# Email alert for exception

**URL:** <https://discuss.elastic.co/t/email-alert-for-exception/348077>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 27, 2023, 7:25pm UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077 "2023-11-27T19:25:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [November 27, 2023, 7:25pm UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/1 "2023-11-27T19:25:40Z")

</div>

Hi,

I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below.

```auto
# rpm -qa | grep logstash
logstash-8.11.0-1.x86_64
# rpm -qa | grep elasticsearch
elasticsearch-8.11.0-1.x86_64
# rpm -qa | grep kibana
kibana-8.11.0-1.x86_64
# cat /etc/redhat-release
Red Hat Enterprise Linux release 8.8 (Ootpa)
#

```

Is there a way to configure email alerts if there are any exceptions or errors found on any application logs which are indexed and stored in Elasticsearch?

Please guide. I am running an open source community edition. Thanks in advance.

Best Regards,

Kaushal

---

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [November 29, 2023, 4:46pm UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/2 "2023-11-29T16:46:39Z")

</div>

Hi,

Checking in again, if someone can pitch in for my earlier post to this forum? Please guide me.

Thanks in advance.

Best Regards,

Kaushal

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 29, 2023, 4:53pm UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/3 "2023-11-29T16:53:37Z")

</div>

Hi @kaushalshriyan

> [@kaushalshriyan](#):
>
> Is there a way to configure email alerts if there are any exceptions or errors found on any application logs which are indexed and stored in Elasticsearch?

Any Exception on Any Log....

That is a pretty broad request... I think you should start with the documentation and how to...

What kind of Logs? What constitutes and Exception? etc...etc...

> **[Start your log collection and analysis with Elastic](https://www.elastic.co/getting-started/observability/collect-and-analyze-logs)**
>
> Elastic provides a scalable solution to start collecting and analyzing your data logs in the cloud. Learn how to ingest, view and start your analysis now.

> **[Alerting | Elastic Observability \[8.11\] | Elastic](https://www.elastic.co/guide/en/observability/current/create-alerts.html)**

Come back with some specific questions and perhaps we can help

---

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [November 30, 2023, 2:17am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/4 "2023-11-30T02:17:00Z")

</div>

@stephenb Thanks for the detailed response. I have a specific use case, for example I have the below specific string as exception in /opt/tomcat9/logs/paymentapi.log

**"No valid account"**

So whenever there are any occurrences of the above string in Elasticsearch, the ELK stack should trigger an email alert.

Is there a free and OSS version of Elastic Observability to install it on Red Hat Enterprise Linux release 8.8 (Ootpa)?

Please guide me.

Thanks in advance.

Best Regards,

Kaushal

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 30, 2023, 3:23am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/5 "2023-11-30T03:23:42Z")

</div>

Hi @kaushalshriyan

I can not provide all the steps you are going to need to read some of the documents, how to etc...

1st do you have the logs ingested into Elasticsearch already?

How did you ingest them?

Can you show a sample JSONs of a couple of the logs documents that are already in elasticsearch?

There is a lot alerting functionality in the Basic / Free version ... BUT email alerting requires a commercial license...

The Basic license which is Free you can create Alerts and Write the alerts to an index... some people use another tool like logstash to read that index and send emails (that is a little more complicated)

First I would try to create an alert... we can worry about the emails later...

> **[Alerting | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html)**

---

<div class="post-metadata">

**Author:** ![kaushalshriyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaushalshriyan/32/44563_2.png) [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Post date:** [December 2, 2023, 3:48am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/6 "2023-12-02T03:48:38Z")

</div>

Thanks Stephen for the detailed explanation. I will go through the documentation. Much appreciated as always. Keep up the good work. 👏 👏 👏

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2023, 3:49am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077/7 "2023-12-30T03:49:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
