Email alert after threshold crossed logstash?

I am using logstash, elasticsearch and kibana to analyse my logs. I am
alerting via email when a particular string comes into the log via email
output in logstash:

email {
match => [ "Session Detected", "logline,Session closed" ]

This works fine.

Now, I want to alert on the count of a field (when a threshold is crossed):
Eg If user is field, I want to alert when number of unique users go more
than 5.

Can this be done via email output in logstash??
Please help.

You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
To view this discussion on the web visit
For more options, visit

I'm interested on that question. I'm facing it too.

Is there a way to send an email after crossing a threshold?