# Alerting in ELK stack?

**URL:** <https://discuss.elastic.co/t/alerting-in-elk-stack/18258>\
**Category:** Elasticsearch\
**Created:** [June 23, 2014, 8:50am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258 "2014-06-23T08:50:22Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siddharth\_Trikha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddharth_trikha/32/133867_2.png) [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Post date:** [June 23, 2014, 8:50am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/1 "2014-06-23T08:50:22Z")

</div>

We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
our logs. So far, so good.

But now we want notification generation on some particular kind of logs. Eg  
When a login failed logs comes more than 5 times (threshold crossed) an  
email to be sent to the sysadmin.

I looked up online and heard about `statsd`, `riemann`, `nagios`, `metric`  
filter (logstash) to achieve our requirement.

Can anyone suggest which fits best with ELK stack?? I am new to this. Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/d8d3b4ef-b687-4e2c-bfe8-64519f9a456a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d8d3b4ef-b687-4e2c-bfe8-64519f9a456a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [June 23, 2014, 10:20am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/2 "2014-06-23T10:20:36Z")

</div>

The solutions I've seen for things like this in ELK usually are on the  
lines of using logstash to reparse the logs in ES and use some output  
(e-mail, nagios, Zabbix) to do the alerting.

For now I've stick with using OSSEC ([www.ossec.net](http://www.ossec.net)) to do my alerting and  
"just" use ELK for log analysis.

On Monday, June 23, 2014 5:50:22 AM UTC-3, Siddharth Trikha wrote:

> We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
> our logs. So far, so good.
> 
> But now we want notification generation on some particular kind of logs.  
> Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> email to be sent to the sysadmin.
> 
> I looked up online and heard about `statsd`, `riemann`, `nagios`, `metric`  
> filter (logstash) to achieve our requirement.
> 
> Can anyone suggest which fits best with ELK stack?? I am new to this.  
> Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/f05ec9c0-9c69-4b07-8f32-e3742fadb718%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/f05ec9c0-9c69-4b07-8f32-e3742fadb718%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Siddharth\_Trikha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddharth_trikha/32/133867_2.png) [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Post date:** [June 23, 2014, 10:49am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/3 "2014-06-23T10:49:03Z")

</div>

@Antonio: I use email output for a particular pattern in a log. But for  
example, when a particular logs comes more than 5 times, for alerting for  
this a state needs to be maintained which is not there in logstash.

I don't know about OSSEC. But how to use it to achieve the above? Presently  
logstash reads logs, ES stores it and kibana presents it. How OSSEC fits  
here?

On Monday, 23 June 2014 15:50:36 UTC+5:30, Antonio Augusto Santos wrote:

> The solutions I've seen for things like this in ELK usually are on the  
> lines of using logstash to reparse the logs in ES and use some output  
> (e-mail, nagios, Zabbix) to do the alerting.
> 
> For now I've stick with using OSSEC ([www.ossec.net](http://www.ossec.net)) to do my alerting and  
> "just" use ELK for log analysis.
> 
> On Monday, June 23, 2014 5:50:22 AM UTC-3, Siddharth Trikha wrote:
> 
> > We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
> > our logs. So far, so good.
> > 
> > But now we want notification generation on some particular kind of logs.  
> > Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> > email to be sent to the sysadmin.
> > 
> > I looked up online and heard about `statsd`, `riemann`, `nagios`,  
> > `metric` filter (logstash) to achieve our requirement.
> > 
> > Can anyone suggest which fits best with ELK stack?? I am new to this.  
> > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7ad5d8cf-41a8-4cbf-b4ba-90de0dba80c0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7ad5d8cf-41a8-4cbf-b4ba-90de0dba80c0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Klavs\_Klavsen](https://avatars.discourse-cdn.com/v4/letter/k/90db22/32.png) [@Klavs\_Klavsen](https://discuss.elastic.co/u/Klavs_Klavsen)\
**Post date:** [June 23, 2014, 11:11am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/4 "2014-06-23T11:11:00Z")

</div>

I haven't done it yet.. but my plan is to simply do REST searches.. and if  
I get a lot of alerts and want to check often.. I'd switch to setting up  
percolators.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/7ff6253e-698b-43e8-acda-1227a3b694f0%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/7ff6253e-698b-43e8-acda-1227a3b694f0%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [June 23, 2014, 11:25am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/5 "2014-06-23T11:25:53Z")

</div>

OSSEC is a HIDS (Host Intrusion Detection SYstem), its objective is to  
parse logs, check the logs against rules and send alerts. It has a vast  
amount of rules already defined, so when it starts checking your logs it  
will start firing alerts.

