"
- },
- "pid": 6880,
- "pgid": 0,
- "state": "running"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 156250
- },
- "beat": {
- "version": "6.0.0",
- "name": "pon258",
- "hostname": "pon258"
- }
- }
- 2018/02/22 16:11:55.707465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "name": "process",
- "rtt": 156250,
- "module": "system"
- },
- "system": {
- "process": {
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "start_time": "2018-02-22T14:13:02.535Z",
- "total": {
- "norm": {
- "pct": 0.0007
- },
- "pct": 0.0026
- }
- },
- "pid": 1196,
- "ppid": 432,
- "pgid": 0,
- "name": "winlogon.exe",
- "state": "running",
- "memory": {
- "rss": {
- "bytes": 11235328,
- "pct": 0.0007
- },
- "share": 0,
- "size": 15253504
- }
- }
- },
- "beat": {
- "version": "6.0.0",
- "name": "pon258",
- "hostname": "pon258"
- }
- }
- 2018/02/22 16:11:55.707465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "cpu": {
- "total": {
- "pct": 0.0022,
- "norm": {
- "pct": 0.0006
- }
- },
- "start_time": "2018-02-19T04:01:51.265Z"
- },
- "pid": 568,
- "ppid": 508,
- "pgid": 0,
- "username": "NT AUTHORITY\\SYSTEM",
- "name": "lsass.exe",
- "state": "running",
- "memory": {
- "size": 19484672,
- "rss": {
- "pct": 0.0013,
- "bytes": 23089152
- },
- "share": 0
- }
- }
- },
- "metricset": {
- "rtt": 156250,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.707465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "name": "HealthService.exe",
- "memory": {
- "share": 0,
- "size": 60641280,
- "rss": {
- "pct": 0.0013,
- "bytes": 22597632
- }
- },
- "cpu": {
- "total": {
- "norm": {
- "pct": 0.0006
- },
- "pct": 0.0022
- },
- "start_time": "2018-02-19T04:01:59.078Z"
- },
- "pid": 1552,
- "ppid": 556,
- "pgid": 0,
- "username": "NT AUTHORITY\\SYSTEM",
- "state": "running"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 171875
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.707465 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pgid": 0,
- "name": "csrss.exe",
- "state": "running",
- "pid": 9840,
- "ppid": 432,
- "username": "NT AUTHORITY\\SYSTEM",
- "memory": {
- "rss": {
- "bytes": 7168000,
- "pct": 0.0004
- },
- "share": 0,
- "size": 3932160
- },
- "cpu": {
- "total": {
- "pct": 0.0022,
- "norm": {
- "pct": 0.0006
- }
- },
- "start_time": "2018-02-22T16:07:22.926Z"
- }
- }
- },
- "metricset": {
- "rtt": 171875,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.723090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 171875
- },
- "system": {
- "process": {
- "memory": {
- "rss": {
- "bytes": 10903552,
- "pct": 0.0006
- },
- "share": 0,
- "size": 15192064
- },
- "ppid": 432,
- "state": "running",
- "name": "winlogon.exe",
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "total": {
- "pct": 0.0018,
- "norm": {
- "pct": 0.0005
- }
- },
- "start_time": "2018-02-22T13:46:30.988Z"
- },
- "pid": 1324,
- "pgid": 0
- }
- }
- }
- 2018/02/22 16:11:55.723090 async.go:143: DBG 9 events out of 9 events sent to logstash. Continue sending
- 2018/02/22 16:11:55.723090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "ppid": 556,
- "pgid": 0,
- "name": "CcmExec.exe",
- "username": "NT AUTHORITY\\SYSTEM",
- "pid": 3232,
- "state": "running",
- "memory": {
- "share": 0,
- "size": 31883264,
- "rss": {
- "bytes": 59596800,
- "pct": 0.0035
- }
- },
- "cpu": {
- "total": {
- "pct": 0.0018,
- "norm": {
- "pct": 0.0005
- }
- },
- "start_time": "2018-02-19T04:31:56.782Z"
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 171875
