# Need help creating an alert for unexpected MongoDB database size changes

**URL:** <https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838>\
**Category:** Help\
**Tags:** cloud, configuration, installation, dashboards, agent, alerts, notifications, collectors, integrations\
**Created:** [November 21, 2025, 6:05pm UTC](https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838 "2025-11-21T18:05:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richard\_Barrantes](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/richard_barrantes/32/3814_2.png) [@Richard\_Barrantes](https://community.netdata.cloud/u/Richard_Barrantes)\
**Post date:** [November 21, 2025, 6:05pm UTC](https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838/1 "2025-11-21T18:05:49Z")

</div>

I would like assistance creating a Netdata alert to detect unexpected changes in MongoDB database size.  
I’m using the MongoDB collector, and my goal is to trigger an alert only when the database size presents sudden growth or shrink, not when it remains constant.  
The challenge is building a reliable alert condition that avoids false positives.

I expected to configure a chart-based alert that triggers only when the database size changes unexpectedly (for example, a sudden growth of several GB or an unexpected drop), and not raise alerts when the size remains stable.

---

<div class="post-metadata">

**Author:** ![kanelatechnical](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/kanelatechnical/32/4699_2.png) [@kanelatechnical](https://community.netdata.cloud/u/kanelatechnical)\
**Post date:** [November 24, 2025, 12:25pm UTC](https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838/2 "2025-11-24T12:25:52Z")

</div>

Hi there,

For your use case, the best starting point is a **rate-of-change alert**. Instead of watching the absolute size, it measures how fast the size is changing over time, so it naturally ignores databases whose size is stable.

### Basic Rate-of-Change Alert

Here’s an example configuration you can use as a starting point:

```auto
# Detect sudden database growth/shrinkage
template: mongodb_database_size_rate_change
      on: mongodb.database_data_size
   class: Utilization
    type: Database
component: MongoDB
  lookup: max -1s at -10m unaligned of data_size
    calc: abs(($this - $data_size) / 600)
   units: bytes/s
   every: 1m
    warn: $this > 10485760 # 10 MB/s growth rate
    crit: $this > 52428800 # 50 MB/s growth rate
   delay: down 15m multiplier 1.5 max 1h
 summary: MongoDB database ${label:database} size changing rapidly
    info: Database ${label:database} size is changing at ${this} bytes/sec (10-min window)
      to: dba

```

**How it works:**

- Compares the current database size to the size from 10 minutes ago

- Calculates the rate of change in bytes per second (how fast it’s growing or shrinking)

- Only triggers when the change rate exceeds the thresholds you set

- Uses `abs()` to catch both growth and shrinkage with a single rule

- Waits 15 minutes before clearing the alert to help prevent flapping

**How the calculation works:**

- `lookup: max -1s at -10m` retrieves the database size from 10 minutes ago

- This value is stored in `$this` (the result of the lookup)

- `$data_size` is the current database size (dimension auto-variable)

- Formula: `abs(($this - $data_size) / 600)`

- Division by 600 converts the change over 10 minutes (600 seconds) to bytes per second

- Result: absolute rate of change in bytes per second

**Variable mapping:**

- `$this` = database size from 10 minutes ago (result of lookup)

- `$data_size` = current database size (dimension variable)

- `$now` = current Unix timestamp (Netdata variable)

- `$after` = start timestamp of lookup window (Netdata variable)

### Threshold Guidance

The example thresholds above are intentionally conservative and need tuning for your environment:

**For reference:**

- 10 MB/s = 600 MB change over 10 minutes

- 50 MB/s = 3 GB change over 10 minutes

**Adjust based on your database size:**

- **Small databases (\< 10 GB):**

- **Medium databases (10-100 GB):**

- **Large databases (\> 100 GB):**

Set thresholds 50-100% above the maximum change rate you normally see during expected bulk operations.

## Implementation Steps

### Step 1: Enable Database-Level Metrics

Make sure your MongoDB collector is configured to collect database-level metrics, otherwise the `mongodb.database_data_size` chart won’t exist:

```auto
# /etc/netdata/go.d/mongodb.conf
jobs:
  - name: local
    uri: mongodb://netdata:password@localhost:27017
    databases:
      includes:
        - "* *" # Collect metrics for all databases

```

### Step 2: Create Alert Configuration

```auto
sudo /etc/netdata/edit-config health.d/mongodb.conf

```

Add the alert template with your chosen thresholds.

### Step 3: Reload Health Configuration

```auto
sudo netdatacli reload-health

```

### Step 4: Verify Alert is Active

After reloading, verify the alert loaded successfully:

1. **Check alert status via API:**

2. **Look for** `mongodb_database_size_rate_change` in the output

3. **Verify it shows** `"status": "CLEAR"` (not “DISABLED” or missing)

4. **View the chart with alert:**

5. **Check the alarms page:**

This configuration should give you reliable detection of unexpected database size changes. If you run into issues during implementation or need help tuning the thresholds after observing your workload patterns, just reply to this message.

---

<div class="post-metadata">

**Author:** ![Richard\_Barrantes](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/richard_barrantes/32/3814_2.png) [@Richard\_Barrantes](https://community.netdata.cloud/u/Richard_Barrantes)\
**Post date:** [November 24, 2025, 8:47pm UTC](https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838/3 "2025-11-24T20:47:37Z")

</div>

Hi @kanelatechnical,

Thanks for your help! I will test the suggested solution and share any results with the community.

Regards,

---

<div class="post-metadata">

**Author:** ![Richard\_Barrantes](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/richard_barrantes/32/3814_2.png) [@Richard\_Barrantes](https://community.netdata.cloud/u/Richard_Barrantes)\
**Post date:** [December 2, 2025, 6:41pm UTC](https://community.netdata.cloud/t/need-help-creating-an-alert-for-unexpected-mongodb-database-size-changes/7838/4 "2025-12-02T18:41:47Z")

</div>

Hello!

The solution you provided worked perfectly, but now we have another challenge and it would be great if you could help us.  
We want to monitor the average data-size change rate over the last 24 hours, compare it with the current rate, and trigger an alert if the current rate exceeds the previously calculated average by X%.

We will remain attentive to your comments.

Regards,
