# Watcher repository by metricbeat module (kubernetes, system)

**URL:** <https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 23, 2019, 6:52pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736 "2019-09-23T18:52:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [September 23, 2019, 6:52pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736/1 "2019-09-23T18:52:31Z")

</div>

Hi,

What do people here think of creating a repository to store default (or example) [Watcher](https://www.elastic.co/guide/en/elastic-stack-overview/current/watcher-getting-started.html) alerts for the kubernetes and/or system module? (I'm also in favor of other modules but we should pick somewhere to start).

My hunch is that _most_ teams would want a similar set of basic alerts, and that _most_ teams don't have the best coverage so far. Combining efforts would be very helpful.

Best,  
Justin

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [September 23, 2019, 8:02pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736/2 "2019-09-23T20:02:12Z")

</div>

Hello,

There are some sample watches in this repository:

> **[elastic/examples](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches)**
>
> Home for Elasticsearch examples available to everyone. It's a great way to get started. - elastic/examples

If none of the samples is what you're looking for, perhaps we can include some additional sample watches.

Thanks.

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [September 23, 2019, 8:54pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736/3 "2019-09-23T20:54:40Z")

</div>

Hi @Michael_Madden, thanks for the reply.

I've seen this repo. I guess to be more specific, I'm suggesting we create a full suite of alerts that teams can apply to get a base level of monitoring for each host running metricbeat.

Alarms for CPU, memory, filesystem (system module). Then things like pending pods, pods in a crash loop, pods using more resources than requested (kubernetes module).

Ideally one would just run `make apply` and we'd http PUT each watch.json to the cluster.

[kube-prometheus](https://github.com/coreos/kube-prometheus) does something very similar for the prometheus/grafana stack.

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [October 8, 2019, 10:03pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736/4 "2019-10-08T22:03:22Z")

</div>

Just to follow up here... does that sound reasonable?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2019, 10:03pm UTC](https://discuss.elastic.co/t/watcher-repository-by-metricbeat-module-kubernetes-system/200736/5 "2019-11-05T22:03:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