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.723090 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "cpu": {
- "total": {
- "norm": {
- "pct": 0.0004
- },
- "pct": 0.0017
- },
- "start_time": "2018-02-22T09:33:52.815Z"
- },
- "pgid": 0,
- "name": "ChristiesAppraisalsManagement.exe",
- "memory": {
- "size": 236867584,
- "rss": {
- "bytes": 265142272,
- "pct": 0.0154
- },
- "share": 0
- },
- "pid": 4112,
- "ppid": 7280,
- "state": "running",
- "username": "CHRISTIES\\crepp"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 187500
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.738715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "rtt": 187500,
- "module": "system",
- "name": "process"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "memory": {
- "rss": {
- "pct": 0.0046,
- "bytes": 79101952
- },
- "share": 0,
- "size": 9310208
- },
- "cpu": {
- "start_time": "2018-02-19T04:01:51.250Z",
- "total": {
- "pct": 0.0014,
- "norm": {
- "pct": 0.0004
- }
- }
- },
- "pid": 556,
- "ppid": 508,
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "pgid": 0,
- "name": "services.exe"
- }
- }
- }
- 2018/02/22 16:11:55.738715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "state": "running",
- "cpu": {
- "total": {
- "norm": {
- "pct": 0
- },
- "pct": 0
- },
- "start_time": "2018-02-19T04:02:04.296Z"
- },
- "pid": 2488,
- "ppid": 556,
- "pgid": 0,
- "memory": {
- "share": 0,
- "size": 37179392,
- "rss": {
- "pct": 0.0032,
- "bytes": 55414784
- }
- },
- "name": "beremote.exe",
- "username": "NT AUTHORITY\\SYSTEM"
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 187500
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.738715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pgid": 0,
- "pid": 788,
- "ppid": 2860,
- "name": "w3wp.exe",
- "state": "running",
- "username": "NT AUTHORITY\\NETWORK SERVICE",
- "memory": {
- "size": 46096384,
- "rss": {
- "bytes": 53833728,
- "pct": 0.0031
- },
- "share": 0
- },
- "cpu": {
- "start_time": "2018-02-22T16:07:52.863Z",
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- }
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 203125
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.738715 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "name": "vmware-converter-a.exe",
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T04:02:02.781Z"
- },
- "ppid": 556,
- "pgid": 0,
- "pid": 2320,
- "memory": {
- "size": 32411648,
- "rss": {
- "bytes": 45416448,
- "pct": 0.0026
- },
- "share": 0
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 203125
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.754340 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 203125
- },
- "system": {
- "process": {
- "state": "running",
- "username": "NT AUTHORITY\\SYSTEM",
- "pid": 1920,
- "name": "metricbeat.exe",
- "memory": {
- "size": 92635136,
- "rss": {
- "bytes": 36761600,
- "pct": 0.0021
- },
- "share": 0
- },
- "cpu": {
- "total": {
- "pct": 0.0008,
- "norm": {
- "pct": 0.0002
- }
- },
- "start_time": "2018-02-19T04:01:59.218Z"
- },
- "ppid": 556,
- "pgid": 0
- }
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.754340 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pid": 7092,
- "pgid": 0,
- "username": "CHRISTIES\\ynilajkar",
- "memory": {
- "size": 91029504,
- "rss": {
- "pct": 0.002,
- "bytes": 34689024
- },
- "share": 0
- },
- "ppid": 9060,
- "name": "metricbeat.exe",
- "state": "running",
- "cpu": {
- "total": {
- "pct": 0.001,
