# ElasticCloud - alert on disk usage using metricbeats

**URL:** <https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663>\
**Category:** Kibana\
**Tags:** runtime-fields\
**Created:** [May 13, 2022, 9:58am UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663 "2022-05-13T09:58:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas\_Masquelier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_masquelier/32/105641_2.png) [@Thomas\_Masquelier](https://discuss.elastic.co/u/Thomas_Masquelier)\
**Post date:** [May 13, 2022, 9:58am UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/1 "2022-05-13T09:58:49Z")

</div>

I'm struggling to understand how to define an alert for my hosts disk usage in elastic cloud.  
The agent is installed on my different hosts with the "system" integration. Pretty sure this use metricbeats.

I can see this vizualisation here :

 ![EQgzk](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb7279bc82821a6818f8c835e4d9cb7ee2a8cd82.png)

However the disk usage use a couple of field to get it's percentage :

- system.fsstat.total\_size.total
- system.fsstat.total\_size.used

When I review that part of the dashboard I end up with this :

```auto
    {
      "size": 0,
      "query": {
        "bool": {
          "must": [
            {
              "range": {
                "@timestamp": {
                  "gte": "2022-05-12T08:47:46.895Z",
                  "lte": "2022-05-12T08:57:46.895Z",
                  "format": "strict_date_optional_time"
                }
              }
            },
            {
              "bool": {
                "must": [],
                "filter": [
                  {
                    "bool": {
                      "should": [
                        {
                          "match_phrase": {
                            "data_stream.dataset": "system.fsstat"
                          }
                        }
                      ],
                      "minimum_should_match": 1
                    }
                  }
                ],
                "should": [],
                "must_not": []
              }
            }
          ],
          "filter": [],
          "should": [],
          "must_not": []
        }
      },
      "aggs": {
        "timeseries": {
          "auto_date_histogram": {
            "field": "@timestamp",
            "buckets": 1
          },
          "aggs": {
            "4e4dee91-4d1d-11e7-b5f2-2b7c1895bf32": {
              "filter": {
                "exists": {
                  "field": "system.fsstat.total_size.used"
                }
              },
              "aggs": {
                "docs": {
                  "top_hits": {
                    "size": 1,
                    "fields": [
                      "system.fsstat.total_size.used"
                    ],
                    "sort": [
                      {
                        "@timestamp": {
                          "order": "desc"
                        }
                      }
                    ]
                  }
                }
              }
            },
            "57c96ee0-4d54-11e7-b5f2-2b7c1895bf32": {
              "filter": {
                "exists": {
                  "field": "system.fsstat.total_size.total"
                }
              },
              "aggs": {
                "docs": {
                  "top_hits": {
                    "size": 1,
                    "fields": [
                      "system.fsstat.total_size.total"
                    ],
                    "sort": [
                      {
                        "@timestamp": {
                          "order": "desc"
                        }
                      }
                    ]
                  }
                }
              }
            }
          },
          "meta": {
            "timeField": "@timestamp",
            "panelId": "4e4dc780-4d1d-11e7-b5f2-2b7c1895bf32",
            "seriesId": "4e4dee90-4d1d-11e7-b5f2-2b7c1895bf32",
            "intervalString": "600000ms",
            "indexPatternString": "metrics-*",
            "normalized": true
          }
        }
      },
      "runtime_mappings": {}
    }

```

I want to create a threshold alert when the disk of any of my host reach, let's say 90%.  
Threshold alert only takes one value, so I'm not able to create this alert.  
Shoud I create a new field somewhere in metricbeats index or should I use a custom query alert ?

I'm quite new to ElasticCloud, I found a couple of solution using Python script etc but that seems a bit overkill for what I'm trying to achieve.

Hopefully someone will have a simple solution.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 14, 2022, 10:04pm UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/2 "2022-05-14T22:04:16Z")

</div>

Hi @Thomas_Masquelier welcome to the community and thanks for trying Elastic Cloud.

Did you see this?

> **[Get notified about deployment health issues | Elasticsearch Service...](https://www.elastic.co/guide/en/cloud/current/ec-cluster-health-notifications.html)**

If you enable monitoring, these kind of alerts are out of the box.

---

<div class="post-metadata">

**Author:** ![Thomas\_Masquelier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_masquelier/32/105641_2.png) [@Thomas\_Masquelier](https://discuss.elastic.co/u/Thomas_Masquelier)\
**Post date:** [May 16, 2022, 8:31am UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/3 "2022-05-16T08:31:14Z")

</div>

Thanks for your reply.  
However I'm not talking about monitoring my elastic deployment but I want to enable alerts for agents that are enrolled with my stack (VM's i'm monitoring with the "system" integration)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 16, 2022, 2:57pm UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/4 "2022-05-16T14:57:52Z")

</div>

Apologies I was a bit confused... well then lets take a look

Here are the docs I would take a look at

> **[Create a metrics threshold rule | Observability Guide \[8.2\] | Elastic](https://www.elastic.co/guide/en/observability/current/metrics-threshold-alert.html)**

First do you hosts that you are monitoring show up in the Metrics App

 ![Screen Shot 2022-05-16 at 7.47.12 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d24c034a8e926d7aa8a9fd7124526eb6ce0782cf.png)

 ![Screen Shot 2022-05-16 at 7.51.23 AM](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa494fbc053c815f5cac8426cb6952da5b72b40d.png)

Create A rule Note you can even create a Critical and Warning Levels

 ![Screen Shot 2022-05-16 at 7.52.04 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a814ad7ef23ff10830fcb5253b8d7faa5aa7d80e.png)

You will probably want to group by `host.name` so the alert is created by each host, and suppose you only wanted this to run against a certain subset of hosts you can provide a KQL filter

 ![Screen Shot 2022-05-16 at 7.53.13 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/9/3912bddb330291f65a9ad5f4838df5df39cc1a1e.png)

Then Create an Action

 ![Screen Shot 2022-05-16 at 7.57.07 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aebe4341a3c263b4270e6e64cb641c8d70b85f3d.png)

Hope This Helps

---

<div class="post-metadata">

**Author:** ![Thomas\_Masquelier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_masquelier/32/105641_2.png) [@Thomas\_Masquelier](https://discuss.elastic.co/u/Thomas_Masquelier)\
**Post date:** [May 19, 2022, 1:12pm UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/5 "2022-05-19T13:12:51Z")

</div>

Awesome,  
I understood the way alerting was working however I didn't know the filed \*.pct was actually a percentage already.

I tought I would need to create a field.

Thank you so much, this issue is now resolved 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2022, 1:13pm UTC](https://discuss.elastic.co/t/elasticcloud-alert-on-disk-usage-using-metricbeats/304663/6 "2022-06-16T13:13:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
