# ELK 8.11 Basic License – Alert if logs with specific field are missing for 30 mins

**URL:** <https://discuss.elastic.co/t/elk-8-11-basic-license-alert-if-logs-with-specific-field-are-missing-for-30-mins/385166>\
**Category:** Monitoring\
**Created:** [February 23, 2026, 3:16pm UTC](https://discuss.elastic.co/t/elk-8-11-basic-license-alert-if-logs-with-specific-field-are-missing-for-30-mins/385166 "2026-02-23T15:16:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_Xavier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_xavier/32/141064_2.png) [@Alex\_Xavier](https://discuss.elastic.co/u/Alex_Xavier)\
**Post date:** [February 23, 2026, 3:16pm UTC](https://discuss.elastic.co/t/elk-8-11-basic-license-alert-if-logs-with-specific-field-are-missing-for-30-mins/385166/1 "2026-02-23T15:16:25Z")

</div>

Hi,

I’m using ELK Stack 8.11.0 (Basic License) and need to trigger an Email or SMS alert if logs with a specific field (example: state:132) are not received for 30 minutes.

Logs normally arrive every few seconds. If no logs arrive for that field within 30 minutes, I want an alert.

Questions:

Can this be done with Basic license Kibana Alerting?

Should I use Index threshold rule or ES query rule?

How to detect missing logs condition?

How to configure Email or SMS alert (via webhook/SMS gateway)?

Thanks!

---

<div class="post-metadata">

**Author:** ![pestevao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pestevao/32/44138_2.png) [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Post date:** [February 23, 2026, 11:09pm UTC](https://discuss.elastic.co/t/elk-8-11-basic-license-alert-if-logs-with-specific-field-are-missing-for-30-mins/385166/2 "2026-02-23T23:09:26Z")

</div>

Take a look at ElastAlert 2 - [GitHub - jertel/elastalert2: ElastAlert 2 is a continuation of the original yelp/elastalert project. Pull requests are appreciated!](https://github.com/jertel/elastalert2/)
