Skip to content

System Alert

Server monitoring in Bash and systemd. Alerts land in Telegram, Discord or a webhook.

Free and MIT licensed, currently in alpha. No resident agent, no daemon and no SaaS account. One deploy command copies it to your server.

Copy
# set SSH_HOST_1, SSH_USER and REMOTE_DIR in .env
cp .env.example .env
./deploy.sh

Quiet by default, tunable when you care

CPU, RAM, disk, I/O wait and network alerts fire only after a breach lasts five minutes, so a short spike stays quiet. Each one sends a recovery message when it clears.

CPU threshold
80%
user plus system
RAM threshold
85%
percent used
Disk threshold
85%
checked per mount
Sustained before alerting
5 min
set by RESOURCE_SUSTAIN_MINUTES

Source: default values in .env.server.example. Every value is a plain variable you can change.

What you get

  • Resources

    CPU, RAM, every mounted disk, I/O wait (needs iostat) and network throughput on the default interface. tmpfs, udev and loop devices are skipped.

  • Services

    Watches the units in SERVICES_TO_MONITOR, or every enabled service minus a skip list. Down alerts are batched and include the recent journal lines.

  • SSH brute force and logins

    Counts failed sshd attempts over five minutes and alerts at 10 or more, listing the top 5 source IPs. A PAM hook alerts the moment someone logs in.

  • Log growth

    Flags files over 500 MB, or a directory over 2 GB, under LOG_DIRS (default /var/log), so a runaway log does not fill the disk unnoticed.

  • Telegram, Discord or a webhook

    One notifier script per channel. Telegram sends info and recovery messages silently, so only real problems make your phone buzz.

  • One command deploy

    deploy.sh copies the scripts and a generated config over SSH, installs missing curl, bc and sysstat, and sets up a systemd timer or cron.

Read the alert before you read the logs

Every alert names the host, the current value and the threshold. Service alerts add the latest journal lines, and brute force alerts list the source IPs.

Each alert is sent once per breach and tracked in state files, so a problem that lasts an hour does not send sixty messages.

The example on the right uses made-up values.

telegram alertCopy
🔴 *CPU Usage Alert*
🖥 `my-server`
CPU usage is critically high.
📊 Current: `92%` / Threshold: `80%`
📈 Load average: `1.2 1.0 0.9`
⏱ Sustained: `5 min`
🕐 `2026-01-01 12:00:00 UTC`

Deploying to a server

  1. Point it at your host. Copy .env.example to .env and set SSH_HOST_1, SSH_USER and REMOTE_DIR. The default remote directory is /etc/server-monitor.
  2. Preset your alerts, optionally. Copy .env.server.example to .env.server to set thresholds and channels ahead of time.
  3. Deploy. Run ./deploy.sh. It asks which monitors and channels to enable, then installs a systemd timer that runs every 60 seconds. Pass --cron if you prefer cron.
  4. Check it on the server. Run run-monitors.sh --list to see the monitors, or run-monitors.sh --force to run them now.

Good to know

  • It is in alpha, so expect rough edges and changes. Debian and Ubuntu are the tested targets, because the deploy script installs missing tools with apt-get.
  • The monitors need systemd and journalctl. The deploy needs SSH, rsync and sudo on the target.
  • The service runs as root, hardened with NoNewPrivileges, ProtectSystem=strict, ProtectHome and PrivateTmp. It can write only to /etc/server-monitor/state.

Questions

What is System Alert?
A set of Bash scripts that a systemd timer or cron job runs on your Linux server. They check resources, services, SSH activity and log sizes, then send alerts to Telegram, Discord or a generic webhook.
Does it install an agent?
No resident agent or daemon. A systemd oneshot unit fires every minute, runs the checks with tools already on the box (top, free, df, journalctl, curl) and exits.
Will a short CPU spike wake me up?
No. CPU, RAM, disk, I/O wait and network alerts fire only after the breach lasts five minutes, and each sends a recovery message when it ends. You can change the window.
Is it free?
Yes. It is MIT licensed and marked alpha, so check the alerts on a test server before you rely on them.
Which alert channels are supported?
Telegram, Discord and a generic webhook. Each has its own notifier script under scripts/notifiers/.

Deploy it to one test server

Issues and stars on GitHub help other people find it.