In my architecture OSSEC fits outside the ELK stack. It parses the logs (as  
Logstash) but write alerts to files and send alerts by email.  
I've another logstash instance that reads the alerts from OSSEC, so I can  
have a nice Dashboard for them on Kibana.

On Monday, June 23, 2014 7:49:03 AM UTC-3, Siddharth Trikha wrote:

> @Antonio: I use email output for a particular pattern in a log. But for  
> example, when a particular logs comes more than 5 times, for alerting for  
> this a state needs to be maintained which is not there in logstash.
> 
> I don't know about OSSEC. But how to use it to achieve the above?  
> Presently logstash reads logs, ES stores it and kibana presents it. How  
> OSSEC fits here?
> 
> On Monday, 23 June 2014 15:50:36 UTC+5:30, Antonio Augusto Santos wrote:
> 
> > The solutions I've seen for things like this in ELK usually are on the  
> > lines of using logstash to reparse the logs in ES and use some output  
> > (e-mail, nagios, Zabbix) to do the alerting.
> > 
> > For now I've stick with using OSSEC ([www.ossec.net](http://www.ossec.net)) to do my alerting  
> > and "just" use ELK for log analysis.
> > 
> > On Monday, June 23, 2014 5:50:22 AM UTC-3, Siddharth Trikha wrote:
> > 
> > > We are using the `ELK stack (logstash, elasticsearch, kibana)` to  
> > > analyze our logs. So far, so good.
> > > 
> > > But now we want notification generation on some particular kind of logs.  
> > > Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> > > email to be sent to the sysadmin.
> > > 
> > > I looked up online and heard about `statsd`, `riemann`, `nagios`,  
> > > `metric` filter (logstash) to achieve our requirement.
> > > 
> > > Can anyone suggest which fits best with ELK stack?? I am new to this.  
> > > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ba8d6ae3-4652-4618-b5a0-45fddeb313cd%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ba8d6ae3-4652-4618-b5a0-45fddeb313cd%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Siddharth\_Trikha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddharth_trikha/32/133867_2.png) [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Post date:** [June 23, 2014, 11:42am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/6 "2014-06-23T11:42:46Z")

</div>

So inputing log files to logstash-parse-store-view them and separately  
doing this for alerts:ossec-parse-alert, will this not create redudancy??

Does OSSEC has rules for threshold crossing?? Any suggestions which fits my  
scenario best?

On Monday, 23 June 2014 16:55:54 UTC+5:30, Antonio Augusto Santos wrote:

> OSSEC is a HIDS (Host Intrusion Detection SYstem), its objective is to  
> parse logs, check the logs against rules and send alerts. It has a vast  
> amount of rules already defined, so when it starts checking your logs it  
> will start firing alerts.
> 
> In my architecture OSSEC fits outside the ELK stack. It parses the logs  
> (as Logstash) but write alerts to files and send alerts by email.  
> I've another logstash instance that reads the alerts from OSSEC, so I can  
> have a nice Dashboard for them on Kibana.
> 
> On Monday, June 23, 2014 7:49:03 AM UTC-3, Siddharth Trikha wrote:
> 
> > @Antonio: I use email output for a particular pattern in a log. But for  
> > example, when a particular logs comes more than 5 times, for alerting for  
> > this a state needs to be maintained which is not there in logstash.
> > 
> > I don't know about OSSEC. But how to use it to achieve the above?  
> > Presently logstash reads logs, ES stores it and kibana presents it. How  
> > OSSEC fits here?
> > 
> > On Monday, 23 June 2014 15:50:36 UTC+5:30, Antonio Augusto Santos wrote:
> > 
> > > The solutions I've seen for things like this in ELK usually are on the  
> > > lines of using logstash to reparse the logs in ES and use some output  
> > > (e-mail, nagios, Zabbix) to do the alerting.
> > > 
> > > For now I've stick with using OSSEC ([www.ossec.net](http://www.ossec.net)) to do my alerting  
> > > and "just" use ELK for log analysis.
> > > 
> > > On Monday, June 23, 2014 5:50:22 AM UTC-3, Siddharth Trikha wrote:
> > > 
> > > > We are using the `ELK stack (logstash, elasticsearch, kibana)` to  
> > > > analyze our logs. So far, so good.
> > > > 
> > > > But now we want notification generation on some particular kind of  
> > > > logs. Eg When a login failed logs comes more than 5 times (threshold  
> > > > crossed) an email to be sent to the sysadmin.
> > > > 
> > > > I looked up online and heard about `statsd`, `riemann`, `nagios`,  
> > > > `metric` filter (logstash) to achieve our requirement.
> > > > 
> > > > Can anyone suggest which fits best with ELK stack?? I am new to this.  
> > > > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b88ce0be-0a32-4bee-8d68-6d1ea324aa5e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b88ce0be-0a32-4bee-8d68-6d1ea324aa5e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [June 23, 2014, 1:12pm UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/7 "2014-06-23T13:12:37Z")

</div>

Yes, it adds redundancy, but, for now, I think its the best option.

