I checked the link and now I am aware that the basic license offers some alerting features. Can you please tell me if I those relay on X-Pack (do I need to enable it?) or provide a link to a good tutorial so I can configure and start using it.
I have been checking the documentation related to alerting, but it is still not clear to me what types alerts I can access with just the Basic License. Watcher is not available.
Alerts about the operation or performance of the node?
Alerts if the service is interrupted?
Custom alerts given a specific event?
Is there a list of alerts I can check to see if those I am looking for are available with the Basic License?
I would be particularly interested in receiving an alert email, if an index or a counter receives or reaches a specific value. For example, if I use Winlogbeat, I want to receive an alert email every time ELK receives a specific Event ID. Or receive an email every time an Event ID 4625 is generated for a specific user account.
If an administration account fails to authenticate successfully and generates three Event ID 4625s in a row, it would be useful to receive an alert email.
Do I have access to this type of alerts, based on the data I collect?
I would be particularly interested in receiving an alert email, if an index or a counter receives or reaches a specific value.
This is possible using the Index Threshold alert type though the basic license only allows in-stack actions so a Gold subscription would be required to send an email. You can log to the server or index a document in basic.