# Elasicsearch alerts on Icinga

**URL:** <https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760>\
**Category:** Elasticsearch\
**Created:** [March 19, 2015, 12:48pm UTC](https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760 "2015-03-19T12:48:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [March 19, 2015, 12:48pm UTC](https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760/1 "2015-03-19T12:48:05Z")

</div>

Hello good people,

We have an ELK setup for our nginx / postfix etc logs. it's great.

Now we'd like to be able to alert based on various criteria. icinga is  
great, we just installed it to play with.

is there a plugin that we can use to query elasticsearch from within  
icinga, to create alerts?

we have a POC but it's a ruby script, hence clunky...

Thanks,  
Yarden

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2015, 4:38pm UTC](https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760/2 "2015-03-19T16:38:38Z")

</div>

There are a few nagios scripts people have written, eg

> **[GitHub - anchor/nagios-plugin-elasticsearch: An ElasticSearch availability...](https://github.com/anchor/nagios-plugin-elasticsearch)**
>
> An ElasticSearch availability and performance monitoring plugin for Nagios - GitHub - anchor/nagios-plugin-elasticsearch: An ElasticSearch availability and performance monitoring plugin for Nagios

On 19 March 2015 at 05:48, Yarden Bar [ayash.jorden@gmail.com](mailto:ayash.jorden@gmail.com) wrote:

> Hello good people,
> 
> We have an ELK setup for our nginx / postfix etc logs. it's great.
> 
> Now we'd like to be able to alert based on various criteria. icinga is  
> great, we just installed it to play with.
> 
> is there a plugin that we can use to query elasticsearch from within  
> icinga, to create alerts?
> 
> we have a POC but it's a ruby script, hence clunky...
> 
> Thanks,  
> Yarden
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X9bVQLnbfifgryLzGcPpqeYMO\_bLsjacmkQ7GmgGnELkQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X9bVQLnbfifgryLzGcPpqeYMO_bLsjacmkQ7GmgGnELkQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Yarden\_Bar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yarden_bar/32/736_2.png) [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Post date:** [March 22, 2015, 2:39pm UTC](https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760/3 "2015-03-22T14:39:07Z")

</div>

Thanks Mark for the Nagios plugin suggestion. just that I'm not aiming at  
monitoring ES itself (that would be later, down the road)

What I'm looking for is an efficient way( a framework maybe) to register  
alerts into Icinga/Nagios that will recieve an Elasticsearch query as a  
parameter and start alerting based on a threshold parameters(which are  
supplied as well).

Currently I'm coding each ES based check manually.

Thanks in advance for any ideas..  
Yarden

On Thursday, March 19, 2015 at 6:39:06 PM UTC+2, Mark Walkom wrote:

> There are a few nagios scripts people have written, eg  
> [GitHub - anchor/nagios-plugin-elasticsearch: An ElasticSearch availability and performance monitoring plugin for Nagios](https://github.com/anchor/nagios-plugin-elasticsearch)
> 
> On 19 March 2015 at 05:48, Yarden Bar \<[ayash....@gmail.com](mailto:ayash....@gmail.com) \<javascript:\>\>  
> wrote:
> 
> > Hello good people,
> > 
> > We have an ELK setup for our nginx / postfix etc logs. it's great.
> > 
> > Now we'd like to be able to alert based on various criteria. icinga is  
> > great, we just installed it to play with.
> > 
> > is there a plugin that we can use to query elasticsearch from within  
> > icinga, to create alerts?
> > 
> > we have a POC but it's a ruby script, hence clunky...
> > 
> > Thanks,  
> > Yarden
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4d325d11-8197-44ed-a73d-802f21534d9a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0b2e9bbf-7d6c-4582-9a4a-709c2fead1ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0b2e9bbf-7d6c-4582-9a4a-709c2fead1ed%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:25am UTC](https://discuss.elastic.co/t/elasicsearch-alerts-on-icinga/22760/4 "2017-07-06T00:25:07Z")

</div>