OSSEC has a very flexible analysing system, and it should fit your needs  
without much trouble.

On Monday, June 23, 2014 8:42:46 AM UTC-3, Siddharth Trikha wrote:

> So inputing log files to logstash-parse-store-view them and separately  
> doing this for alerts:ossec-parse-alert, will this not create redudancy??
> 
> Does OSSEC has rules for threshold crossing?? Any suggestions which fits  
> my scenario best?
> 
> On Monday, 23 June 2014 16:55:54 UTC+5:30, Antonio Augusto Santos wrote:
> 
> > OSSEC is a HIDS (Host Intrusion Detection SYstem), its objective is to  
> > parse logs, check the logs against rules and send alerts. It has a vast  
> > amount of rules already defined, so when it starts checking your logs it  
> > will start firing alerts.
> > 
> > In my architecture OSSEC fits outside the ELK stack. It parses the logs  
> > (as Logstash) but write alerts to files and send alerts by email.  
> > I've another logstash instance that reads the alerts from OSSEC, so I can  
> > have a nice Dashboard for them on Kibana.
> > 
> > On Monday, June 23, 2014 7:49:03 AM UTC-3, Siddharth Trikha wrote:
> > 
> > > @Antonio: I use email output for a particular pattern in a log. But for  
> > > example, when a particular logs comes more than 5 times, for alerting for  
> > > this a state needs to be maintained which is not there in logstash.
> > > 
> > > I don't know about OSSEC. But how to use it to achieve the above?  
> > > Presently logstash reads logs, ES stores it and kibana presents it. How  
> > > OSSEC fits here?
> > > 
> > > On Monday, 23 June 2014 15:50:36 UTC+5:30, Antonio Augusto Santos wrote:
> > > 
> > > > The solutions I've seen for things like this in ELK usually are on the  
> > > > lines of using logstash to reparse the logs in ES and use some output  
> > > > (e-mail, nagios, Zabbix) to do the alerting.
> > > > 
> > > > For now I've stick with using OSSEC ([www.ossec.net](http://www.ossec.net)) to do my alerting  
> > > > and "just" use ELK for log analysis.
> > > > 
> > > > On Monday, June 23, 2014 5:50:22 AM UTC-3, Siddharth Trikha wrote:
> > > > 
> > > > > We are using the `ELK stack (logstash, elasticsearch, kibana)` to  
> > > > > analyze our logs. So far, so good.
> > > > > 
> > > > > But now we want notification generation on some particular kind of  
> > > > > logs. Eg When a login failed logs comes more than 5 times (threshold  
> > > > > crossed) an email to be sent to the sysadmin.
> > > > > 
> > > > > I looked up online and heard about `statsd`, `riemann`, `nagios`,  
> > > > > `metric` filter (logstash) to achieve our requirement.
> > > > > 
> > > > > Can anyone suggest which fits best with ELK stack?? I am new to this.  
> > > > > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/db98e711-254e-4a33-8592-c5277fc1a9fb%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/db98e711-254e-4a33-8592-c5277fc1a9fb%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Michael\_Hart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_hart/32/65937_2.png) [@Michael\_Hart](https://discuss.elastic.co/u/Michael_Hart)\
**Post date:** [June 25, 2014, 3:18pm UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/8 "2014-06-25T15:18:01Z")

</div>

We use Nagios for alerting. I originally was using the nsca output plugin  
for logstash, but found that it took close to a second to execute the  
command line nsca client, and if we got flooded with alert messages,  
logstash would fall behind. I've since switched to use the http output and  
send json to the nagios-api server ([GitHub - zorkian/nagios-api: A REST-like, JSON interface to Nagios](https://github.com/zorkian/nagios-api)).  
That seems to scale a lot better.

