# Alerting in Filebeat?

**URL:** <https://discuss.elastic.co/t/alerting-in-filebeat/203291>\
**Category:** Beats\
**Tags:** elastic-stack-alerting, filebeat\
**Created:** [October 11, 2019, 9:17pm UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291 "2019-10-11T21:17:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![neilp](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@neilp](https://discuss.elastic.co/u/neilp)\
**Post date:** [October 11, 2019, 9:17pm UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291/1 "2019-10-11T21:17:59Z")

</div>

Hi everyone,

I was wondering if there is a configuration option in Filebeat to do alerting when it is about to send a log over to logstash?

Thanks,  
Neil

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 14, 2019, 10:07am UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291/2 "2019-10-14T10:07:32Z")

</div>

Hey,

can you clarify what you would like to do trigger with this alert? If this is about triggering based on data being read, than the regular alerting feature looks like what you need. See [https://www.elastic.co/what-is/elasticsearch-alerting](https://www.elastic.co/what-is/elasticsearch-alerting) and [https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-getting-started.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-getting-started.html)

--Alex

---

<div class="post-metadata">

**Author:** ![neilp](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@neilp](https://discuss.elastic.co/u/neilp)\
**Post date:** [October 14, 2019, 6:24pm UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291/3 "2019-10-14T18:24:48Z")

</div>

Hi Alex,

I have made the following change filebeat.yml:  
"include\_lines: ['WARNING']".

And the goal was to alert an when filebeat finds a log containing this error and not have to specify an index, source or regex again etc.

Could I send the logs from this specific filebeat instance to a new index and make watcher alerts to watch only that index?

Thanks  
Neil

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2019, 6:24pm UTC](https://discuss.elastic.co/t/alerting-in-filebeat/203291/4 "2019-11-11T18:24:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
