# Email on alert

**URL:** <https://discuss.elastic.co/t/email-on-alert/92353>\
**Category:** Logstash\
**Created:** [July 8, 2017, 6:10am UTC](https://discuss.elastic.co/t/email-on-alert/92353 "2017-07-08T06:10:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Padmavathy](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Padmavathy](https://discuss.elastic.co/u/Padmavathy)\
**Post date:** [July 8, 2017, 6:10am UTC](https://discuss.elastic.co/t/email-on-alert/92353/1 "2017-07-08T06:10:07Z")

</div>

I am using logstash 5.3.I am taking records from oracle database as a cron job.

I need to send a email to sort problem which arises when logstash is loading data or elasticsearch server is down  
Can someone help me with this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 8, 2017, 3:43pm UTC](https://discuss.elastic.co/t/email-on-alert/92353/2 "2017-07-08T15:43:02Z")

</div>

One avenue to explore could be to configure Logstash to have an output that send heartbeats to a heartbeat monitoring tool like [Lovebeat](https://github.com/boivie/lovebeat). If the Logstash pipeline is clogged (e.g. because of ES problems) the heartbeats won't be sent either and you'll get an alert.

---

<div class="post-metadata">

**Author:** ![Padmavathy](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Padmavathy](https://discuss.elastic.co/u/Padmavathy)\
**Post date:** [July 10, 2017, 2:22pm UTC](https://discuss.elastic.co/t/email-on-alert/92353/3 "2017-07-10T14:22:01Z")

</div>

thanks @magnusbaeck

this is my config  
input  
{  
heartbeat {  
interval =\> 10  
type =\> "heartbeat"  
}  
}  
output {  
#stdout { codec =\> json\_lines }  
if [type] == "heartbeat" {  
email  
{  
from =\> 'abc@gmail.com'  
to =\> 'abc@gmail.com'  
port =\> 25  
domain =\> '[mail.logstash.net](http://mail.logstash.net)'  
}  
}  
elasticsearch {  
index =\> "time3"  
document\_type =\> "time3"  
hosts =\> "localhost"  
}  
}

but i get the following error  
19:47:23.914 [[main]\>worker0] ERROR logstash.outputs.email - Something happen wh  
ile delivering an email {:exception=\>#\<Errno::ECONNREFUSED: Connection refused -  
Connection refused\>}

Can you help me with this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 11, 2017, 5:59pm UTC](https://discuss.elastic.co/t/email-on-alert/92353/4 "2017-07-11T17:59:36Z")

</div>

> domain =\> '[mail.logstash.net](http://mail.logstash.net)'

This is bogus, remove it. The documentation of the `domain` is really bad so I can't blame you; I'll send a PR to improve it.

You have configured the email output to connect to localhost:25. It seems you don't have an SMTP server running at that location. Either make sure you are or reconfigure Logstash to connect to a working SMTP server.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2017, 5:59pm UTC](https://discuss.elastic.co/t/email-on-alert/92353/5 "2017-08-08T17:59:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
