# Generate alert for error message in metrics dataset

**URL:** <https://discuss.elastic.co/t/generate-alert-for-error-message-in-metrics-dataset/318888>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [November 14, 2022, 5:48pm UTC](https://discuss.elastic.co/t/generate-alert-for-error-message-in-metrics-dataset/318888 "2022-11-14T17:48:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [November 14, 2022, 5:48pm UTC](https://discuss.elastic.co/t/generate-alert-for-error-message-in-metrics-dataset/318888/1 "2022-11-14T17:48:44Z")

</div>

We have a situation where `dockerd` will periodically crash on a host, creating issues with jobs running in a timely fashion. Our application team would like to be notified when `dockerd` goes down. Unfortunately, we do not have the Docker API configured, so I'm unable to simply put a monitor on `localhost:2375/_ping`.

I have observed that when the Docker integration is unable to connect to `/var/run/docker.sock`, it generates a specific error message in the `docker.*` `metrics` data sets.

How can I generate an alert based on this? Frankly, simply alerting on the presence of `error.message` would suffice for this use case.

# Edit

The ability to monitor a unix socket and simply alert if I were unable to connect to it would work as well (e.g., `unix:///var/run/docker.sock`).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2022, 5:49pm UTC](https://discuss.elastic.co/t/generate-alert-for-error-message-in-metrics-dataset/318888/2 "2022-12-12T17:49:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
