# \_DataId Health Monitoring

**URL:** <https://discuss.elastic.co/t/dataid-health-monitoring/385914>\
**Category:** Elastic Security\
**Created:** [April 16, 2026, 7:48am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914 "2026-04-16T07:48:36Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 16, 2026, 7:48am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/1 "2026-04-16T07:48:37Z")

</div>

Looking to build a logic which alerts whenever there is a log stoppage detected on Elastic through \_dataId. I appreciate any suggestions here.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [April 16, 2026, 11:32am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/2 "2026-04-16T11:32:15Z")

</div>

Hello @saratsekhar

Welcome to the Community!!

Can you please share more details about the data / alert needed?

If you have datastream/index pattern we can create a dataview , we can create a rule & count the number of records with \_dataId , if count \< 1 in last 15 minutes than an alert should be triggered that no data in Elastic.

Thanks!!

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 16, 2026, 12:03pm UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/3 "2026-04-16T12:03:29Z")

</div>

Thank you,

I need to create an alert that detects complete log stoppage from critical servers. Rather than monitoring specific hosts, I want to track by `dataId`.

I attempted to use an index-based threshold rule with the condition set to trigger when document count falls below 1 within a specified time interval. However, this approach has two problems:

1. High alert volume - The rule generates excessive alerts

2. Lack of specificity - When an alert fires, I cannot identify which specific `_dataId` caused the stoppage

How can I configure this to properly track log stoppage per `dataId` and include that information in the alert?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [April 17, 2026, 5:53am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/4 "2026-04-17T05:53:42Z")

</div>

Hello @saratsekhar

So if i understand it correctly \_dataId is your server name ? If yes, what is the unique count of critical servers for which data is received & monitor is in place?

Thanks!!

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 17, 2026, 6:25am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/5 "2026-04-17T06:25:13Z")

</div>

Hello,

_dataId is unique across log type like windows, linux, firewall, database, procxy etc. So need an alert whenever these_ dataIDs stop sending any log.

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 17, 2026, 8:22am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/6 "2026-04-17T08:22:49Z")

</div>

@Tortoise Index based threshold rule is recommended here?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [April 17, 2026, 8:43am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/7 "2026-04-17T08:43:34Z")

</div>

Hello @saratsekhar

Index based threshold can be used but it will not serve your need...If i understand you usecase...

Index =\> ABC  
In this index we continuously receive data  
there is one field \_dataId \> this will have various values example \> windows/mac/os/android

Now the rule should run and tell that in last 15 minutes we have not received data for windows/mac if the count of these records are 0 ?

actually if the source is fixed (windows/mac/os/android) in that case we will have to go for Watcher as shared here :

> [@Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574/2):
>
> Hello @Joey_Visbeen We can use the chain input job without transform , the action part needs to be updated as per your requirement along with the time range as it was used as 5h incase below code is as per the requirement (script part generated using LLM) - { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": [ { "first": { "search": { "request": { "search\_type": "query\_th…

because in rule it will alert that last 15 minutes there is no data but for which source there is no data that output will not be possible.

Thanks!!

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 21, 2026, 7:52am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/8 "2026-04-21T07:52:20Z")

</div>

Thanks for providing the information, last statement is applicable for Threshold rule or a Watcher?

because in rule it will alert that last 15 minutes there is no data but for which source there is no data that output will not be possible.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [April 21, 2026, 8:12am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/9 "2026-04-21T08:12:15Z")

</div>

Hello @saratsekhar  
Below statement was for Rule :

_because in rule it will alert that last 15 minutes there is no data but for which source there is no data that output will not be possible_

As for Watcher example if you see there is fixed source which is added from where you expected the data to be received & if any of the source does not have data than it will say which source has no data.

Thanks!!

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 21, 2026, 8:17am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/10 "2026-04-21T08:17:40Z")

</div>

thanks @Tortoise , could you please advise on the steps to create this in Watcher?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [April 21, 2026, 9:11am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/11 "2026-04-21T09:11:42Z")

</div>

Hello @saratsekhar

Please review the watcher shared in below link with similar usecase but has different values :

> [@Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574/2):
>
> Hello @Joey_Visbeen We can use the chain input job without transform , the action part needs to be updated as per your requirement along with the time range as it was used as 5h incase below code is as per the requirement (script part generated using LLM) - { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": [ { "first": { "search": { "request": { "search\_type": "query\_th…

Thanks!!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 21, 2026, 2:45pm UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/12 "2026-04-21T14:45:54Z")

</div>

Alerting on missing data can be a little tricky sometimes, what worked for me was creating a custom ESQL rule to calculate the lag between the current time (the rule execution time) and the time of the last event.

```auto
FROM index
| STATS last_timestamp = MAX(event.ingested) by event.dataset
| EVAL lag = DATE_DIFF("minute", last_timestamp, NOW())
| WHERE lag >= 15
| LIMIT 100

```

In this case this would calculate the lag between the tima of the rule exation and the time of the last indexed event, in t his case I'm using the `event.ingested` field, it would also group by a particular field, in this case `event.dataset`, and it would return all `event.dataset` where the lag is equal o higher than 15 minutes.

I need to run this rule with a look back window at least wice the lag time, in this case 30 minutes, so I will get at least one alert.

You may try to adapt this query to your data to see if it works.

---

<div class="post-metadata">

**Author:** ![saratsekhar](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@saratsekhar](https://discuss.elastic.co/u/saratsekhar)\
**Post date:** [April 22, 2026, 6:45am UTC](https://discuss.elastic.co/t/dataid-health-monitoring/385914/13 "2026-04-22T06:45:46Z")

</div>

Thanks for sharing the information :), will give a try.
