# Alert for disk space on server with multiple disks

**URL:** <https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 28, 2018, 8:31pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856 "2018-06-28T20:31:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [June 28, 2018, 8:31pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856/1 "2018-06-28T20:31:31Z")

</div>

Hello Community,

I working to get an alert for diskspace over 75% on server which have multiple drives (A, B, C, D). I having difficulty to in compare condition with multiple drives in a bucket. I hope below snippet of code and results will give some idea  
{  
"trigger": {  
"schedule": {  
"interval": "1m"  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": [  
{  
"exists": {  
"field": "system.filesystem.used.pct"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-15m",  
"lte": "now",  
"format": "epoch\_millis"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"host": {  
"terms": {  
"field": "beat.hostname",  
"size": 20,  
"order": {  
"pct": "desc"  
}  
},  
"aggs": {  
"pct": {  
"max": {  
"field": "system.filesystem.used.pct",  
"script": {  
"source": "doc['system.filesystem.used.pct'].value \*100",  
"lang": "painless"  
}  
}  
},  
"mpoint": {  
"terms": {  
"field": "system.filesystem.mount\_point",  
"size": 5,  
"order": {  
"pct": "desc"  
}  
},  
"aggs": {  
"pct": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"script": {  
"source": "ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; for (int i = 0; i \< arr.length; i++) { if (arr[i]['pct'].value \> params.threshold) { return true; } } return false;",  
"lang": "painless",  
"params": {  
"threshold": 0.75  
}  
}  
},  
"actions": {  
"email\_1": {  
"email": {  
"profile": "standard",  
"priority": "high",  
"to": [  
"test@test.com"  
],  
"subject": "High FS Usage on {{ctx.payload.aggregations.host.buckets.0.key}}",  
"body": {  
"html": " **{{ctx.payload.aggregations.host.buckets.0.mpoint.buckets.0.key}}** reached **{{ctx.payload.aggregations.host.buckets.0.pct.value}}%**"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [June 28, 2018, 9:04pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856/2 "2018-06-28T21:04:52Z")

</div>

And the results are ,

```
`{

```

"watch\_id": "_inlined_",  
"node": "Bd-EWXLQTbKMG-oCTDvGhQ",  
"state": "executed",  
"status": {  
"state": {  
"active": true,  
"timestamp": "2018-06-28T20:38:31.505Z"  
},  
"last\_checked": "2018-06-28T20:38:31.505Z",  
"last\_met\_condition": "2018-06-28T20:38:31.505Z",  
"actions": {  
"email\_1": {  
"ack": {  
"timestamp": "2018-06-28T20:38:31.505Z",  
"state": "ackable"  
},  
"last\_execution": {  
"timestamp": "2018-06-28T20:38:31.505Z",  
"successful": true  
},  
"last\_successful\_execution": {  
"timestamp": "2018-06-28T20:38:31.505Z",  
"successful": true  
}  
}  
},  
"execution\_state": "executed",  
"version": -1  
},  
"trigger\_event": {  
"type": "manual",  
"triggered\_time": "2018-06-28T20:38:31.505Z",  
"manual": {  
"schedule": {  
"scheduled\_time": "2018-06-28T20:38:31.505Z"  
}  
}  
},  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"metricbeat-\*"  
],  
"types": [],  
"body": {  
"size": 0,  
"query": {  
"bool": {  
"must": [  
{  
"exists": {  
"field": "system.filesystem.used.pct"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-15m",  
"lte": "now",  
"format": "epoch\_millis"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"host": {  
"terms": {  
"field": "beat.hostname",  
"size": 20,  
"order": {  
"pct": "desc"  
}  
},  
"aggs": {  
"pct": {  
"max": {  
"field": "system.filesystem.used.pct",  
"script": {  
"source": "doc['system.filesystem.used.pct'].value \*100",  
"lang": "painless"  
}  
}  
},  
"mpoint": {  
"terms": {  
"field": "system.filesystem.mount\_point",  
"size": 5,  
"order": {  
"pct": "desc"  
}  
},  
"aggs": {  
"pct": {  
"max": {  
"field": "system.filesystem.used.pct"  
}  
}  
}  
}  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.aggregations.host.buckets.0.pct.value": {  
"gt": 75  
}  
}  
},  
"metadata": {  
"xpack": {  
"type": "json"  
}  
},  
"result": {  
"execution\_time": "2018-06-28T20:38:31.505Z",  
"execution\_duration": 165,  
"input": {  
"type": "search",  
"status": "success",  
"payload": {  
"\_shards": {  
"total": 186,  
"failed": 0,  
"successful": 186,  
"skipped": 180  
},  
"hits": {  
"hits": [],  
"total": 644,  
"max\_score": 0  
},  
"took": 163,  
"timed\_out": false,  
"aggregations": {  
"host": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"pct": {  
"value": 90.4  
},  
"doc\_count": 55,  
"mpoint": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"pct": {  
"value": 0.904  
},  
"doc\_count": 11,  
"key": "/opt/data2"  
},  
{  
"pct": {  
"value": 0.88  
},  
"doc\_count": 11,  
"key": "/opt/data"  
},  
{  
"pct": {  
"value": 0.709  
},  
"doc\_count": 11,  
"key": "/opt/data3"  
},  
{  
"pct": {  
"value": 0.618  
},  
"doc\_count": 11,  
"key": "/"  
},  
{  
"pct": {  
"value": 0.225  
},  
"doc\_count": 11,  
"key": "/opt/data4"  
}  
]  
},  
"key": "Server-1"  
},  
{  
"pct": {  
"value": 73.10000000000001  
},  
"doc\_count": 15,  
"mpoint": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets": [  
{  
"pct": {  
"value": 0.7310000000000001  
},  
"doc\_count": 15,  
"key": "A:\"  
}  
]  
},  
"key": "server - 2"  
}  
]  
}  
}  
},

