# Alerting based on the keyword in logs

**URL:** https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295
**Category:** Logs
**Tags:** elastic-stack-alerting
**Created:** [January 6, 2021, 8:24am UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295 "2021-01-06T08:24:41Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![v\_anil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/v_anil/32/79783_2.png) [@v\_anil](https://discuss.elastic.co/u/v_anil)
#### Post date: [January 6, 2021, 8:24am UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295/1 "2021-01-06T08:24:42Z")

</div>

Hi ,

Is there anyway we can configure an alert based on the keyword in the logs, and alert them if we found more than threshould.

for ex: If the logs contain "Exception or ERROR" more than 10 times in last 2 min , i want to send an alert with the pod name and the logs message.

Currently i am using kibana 6.8 , but yeah i know the current version is not supporting the alerts. I just wanted to make sure the above alert is possible to setup. If yes then i will upgrade the elasticsearch and kibana.

Can someone please suggest whether it is possible or not..? if yes is there any doc that i can follow..?

---

<div class="post-metadata">

### Author: ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)
#### Post date: [January 6, 2021, 9:36am UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295/2 "2021-01-06T09:36:05Z")

</div>

Hi,  
I think you can use the [Threshold rule](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#create-threshold-rule) for your scenario.

---

<div class="post-metadata">

### Author: ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)
#### Post date: [January 6, 2021, 10:35am UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295/3 "2021-01-06T10:35:26Z")

</div>

Hi,

If you were to upgrade you’d be able to use a [Log threshold](https://www.elastic.co/guide/en/observability/master/logs-threshold-alert.html) alert for this functionality.

---

<div class="post-metadata">

### Author: ![v\_anil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/v_anil/32/79783_2.png) [@v\_anil](https://discuss.elastic.co/u/v_anil)
#### Post date: [January 6, 2021, 5:16pm UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295/4 "2021-01-06T17:16:25Z")

</div>

@borna_talebi and @Kerry thanks for your valuable options.

[Log threshold](https://www.elastic.co/guide/en/observability/master/logs-threshold-alert.html) worked.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 3, 2021, 5:16pm UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295/5 "2021-02-03T17:16:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
