# Alerting on log data

**URL:** <https://discuss.elastic.co/t/alerting-on-log-data/242932>\
**Category:** Logs\
**Tags:** elastic-stack-alerting\
**Created:** [July 28, 2020, 4:06pm UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932 "2020-07-28T16:06:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanRoscigno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danroscigno/32/70277_2.png) [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Post date:** [July 28, 2020, 4:06pm UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932/1 "2020-07-28T16:06:47Z")

</div>

Here is some information that is in my logs:

 ![alerting-1](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba771779654750654aebea04c6ab24c8c1bdc1a4.png)

I would like to be able to create alerts any time a log entry includes the word ERROR, and the kubernetes.pod.name includes the string `redis-leader`. I have removed the match against ERROR in the log as this works fine, I am only having a problem matching on `redis-leader` within kubernetes.pod.name. I am using the log threshold alert type. Here are some things I tried:

This does not work:

```auto
WHEN more than or equals 1 log entry 
WITH kubernetes.pod.name IS redis-leader-*
FOR THE LAST 5 minutes

```

This works, but I have to add an alert for every pod, and if the app scales the new pods are unmonitored because the pod gets a fresh name:

```auto
WHEN more than or equals 1 log entry 
WITH kubernetes.pod.name IS redis-leader-74d59c4b7f-zxz81
FOR THE LAST 5 minutes

```

Should I be able to use wildcards? I tried a bunch of escaping and quoting, but never got there.

The next thing I would like to do is to add something like a group by, as an alert that tells me that there were five error messages for redis-leaders is less valuable that 3 separate alerts telling me that redis-leaders had messages containing errors. I cannot find a group by in the UI for log thresholds. It would be great if I could use the technique from [Create alert per multiple fields](https://discuss.elastic.co/t/create-alert-per-multiple-fields/242706/2)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [July 31, 2020, 9:10am UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932/2 "2020-07-31T09:10:44Z")

</div>

Hi @DanRoscigno,

the ability to create [grouped alerts](https://github.com/elastic/kibana/pull/68250) will be included in the upcoming 7.9.0 release:

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/508aa93830e4a29f363b29eb273069ac65ec390e.png)

Wildcards are currently not supported in the field comparison operators. On analyzed fields the `matches` operator is available, which is uses the `match` Elasticsearch clause. Other operators will probably be added in the future.

For your use-case it sounds like you would be best served by using an `is` operator to filter by some keyword field that exactly identifies all redis leaders (e.g. the image name? or a tag/label?) in combination with a group by `kubernetes.pod.name`.

---

<div class="post-metadata">

**Author:** ![DanRoscigno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danroscigno/32/70277_2.png) [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Post date:** [July 31, 2020, 2:14pm UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932/3 "2020-07-31T14:14:18Z")

</div>

Thanks @weltenwort ! I spun up a 7.9 cluster and the group by is perfect. I definitely see a need for searching within keyword fields, and the upcoming wildcard fields. Should I put in an ER or is that already on the list?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 3, 2020, 10:10am UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932/4 "2020-08-03T10:10:59Z")

</div>

Glad it seems useful to you! I couldn't find anything that tracks the addition of such an operator on keyword fields, so an ER would definitely increase the chance that it'll be added. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2020, 10:11am UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932/5 "2020-08-31T10:11:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