---

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [June 28, 2018, 9:05pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856/3 "2018-06-28T21:05:22Z")

</div>

Continuation of results

```
  ` "search": {
    
"request": {
      "search_type": "query_then_fetch",
      "indices": [
        "metricbeat-*"
      ],
      "types": [],
      "body": {
        "size": 0,
        "query": {
          "bool": {
            "must": [
              {
                "exists": {
                  "field": "system.filesystem.used.pct"
                }
              },
              {
                "range": {
                  "@timestamp": {
                    "gte": "now-15m",
                    "lte": "now",
                    "format": "epoch_millis"
                  }
                }
              }
            ]
          }
        },
        "aggs": {
          "host": {
            "terms": {
              "field": "beat.hostname",
              "size": 20,
              "order": {
                "pct": "desc"
              }
            },
            "aggs": {
              "pct": {
                "max": {
                  "field": "system.filesystem.used.pct",
                  "script": {
                    "source": "doc['system.filesystem.used.pct'].value *100",
                    "lang": "painless"
                  }
                }
              },
              "mpoint": {
                "terms": {
                  "field": "system.filesystem.mount_point",
                  "size": 5,
                  "order": {
                    "pct": "desc"
                  }
                },
                "aggs": {
                  "pct": {
                    "max": {
                      "field": "system.filesystem.used.pct"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
},
"condition": {
  "type": "compare",
  "status": "success",
  "met": true,
  "compare": {
    "resolved_values": {
      "ctx.payload.aggregations.host.buckets.0.pct.value": 90.4
    }
  }
},
"actions": [
  {
    "id": "email_1",
    "type": "email",
    "status": "simulated",
    "email": {
      "message": {
        "id": "_inlined__f13ff6e7-56aa-426d-beb8-c69a328b70e6-2018-06-28T20:38:31.505Z",
        "priority": "high",
        "sent_date": "2018-06-28T20:38:31.670Z",
        "to": [
          "rpendela@creditshop.com"
        ],
        "subject": "Disk space on <b>A:\\</b> reached <b>90.4%</b> on server "server-1",
        "body": {
          "text": "test"
        }
      }
    }
  }
]

```

},  
"messages": []  
}`

I want to see the results as

Disk space on disk A:\ reached to 90.4% on server "server-1"  
Disk space on disk B:\ reached to 88.0% on server "server-1"  
Disk space on disk A:\ reached to 73.0% on server "server-2"  
Disk space on disk C:\ reached to 85.8% on server "server-3"`

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 29, 2018, 1:18pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856/4 "2018-06-29T13:18:40Z")

</div>

please format all your messages properly using markdown, those snippets above are super hard to read and reduce the chances of getting help.

try this as a starting point, this also shows how to keep debugging things better using the execute watch API and also to reduce the feedback loop how much sense your watch makes. See [this blog post](https://www.elastic.co/blog/watching-the-watches-writing-debugging-and-testing-watches) for more information

```auto
POST _xpack/watcher/watch/_execute
{
  "alternative_input": {
    "_shards": {
      "total": 186,
      "failed": 0,
      "successful": 186,
      "skipped": 180
    },
    "hits": {
      "hits": [],
      "total": 644,
      "max_score": 0
    },
    "took": 163,
    "timed_out": false,
    "aggregations": {
      "host": {
        "doc_count_error_upper_bound": 0,
        "sum_other_doc_count": 0,
        "buckets": [
          {
            "pct": {
              "value": 90.4
            },
            "doc_count": 55,
            "mpoint": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": [
                {
                  "pct": {
                    "value": 0.904
                  },
                  "doc_count": 11,
                  "key": "/opt/data2"
                },
                {
                  "pct": {
                    "value": 0.88
                  },
                  "doc_count": 11,
                  "key": "/opt/data"
                },
                {
                  "pct": {
                    "value": 0.709
                  },
                  "doc_count": 11,
                  "key": "/opt/data3"
                },
                {
                  "pct": {
                    "value": 0.618
                  },
                  "doc_count": 11,
                  "key": "/"
                },
                {
                  "pct": {
                    "value": 0.225
                  },
                  "doc_count": 11,
                  "key": "/opt/data4"
                }
              ]
            },
            "key": "Server-1"
          }
        ]
      }
    }
  },
  "watch": {
    "trigger": {
      "schedule": {
        "interval": "10h"
      }
    },
    "input": {
      "simple": {
        "foo": "bar"
      }
    },
    "actions": {
      "logme": {
        "transform" : {
          "script" : "def hosts = []; ctx.payload.aggregations.host.buckets.stream().forEach(b -> b.mpoint.buckets.stream().forEach(b2 -> hosts.add(['host':b.key, 'mountpoint':b2.key, 'size': b2.pct.value*100.0]))) ; return ['hosts': hosts]"
        },
        "logging": {
          "text": "{{#ctx.payload.hosts}}{{mountpoint}} on {{host}} has {{size}}{{/ctx.payload.hosts}}\n"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2018, 1:18pm UTC](https://discuss.elastic.co/t/alert-for-disk-space-on-server-with-multiple-disks/137856/5 "2018-07-27T13:18:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
