# Best approach to monitor a Linux Service with the Elastic Agent?

**URL:** <https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916>\
**Category:** Elastic Agent\
**Created:** [February 4, 2026, 6:05pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916 "2026-02-04T18:05:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fer.mt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fer.mt/32/145089_2.png) [@fer.mt](https://discuss.elastic.co/u/fer.mt)\
**Post date:** [February 4, 2026, 6:05pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/1 "2026-02-04T18:05:19Z")

</div>

Hello!  
I have a software that is critical for us so we want to monitor its availability. We want to start by monitoring the process/service that it creates when running. The software runs on Linux systems. Currently, I have install the elastic agent and configured the policy to retrieve System process metrics.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f867ee79c67f2cbdb4510b9b0a06d486f37af023.png)

And I am in fact receiving document when the process(BESClient specifically) is running. However, I need to create a monitor rule that triggers when the process is not running. I tried defining a rule to alert me when there was 1 or less documents in the last 5min but that doesn’t trigger anything.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/981afddf96a64cbf6cca11feab2f3608d667ff4d.png)

How can I accomplish this?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [February 5, 2026, 2:04am UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/2 "2026-02-05T02:04:05Z")

</div>

Hello @fer.mt

Welcome to the Community!!

Below few pointers could help to understand & troubleshoot further :

Could you please share what is the time duration used to monitor this service? Last 5/10/15/30 minutes?

Can you try executing the query in the Discover tab to see what is the output for the query and the records that are returned?

Ideally if the service is down & there is no record for this process your alert should trigger when you check say for last 5/10 min but if time duration is 24 hours than the rule might not trigger as older records will satisfy the condition.

Thanks!!

---

<div class="post-metadata">

**Author:** ![fer.mt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fer.mt/32/145089_2.png) [@fer.mt](https://discuss.elastic.co/u/fer.mt)\
**Post date:** [February 5, 2026, 4:46pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/3 "2026-02-05T16:46:41Z")

</div>

I am using Last 5 minutes.  
There are no results for the agent when the process is not running, results come back once I re-enable the process.  
I enabled the option “Alert me if there's no data” and that will trigger the alert in Elastic.  
Is that a good approach?

---

<div class="post-metadata">

**Author:** ![fer.mt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fer.mt/32/145089_2.png) [@fer.mt](https://discuss.elastic.co/u/fer.mt)\
**Post date:** [February 5, 2026, 5:20pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/4 "2026-02-05T17:20:36Z")

</div>

Update: My approach worked when there is one single agent in the Fleet policy, once I added a second one the alert rule doesn’t trigger. Even though I group by host.name the alerts.  
I think it is not working because while the process is not running on one of the hosts it is running on the other and the query is indeed returning results.

Is there any approach to this?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [February 6, 2026, 5:27pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/5 "2026-02-06T17:27:12Z")

</div>

Hello @fer.mt

It seems the alert does not trigger as there are no records to group by , if the record exists & condition meets than it uses group by so say the usecase will be hostname is sending up/down messages & if down, group by hostname in this scenario it will create trigger for different hostnames. In your case since the record is not received say for 4/5 hostname it will not be able to throw alert for 4 hostnames.

> **[Create a custom threshold rule | Elastic Docs](https://www.elastic.co/docs/solutions/observability/incident-management/create-custom-threshold-rule)**
>
> Create a custom threshold rule to trigger an alert when an Elastic Observability Serverless data type reaches or exceeds a given value. To access this...

One way is using Watcher similar usecase :

> [@Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574/2):
>
> Hello @Joey_Visbeen We can use the chain input job without transform , the action part needs to be updated as per your requirement along with the time range as it was used as 5h incase below code is as per the requirement (script part generated using LLM) - { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": [ { "first": { "search": { "request": { "search\_type": "query\_th…

You will have to add all the hostnames in an array for which you expect a record [] & if count is 0 for any of the host it will add that in the list for missing hostnames.

Example in case of kibana data : kibana\_sample\_data\_ecommerce

Output when it checks for last 15 minutes record received has count \< 1 group by Gender :

```auto
   "missing_gender": [
              "FEMALE"
            ],
            "seen_gender": [
              "MALE"
            ]
          }

```

Thanks!!
