elastalert
elastalert copied to clipboard
How do you make a rule that sends an alert when mount (e.g. "/software" ) does not exist on one of the nodes
I collect my data with metricbeat
''' system.filesystem.mount_point : /software '''