MYTHOSAI

Monitoring / PRACTICAL GUIDE

Design useful low-disk-space alerts in Zabbix

Check actual collection, combine practical thresholds and test delivery without filling a real drive.

Before you start

An existing Zabbix 7.0 host and Windows or Linux agent template; email delivery infrastructure already available.

Start with the real disk data

A low-space email is useful only if it describes the correct machine and volume. Confirm the filesystem has been discovered, the size and free-space items receive fresh values and the units are understood. A 5 GB warning and a 5 percent warning are different policies.

Review the template before adding duplicates

Windows and Linux templates commonly already include filesystem discovery and low-space triggers. Read the inherited item and trigger configuration before adding another rule. Duplicate rules create repeated notifications and make recovery messages confusing.

The vfs.fs.size key supports volume or filesystem size queries. Example keys for a Windows C: volume are:

text
vfs.fs.size[C:,free]
vfs.fs.size[C:,pfree]

Use the exact discovered filesystem identifier and supported item type for your agent and template. The first value is free bytes; the second is percentage free. Do not format bytes as gigabytes without the correct unit conversion.

Choose a defensible threshold

Consider capacity, normal growth and time needed to respond. Percentage thresholds help compare drives of different sizes; absolute thresholds protect small drives from having too little room even when a percentage looks tolerable. Some template policies combine conditions, so inspect the expression and macro descriptions before adjusting them.

Use a sustained evaluation window and a deliberate recovery condition to avoid flapping near the threshold. Exclude volumes intentionally outside scope through documented discovery filters, not by silencing every alert.

Configure notification flow

  1. Verify the email media type using your existing mail service's supported secure configuration.
  2. Add the intended recipient to the authorised Zabbix user/media record.
  3. Limit the action to the correct hosts or groups and relevant severity.
  4. Include host, volume, free capacity, timestamp and the expected response in the message. Avoid sensitive customer data.

SMTP credentials are secrets. An existing email account does not guarantee that its provider allows SMTP sending; follow its supported process rather than promising a universal free relay.

Test without exhausting storage

Use a test host or a temporarily reviewed threshold that creates a controlled problem. Verify the problem event, email, delivery log and recovery message. Restore the intended threshold afterwards. Never fill a production drive to trigger a demonstration.

Common mistakes

An action test alone does not prove the trigger works. Fresh disk data alone does not prove mail delivery. Check all stages and monitor failures so an undelivered email does not silently become your only warning.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.