# Alerting thru Logstash

**URL:** https://discuss.elastic.co/t/alerting-thru-logstash/218266
**Category:** Logstash
**Created:** [February 7, 2020, 2:43am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266 "2020-02-07T02:43:12Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)
#### Post date: [February 7, 2020, 2:43am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/1 "2020-02-07T02:43:13Z")

</div>

Hi-  
I did installed metricbeats on a server, but for some reasons we stop the metricbeats service and start it back after some time. I would need an email alerting thru logstash only when its stopped and if the metricbeats starts again an email has to be sent again only once. Is there any plugin which does that? Or please let me know how do I build this using any other plugins?

Please see we can't have a logstash running on a prod server, we need to have the alerting thru executing the Elastic Search queries and identify whether the data collection have stopped/started.

Thanks!

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 7, 2020, 3:27am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/2 "2020-02-07T03:27:14Z")

</div>

Hi @paul1243 - There is no "plugin" available out-of-the-box that could do that. However, you may want to explore designing a watch that would check the monitoring index for Metricbeat. This would require you to:

- [Enable monitoring](https://www.elastic.co/guide/en/beats/metricbeat/current/monitoring.html) for Metricbeat.
- Write a [watch](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-alerting.html) that periodically check the monitoring index for Metricbeat and send emails accordingly.

I hope that helps.

---

<div class="post-metadata">

### Author: ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)
#### Post date: [February 7, 2020, 4:21am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/3 "2020-02-07T04:21:46Z")

</div>

thanks for your reply @ropc  
unfortunately, we haven't got the x-pack license yet but we are planning very soon. I need to have a working solution until then 🙂 any other suggestions ? thanks !

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 7, 2020, 4:29am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/4 "2020-02-07T04:29:21Z")

</div>

@paul1243 - out of curiosity, what's your stack version?

---

<div class="post-metadata">

### Author: ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)
#### Post date: [February 7, 2020, 5:02am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/5 "2020-02-07T05:02:04Z")

</div>

@ropc - Its 6.8 - with open source basic security features installed.

---

<div class="post-metadata">

### Author: ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)
#### Post date: [February 7, 2020, 6:11am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/6 "2020-02-07T06:11:47Z")

</div>

@paul1243 To be honest, without Monitoring and Alerting, that will be a bit challenging to implement this. If you think about using the [email output plugin](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-email.html) from Logstash, then you would still need an input to act on. Just a random thought, but you could probably write a simple TCP client that monitors your Metricbeat instance and sends a message to Logstash (and use the [http input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html)).

Obviously this is more like an in-house implementation - the best would be to rely on the Monitoring and Alerting capabilities offered in the stack.

---

<div class="post-metadata">

### Author: ![paul1243](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@paul1243](https://discuss.elastic.co/u/paul1243)
#### Post date: [February 7, 2020, 6:19am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/7 "2020-02-07T06:19:21Z")

</div>

Okies @ropc , thanks for your inputs 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 6, 2020, 6:19am UTC](https://discuss.elastic.co/t/alerting-thru-logstash/218266/8 "2020-03-06T06:19:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
