Ability to alert when no data is being recieved


In Watcher is it possible to create an alert that informs us when there is no data being collected regardless is logstash is running or not

Are you looking for something similar to what is described in this example?

That looks like something we would require. Is there any guides to implement this?

I think taking a look at that watch is the best you can do it from a concrete use-case point of view.

In order to get a first feel on how to write and debug watches and shorten the feedback loop until you know what the watch is doing, I'd recommend this blogpost Watching the watches. This should help you a bit to get going.

If you get stuck, feel free to ask all the questions!


Thank you for the information. I will review the blog. We are currently on a free licence. Is there anything available to us that will allow us to be notified when the host/system fails to provide logs without the need to upgrade to a paid version?

you might want to check out our Elastic Cloud, which includes Alerting & Security and does not require you to get a subscription, if you try to prevent that.


