# Email alert in elasticsearch

**URL:** <https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105>\
**Category:** Elasticsearch\
**Created:** [February 6, 2020, 7:44am UTC](https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105 "2020-02-06T07:44:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [February 6, 2020, 7:44am UTC](https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105/1 "2020-02-06T07:44:32Z")

</div>

Hi Team,

I am working on the Email Alert functionality, where i came different scenario like  
Let's Suppose I have configured the metricbeat & filebeat in 10 servers which will send the data to the Elastics cluster. Among 10 servers, If any one of the server went down and it will  
not return the data of that particular server to the Elastic cluster. So, now i want to send the email alert to the user about the node details which went down.

So, I am unable to create the Alert based on the node wise

Is there any way to achieve the Email Alert when any one of the node is not sending the documents to the Elastic cluster

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 7, 2020, 3:03pm UTC](https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105/2 "2020-02-07T15:03:58Z")

</div>

The first thing is to draft a query that can display such data - until this is done there is no need to think about a watch.

How about this:

Query for data in the last 30 minutes, `now-30m`

1. Aggregation: Filter on time `now-15m`, terms aggregration on beat hosts
2. Aggregation: From on time `-15m-30m`, , terms aggregration on beat hosts

Now with this . response you could check if the aggregation response contains different hosts and if there are hosts in the second agg that dont exist in the first. If that is the case, you got a host that is not sending data anymore.

---

<div class="post-metadata">

**Author:** ![Kim-Kruse-Hansen](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Post date:** [February 10, 2020, 7:36pm UTC](https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105/3 "2020-02-10T19:36:20Z")

</div>

Hi

Its common problem , so I wrote a blog post on that topic. Have a read and see it if you can use it. We use this approach on many indices and works well for us.

[https://www.securitydistractions.com/2019/08/05/watching-for-no-data/](https://www.securitydistractions.com/2019/08/05/watching-for-no-data/)

Regards  
Kim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2020, 7:36pm UTC](https://discuss.elastic.co/t/email-alert-in-elasticsearch/218105/4 "2020-03-09T19:36:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
