# Alerting on no log entires

**URL:** <https://discuss.elastic.co/t/alerting-on-no-log-entires/216955>\
**Category:** Logstash\
**Created:** [January 29, 2020, 8:07am UTC](https://discuss.elastic.co/t/alerting-on-no-log-entires/216955 "2020-01-29T08:07:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RichardH](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Post date:** [January 29, 2020, 8:07am UTC](https://discuss.elastic.co/t/alerting-on-no-log-entires/216955/1 "2020-01-29T08:07:27Z")

</div>

Hi All,

I am putting this under Logstash as I am reasonably sure (but not totally sure) I will need Logstash to achieve this.

We have around 170 servers all running the same application. On each of these servers there are about 5 log files we need to monitor. We need to trigger an alert if any \*\*ONE \*\*of these log files stops receiving data for a period of time (say 1 minute for example) as this indicates the application has failed.

I can get Filebeat running on them to monitor the files and send to Elasticsearch, but I can't get my head around what to do next (I'm a server and infrastructure guy not a developer :-))

I am thinking I will have to send logs to Logstash instead of ES, then use a pipeline to write each hostname/logfile combination to it's own index in ES and from there look at a watcher (or ML Job?) to alert if the number of lines in the file hasn't changed over an interval.

Any suggestions?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 29, 2020, 3:06pm UTC](https://discuss.elastic.co/t/alerting-on-no-log-entires/216955/2 "2020-01-29T15:06:26Z")

</div>

I think you can have filebeat write directly to elasticsearch. Use ML to monitor the number of lines for each hostname/logfile and generate alerts based on that.

It's been a while since I ran es/ML so I cannot provide detail.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2020, 3:06pm UTC](https://discuss.elastic.co/t/alerting-on-no-log-entires/216955/3 "2020-02-26T15:06:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
