# Alerting slack

**URL:** <https://discuss.elastic.co/t/alerting-slack/158582>\
**Category:** APM\
**Tags:** elastic-stack-alerting\
**Created:** [November 28, 2018, 2:01pm UTC](https://discuss.elastic.co/t/alerting-slack/158582 "2018-11-28T14:01:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tommy\_Cabrelli](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@Tommy\_Cabrelli](https://discuss.elastic.co/u/Tommy_Cabrelli)\
**Post date:** [November 28, 2018, 2:01pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/1 "2018-11-28T14:01:35Z")

</div>

Hello  
I do use APM to logs all my nodejs errors in ES/Kibana and it works pretty well.  
Is there a way to use a slack hook to notifiy for instance every errors which have status\_code = 500 ?  
I found a working slack logstash output [here](https://github.com/logstash-plugins/logstash-output-slack).  
The problem is that if I use logstash ouput, i can't use the elasticsearch one since APM provide only 1 output.  
Maybe there is a more appropriated tool ?

Thank you for your answers  
regards,

---

<div class="post-metadata">

**Author:** ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)\
**Post date:** [November 28, 2018, 2:59pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/2 "2018-11-28T14:59:54Z")

</div>

Hi Tommy,

You can receive alerts on Slack by setting up a watch straight from the APM ui. Go to your service -\> Click "Errors" tab -\> "Integrations" button -\> "Enable error reports".

You can now configure the watch to trigger for a specified interval. You cannot receive alerts in real-time but you can decrease the interval to your liking.

The created watch will not by default filter errors by status code, but you can manually edit the watch in Management -\> Watcher, and adding the following to the bool filter:

```auto
{
  "term": {
    "context.response.status_code": 500
  }
}

```

Let me know if you have any other questions.

---

<div class="post-metadata">

**Author:** ![Tommy\_Cabrelli](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@Tommy\_Cabrelli](https://discuss.elastic.co/u/Tommy_Cabrelli)\
**Post date:** [November 28, 2018, 4:11pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/3 "2018-11-28T16:11:16Z")

</div>

Hi sqren

Thank you for your answer.  
That looks great ! But I can't find any "Integrations" button in my "Errors" tab :

 ![Capture%20du%202018-11-28%2017%3A10%3A22](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a728ae7ec63a5c835dd28e1fc4dc393ca7f8d7d6.png)

I do have ElasticSearch 6.5.1, Kibana 6.5.1, APM Server 6.5.1

---

<div class="post-metadata">

**Author:** ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)\
**Post date:** [November 28, 2018, 4:40pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/4 "2018-11-28T16:40:01Z")

</div>

Apologies for the confusion. You need a Gold license to use Watcher: [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions).

---

<div class="post-metadata">

**Author:** ![Tommy\_Cabrelli](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@Tommy\_Cabrelli](https://discuss.elastic.co/u/Tommy_Cabrelli)\
**Post date:** [November 29, 2018, 4:59pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/5 "2018-11-29T16:59:32Z")

</div>

Thanks for your answer sqren.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2018, 12:59pm UTC](https://discuss.elastic.co/t/alerting-slack/158582/6 "2018-12-20T12:59:39Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
