# Creating Alert for Disk Space Usage

**URL:** <https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 8, 2018, 2:17pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474 "2018-10-08T14:17:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![johncam](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@johncam](https://discuss.elastic.co/u/johncam)\
**Post date:** [October 8, 2018, 2:17pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/1 "2018-10-08T14:17:45Z")

</div>

I'm trying to create an alert that is triggered when usage for any mount point on any server is in excess of 80%.

When creating a threshold alert under Watcher, I'm looking at getting the average of system.filesystem.used.pct and group this by both terms and system.filesystem.mount\_point (which does not appear to be present in the drop-down menus at all). However, it does not appear that I can enter this type of contruct in the GUI.

Does this sort of query need to be configured via JSON directly or am I missing a trick here? If it must be in JSON, could anybody offer any examples?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 9, 2018, 1:40pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/2 "2018-10-09T13:40:37Z")

</div>

Take a look at the [sample watches](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches), there is a filesystem usage example as well, where you can draw some good inspiration from.

--Alex

---

<div class="post-metadata">

**Author:** ![johncam](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@johncam](https://discuss.elastic.co/u/johncam)\
**Post date:** [October 10, 2018, 9:41am UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/3 "2018-10-10T09:41:16Z")

</div>

Thanks Alex

The problem I have with these examples is that they display filesystem usage as a total of all volumes rather than single volumes (i.e. 80% on Disk C on Host A).

It seems like I am missing fields such as mount point or device to present the granularity I want?

Will spend some more time playing with this today and see where I get.

-- JC

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 10, 2018, 10:09am UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/4 "2018-10-10T10:09:03Z")

</div>

you can have the granularity per host per mount point by using `terms` aggregations that split per host and then per mountpoint. This information exists as part of the metricbeat data.

--Alex

---

<div class="post-metadata">

**Author:** ![johncam](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@johncam](https://discuss.elastic.co/u/johncam)\
**Post date:** [October 10, 2018, 11:40am UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/5 "2018-10-10T11:40:47Z")

</div>

that is exactly what I did for the visualisations and it worked like a charm, but the same fields are not present when I try to create a new threshold alert using the GUI. This is why I am guessing that everything needs to be written in raw JSON?

--JC

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 10, 2018, 12:45pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/6 "2018-10-10T12:45:13Z")

</div>

I think writing a raw watch outside of the threshold UI might be easier, as you need more than one layer of aggregations - I am not sure this works with the threshold UI (my UI skills are limited though).

--Alex

---

<div class="post-metadata">

**Author:** ![johncam](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@johncam](https://discuss.elastic.co/u/johncam)\
**Post date:** [October 10, 2018, 3:51pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/7 "2018-10-10T15:51:10Z")

</div>

Thanks Alex

I'm looking at an alternative approach - using perfmon counters via the windows module in Metricbeat. I believe I have the syntax correct (?) for querying the LogicalDisk:%FreeSpace counter, but there's still no evidence of it in being available in the indexes. I've added the following to metricbeat.yml as a test:

-module: windows  
metricsets: [perfmon]  
period: 60s  
perfmon.ignore\_non\_existent\_counters: true  
perfmon.counters:  
-instance\_label: logicaldisk(_).free\_space  
measurement\_label: logicaldisk.total.free\_space  
query: '\LogicalDisk(_)% Free Space'  
format: "float"

Am I missing something here?

--JC

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2018, 4:01pm UTC](https://discuss.elastic.co/t/creating-alert-for-disk-space-usage/151474/8 "2018-11-07T16:01:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
