# Alert on repeated ping failures

**URL:** <https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [July 6, 2018, 9:13pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981 "2018-07-06T21:13:55Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 6, 2018, 9:13pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/1 "2018-07-06T21:13:55Z")

</div>

I'd like to set up:

1. a dashboard showing the ping status of a number of systems (perhaps a table of system names and their status)
2. alerts indicating when systems have stopped responding to the last X ping attempts.

I currently have Heartbeat pinging a number of systems and am getting an index with @timestamp, but it's not clear to me how to set up the alerts or dashboard from there. Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 8, 2018, 1:02pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/2 "2018-07-08T13:02:46Z")

</div>

You can build your own dashboards in Kibana. I would start with the [Time Series Visual Builder](https://www.elastic.co/guide/en/kibana/current/time-series-visual-builder.html) if I were creating a new visualization.

This is one that I use with Heartbeat.

 ![heartbeat-icmp](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e04368fae1bf5163145884dcacf8b06500b07e1.png)

Then for Altering I use [Watcher](https://www.elastic.co/products/x-pack/alerting) which is part of X-Pack. This will create a watch that queries the data every 60s and looks for hosts that were down and sends me a Slack notification.

```auto
PUT _xpack/watcher/watch/heartbeat-monitor-status-down
{
    "trigger": {
      "schedule": {
        "interval": "1m"
      }
    },
    "input": {
      "search": {
        "request": {
          "search_type": "query_then_fetch",
          "indices": [
            "heartbeat-*"
          ],
          "types": [],
          "body": {
            "size": 0,
            "query": {
              "bool": {
                "must": [
                  {
                    "term": {
                      "monitor.status": {
                        "value": "down"
                      }
                    }
                  }
                ],
                "filter": [
                  {
                    "range": {
                      "@timestamp": {
                        "from": "now-1m"
                      }
                    }
                  }
                ]
              }
            },
            "aggregations": {
              "by_monitors": {
                "terms": {
                  "field": "monitor.id",
                  "size": 10,
                  "min_doc_count": 1
                }
              }
            }
          }
        }
      }
    },
    "condition": {
      "compare": {
        "ctx.payload.hits.total": {
          "gt": 0
        }
      }
    },
    "actions": {
      "notify-slack": {
        "throttle_period_in_millis": 900000,
        "slack": {
          "account": "monitoring",
          "message": {
            "from": "Heartbeat",
            "text": "Some hosts are unresponsive.",
            "dynamic_attachments": {
              "list_path": "ctx.payload.aggregations.by_monitors.buckets",
              "attachment_template": {
                "color": "warning",
                "title": "{{key}}",
                "text": "Total events: {{doc_count}}"
              }
            }
          }
        }
      }
    }
}

```

> <https://twitter.com/Krohbird/status/849749788920877056>

---

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 9, 2018, 5:26pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/3 "2018-07-09T17:26:31Z")

</div>

@andrewkroh, thanks for your reply. I'm not sure how to re-create your dashboard, though:

For the ICMP RTT Times time series visual builder what are you specifying for the aggregation and grouping?

For the up and down count, I guess these are Data \> Metric visualizations, but what do you specify for the metrics/buckets?

For the alert, where does that definition go? Can I enter that in through the Kibana interface?

---

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 9, 2018, 5:39pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/4 "2018-07-09T17:39:27Z")

</div>

I guess under New Watch I should choose Advanced Watch vs. Threshold Alert to be able to enter the JSON definition.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 11, 2018, 1:21pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/5 "2018-07-11T13:21:40Z")

</div>

> [@Rob2](#):
>
> For the ICMP RTT Times time series visual builder what are you specifying for the aggregation and grouping?

I built mine before TSVB existed so I used a Line Chart. But conceptually they will be the same. It's a metric agg on the max `icmp.rtt.us` value. And each line represents a single `monitor.ip` so group by that value.

The up/down metrics are unique counts of the `monitor.id` with a query of either `monitor.status:up` or `monitor.status:down`.

---

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 11, 2018, 4:51pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/6 "2018-07-11T16:51:01Z")

</div>

Ok, thanks.

I haven't managed to reproduce the line chart. On the Metrics Y-axis I have max [icmp.rtt.us](http://icmp.rtt.us). In the Buckets section I have X-Axis date histogram by @timestamp, 30m interval, and Split Series terms by monitor.host. I see some dots/circles but no lines.

 ![linechart](https://us1.discourse-cdn.com/elastic/original/3X/2/3/23e9427f3e8699817195efdc1be83f9d72dfe0cc.jpg)

For the up/down metrics I managed to get something approximately like what you have by using a metric of unique count of monitor.id with buckets split group by terms on monitor status. But otherwise I didn't see how/where to specify a query of either monitor.status:up or monitor.status:down ...

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 12, 2018, 3:06am UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/7 "2018-07-12T03:06:42Z")

</div>

![31%20AM](https://us1.discourse-cdn.com/elastic/original/3X/1/6/1666d4242ee0f88fff6d99cfee183f33bde00f17.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 12, 2018, 3:08am UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/8 "2018-07-12T03:08:34Z")

</div>

> [@Rob2](#):
>
> But otherwise I didn't see how/where to specify a query of either monitor.status:up or monitor.status:down ...

`monitor.status: up` would go into the text box that says "Search...". This will filter things such that the aggregation only includes those that are up.

---

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 12, 2018, 6:07pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/9 "2018-07-12T18:07:33Z")

</div>

Thanks Andrew, your screenshot helped me reproduce the line chart.

For the up/down metric, I didn't see any text box that says "Search..." (there's "JSON Input", "Exclude", "Include") but I found under Buckets \> Split Group \> Aggregation \> Filters that I can filter for "monitor.status:down".

But it looks like for the up/down metric to be useful I would also need it to only count ping records that are from the last X minutes only, and it's not clear how to do that at the same time as having that filter.

 ![2018-07-12%2014_05_35-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/a/b/ab4c142054be0c85835edab4811075bc81635e71.jpg)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 12, 2018, 7:03pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/10 "2018-07-12T19:03:33Z")

</div>

> [@Rob2](#):
>
> I didn't see any text box that says "Search..."

It’s shown in the image you posted. It’s near the top. Right under “Visualize”.

---

<div class="post-metadata">

**Author:** ![Rob2](https://avatars.discourse-cdn.com/v4/letter/r/f9ae1b/32.png) [@Rob2](https://discuss.elastic.co/u/Rob2)\
**Post date:** [July 12, 2018, 7:14pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/11 "2018-07-12T19:14:19Z")

</div>

Ah, thanks Andrew! I didn't realize that that bar was part of the visualization definition ... I was only looking under Data and Options under the index pattern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 7:14pm UTC](https://discuss.elastic.co/t/alert-on-repeated-ping-failures/138981/12 "2018-08-09T19:14:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