We do also have metrics sent from logstash to statsd/graphite, but mostly  
so I can see message rates.

mike

On Monday, June 23, 2014 4:50:22 AM UTC-4, Siddharth Trikha wrote:

> We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
> our logs. So far, so good.
> 
> But now we want notification generation on some particular kind of logs.  
> Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> email to be sent to the sysadmin.
> 
> I looked up online and heard about `statsd`, `riemann`, `nagios`, `metric`  
> filter (logstash) to achieve our requirement.
> 
> Can anyone suggest which fits best with ELK stack?? I am new to this.  
> Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/d609f39f-e452-44e8-a962-0e4b2a88e920%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d609f39f-e452-44e8-a962-0e4b2a88e920%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)\
**Post date:** [July 8, 2014, 5:12am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/9 "2014-07-08T05:12:30Z")

</div>

We have and use SPM [http://sematext.com/spm/](http://sematext.com/spm/) for all our metrics (ES,  
Kafka, Apache, MySQL, Hadoop, everything) and we feed our logs to Logsene  
[http://sematext.com/logsene/](http://sematext.com/logsene/) (it has a Kibana UI and a "native" UI). SPM  
has alerting and anomaly detection, so we use that to get out of bed early  
(nah, not really), but we currently lack alerting in Logsene (i.e. alerting  
on numerical data in logs or on patterns). Since Logsene has Kibana UI and  
can be fed via Logstash and has an Elasticsearch API and backend, that's  
the closest we've gotten to ELK+Alerts.

## Otis

Performance Monitoring \* Log Analytics \* Search Analytics  
Solr & Elasticsearch Support \* [http://sematext.com/](http://sematext.com/)

On Wednesday, June 25, 2014 11:18:01 AM UTC-4, Michael Hart wrote:

> We use Nagios for alerting. I originally was using the nsca output plugin  
> for logstash, but found that it took close to a second to execute the  
> command line nsca client, and if we got flooded with alert messages,  
> logstash would fall behind. I've since switched to use the http output and  
> send json to the nagios-api server ([GitHub - zorkian/nagios-api: A REST-like, JSON interface to Nagios](https://github.com/zorkian/nagios-api)).  
> That seems to scale a lot better.
> 
> We do also have metrics sent from logstash to statsd/graphite, but mostly  
> so I can see message rates.
> 
> mike
> 
> On Monday, June 23, 2014 4:50:22 AM UTC-4, Siddharth Trikha wrote:
> 
> > We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
> > our logs. So far, so good.
> > 
> > But now we want notification generation on some particular kind of logs.  
> > Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> > email to be sent to the sysadmin.
> > 
> > I looked up online and heard about `statsd`, `riemann`, `nagios`,  
> > `metric` filter (logstash) to achieve our requirement.
> > 
> > Can anyone suggest which fits best with ELK stack?? I am new to this.  
> > Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/71f99e2b-6557-4be4-a68d-2df08e53e595%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/71f99e2b-6557-4be4-a68d-2df08e53e595%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Scott\_Wilkerson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scott_wilkerson/32/1142_2.png) [@Scott\_Wilkerson](https://discuss.elastic.co/u/Scott_Wilkerson)\
**Post date:** [October 31, 2014, 8:36pm UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/10 "2014-10-31T20:36:22Z")

</div>

Nagios recently released a new Log Analysis  
[http://www.nagios.com/products/nagios-log-server](http://www.nagios.com/products/nagios-log-server) product called Nagios  
Log Server which is built using the ELK stack and provides alerting,  
authentication, GUI logstash configuration for the whole cluster and a ton  
more.

Alerts based on any query can be sent directly to Nagios, Email, SNMP  
traps, custom script execution and more...

Scott

On Monday, June 23, 2014 3:50:22 AM UTC-5, Siddharth Trikha wrote:

> We are using the `ELK stack (logstash, elasticsearch, kibana)` to analyze  
> our logs. So far, so good.
> 
> But now we want notification generation on some particular kind of logs.  
> Eg When a login failed logs comes more than 5 times (threshold crossed) an  
> email to be sent to the sysadmin.
> 
> I looked up online and heard about `statsd`, `riemann`, `nagios`, `metric`  
> filter (logstash) to achieve our requirement.
> 
> Can anyone suggest which fits best with ELK stack?? I am new to this.  
> Thanks

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/8e05f6ad-8277-4086-8f23-116e0f1698c6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/8e05f6ad-8277-4086-8f23-116e0f1698c6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:52am UTC](https://discuss.elastic.co/t/alerting-in-elk-stack/18258/11 "2017-07-06T00:52:45Z")

</div>