- "norm": {
- "pct": 0.0003
- }
- },
- "start_time": "2018-02-22T16:08:45.316Z"
- }
- }
- },
- "metricset": {
- "module": "system",
- "name": "process",
- "rtt": 203125
- },
- "beat": {
- "hostname": "pon258",
- "version": "6.0.0",
- "name": "pon258"
- }
- }
- 2018/02/22 16:11:55.754340 processor.go:262: DBG Publish event: {
- "@timestamp": "2018-02-22T16:11:55.535Z",
- "@metadata": {
- "beat": "metricbeat",
- "type": "doc",
- "version": "6.0.0"
- },
- "system": {
- "process": {
- "pgid": 0,
- "name": "wmiprvse.exe",
- "username": "NT AUTHORITY\\SYSTEM",
- "ppid": 808,
- "pid": 4436,
- "state": "running",
- "memory": {
- "share": 0,
- "size": 21291008,
- "rss": {
- "bytes": 29478912,
- "pct": 0.0017
- }
- },
- "cpu": {
- "total": {
- "pct": 0,
- "norm": {
- "pct": 0
- }
- },
- "start_time": "2018-02-19T11:35:46.055Z"
- }
- }
- },
- "metricset": {
- "name": "process",
- "rtt": 218750,
- "module": "system"
- },
- "beat": {
- "name": "pon258",
- "hostname": "pon258",
- "version": "6.0.0"
- }
- }
- 2018/02/22 16:11:55.801215 logger.go:29: DBG ackloop: receive ack [6: 0, 9]
- 2018/02/22 16:11:55.801215 logger.go:29: DBG broker ACK events: count=9, start-seq=29, end-seq=37
- 2018/02/22 16:11:55.801215 logger.go:18: DBG ackloop: return ack to broker loop:9
- 2018/02/22 16:11:55.801215 logger.go:18: DBG ackloop: done send ack
- 2018/02/22 16:11:56.723090 async.go:143: DBG 10 events out of 10 events sent to logstash. Continue sending
- 2018/02/22 16:11:56.801215 logger.go:29: DBG ackloop: receive ack [7: 0, 10]
- 2018/02/22 16:11:56.801215 logger.go:29: DBG broker ACK events: count=10, start-seq=38, end-seq=47
- 2018/02/22 16:11:56.801215 logger.go:18: DBG ackloop: return ack to broker loop:10
- 2018/02/22 16:11:56.801215 logger.go:18: DBG ackloop: done send ack
- 2018/02/22 16:12:03.238715 service.go:33: DBG Received sigterm/sigint, stopping
- 2018/02/22 16:12:03.238715 service.go:39: DBG Received svc stop/shutdown request
- 2018/02/22 16:12:03.238715 reload.go:148: INFO Dynamic config reloader stopped
- 2018/02/22 16:12:03.238715 metrics.go:51: INFO Total non-zero values: beat.memstats.gc_next=4747648 beat.memstats.memory_alloc=4024800 beat.memstats.memory_total=19046064 libbeat.config.module.running=2 libbeat.config.module.starts=2 libbeat.config.reloads=3 libbeat.output.events.acked=51 libbeat.o
- utput.events.batches=8 libbeat.output.events.total=51 libbeat.output.read.bytes=48 libbeat.output.type=logstash libbeat.output.write.bytes=6743 libbeat.pipeline.clients=2 libbeat.pipeline.events.active=0 libbeat.pipeline.events.published=51 libbeat.pipeline.events.retry=2 libbeat.pipeline.events.tot
- al=51 libbeat.pipeline.queue.acked=51 metricbeat.system.cpu.events=2 metricbeat.system.cpu.success=2 metricbeat.system.diskio.events=2 metricbeat.system.diskio.success=2 metricbeat.system.filesystem.events=2 metricbeat.system.filesystem.success=2 metricbeat.system.fsstat.events=2 metricbeat.system.f
- sstat.success=2 metricbeat.system.memory.events=2 metricbeat.system.memory.success=2 metricbeat.system.network.events=4 metricbeat.system.network.success=4 metricbeat.system.process.events=35 metricbeat.system.process.success=35 metricbeat.system.process_summary.events=2 metricbeat.system.process_su
- mmary.success=2
- 2018/02/22 16:12:03.238715 metrics.go:52: INFO Uptime: 3m17.890625s
- 2018/02/22 16:12:03.238715 beat.go:268: INFO metricbeat stopped.
- C:\metricbeat>hostname
- pon258
Add Comment
Please, Sign In to add comment