# Custom logs alert

**URL:** <https://discuss.elastic.co/t/custom-logs-alert/304357>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 10, 2022, 2:11pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357 "2022-05-10T14:11:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dhia\_Saibi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhia_saibi/32/102422_2.png) [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Post date:** [May 10, 2022, 2:11pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/1 "2022-05-10T14:11:34Z")

</div>

Hi,  
I want to create a rule in kibana that checks if there is a new ip address (like in the picture) in the log file and sends an alert to mail if there is a new one

 ![Inkedalertss_LI](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d7d882e3f505e4c4ded7f0d91db0c4a1b35c1cc.jpeg)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [May 10, 2022, 11:18pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/2 "2022-05-10T23:18:34Z")

</div>

You should implement an ingest/Logstash pipeline to parse out the IP address to index the IP address into a separate field and use that field for your alerting purposes.

Another option will be to create a runtime field by using `grok`.

---

<div class="post-metadata">

**Author:** ![Dhia\_Saibi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhia_saibi/32/102422_2.png) [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Post date:** [May 12, 2022, 3:39pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/3 "2022-05-12T15:39:10Z")

</div>

Do I need to use Logstash ? because I couldn't send logs from filebeat to logstash instead I'm sending logs from filebeat to elastic directly.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 12, 2022, 3:46pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/4 "2022-05-12T15:46:37Z")

</div>

Yes you can use an ingest pipeline to parse that log, grok works with ingest pipelines as well you could have a nicely parse log 🙂 without logstash

> **[Ingest pipelines | Elasticsearch Guide \[8.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html)**

You will need to do that first and then when you have that ... I suspect you would use a detection for new IPs... get that parsed and then come back and open a very specific topic.

"Alert on New IP Address" or something like that your current title is way too vague and the right people will not look at it.

---

<div class="post-metadata">

**Author:** ![Dhia\_Saibi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhia_saibi/32/102422_2.png) [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Post date:** [May 12, 2022, 8:08pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/5 "2022-05-12T20:08:56Z")

</div>

Thanks for your response, next time I will make sure to pick a good title to my question.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2022, 8:09pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357/6 "2022-06-09T20:09:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
