# Best approach to monitor a Linux Service with the Elastic Agent?

**URL:** <https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916>\
**Category:** Elastic Agent\
**Created:** [February 4, 2026, 6:05pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916 "2026-02-04T18:05:19Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [February 6, 2026, 5:27pm UTC](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916/5 "2026-02-06T17:27:12Z")

</div>

Hello @fer.mt

It seems the alert does not trigger as there are no records to group by , if the record exists & condition meets than it uses group by so say the usecase will be hostname is sending up/down messages & if down, group by hostname in this scenario it will create trigger for different hostnames. In your case since the record is not received say for 4/5 hostname it will not be able to throw alert for 4 hostnames.

> **[Create a custom threshold rule | Elastic Docs](https://www.elastic.co/docs/solutions/observability/incident-management/create-custom-threshold-rule)**
>
> Create a custom threshold rule to trigger an alert when an Elastic Observability Serverless data type reaches or exceeds a given value. To access this...

One way is using Watcher similar usecase :

> [@Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574/2):
>
> Hello @Joey_Visbeen We can use the chain input job without transform , the action part needs to be updated as per your requirement along with the time range as it was used as 5h incase below code is as per the requirement (script part generated using LLM) - { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": [ { "first": { "search": { "request": { "search\_type": "query\_th…

You will have to add all the hostnames in an array for which you expect a record [] & if count is 0 for any of the host it will add that in the list for missing hostnames.

Example in case of kibana data : kibana\_sample\_data\_ecommerce

Output when it checks for last 15 minutes record received has count \< 1 group by Gender :

```auto
   "missing_gender": [
              "FEMALE"
            ],
            "seen_gender": [
              "MALE"
            ]
          }

```

Thanks!!

---

_[View the full topic](https://discuss.elastic.co/t/best-approach-to-monitor-a-linux-service-with-the-elastic-agent/384916)._
