# How to Alert When Elastic Agent Goes Offline?

**URL:** <https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222>\
**Category:** Kibana\
**Tags:** fleet\
**Created:** [June 16, 2025, 10:53pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222 "2025-06-16T22:53:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bakhtiyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakhtiyar/32/143724_2.png) [@bakhtiyar](https://discuss.elastic.co/u/bakhtiyar)\
**Post date:** [June 16, 2025, 10:53pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/1 "2025-06-16T22:53:22Z")

</div>

Hi everyone,

I'm using **Elastic Agent with Fleet** and I can see the agent status (e.g., healthy, offline) from the **Fleet → Agents** UI in Kibana.

Now, I want to **create an alert** that triggers when an agent goes **offline for more than 15 minutes**. Ideally, I'd like to:

- Automatically detect this using the agent’s **status** in Fleet
- Set up an **alert rule** in Kibana (Stack Management → Rules)
- Optionally get notified via email or Slack when an agent status changes to offline

I’m aware that Fleet stores metadata in the `.fleet-agents` and `.fleet-agent-events` indices, but I’m not sure what the **recommended approach** is for alerting on offline agents.

Can anyone from the community or Elastic team guide me on:

1. Best practices for alerting on **offline agent status**
2. Whether querying `.fleet-agents` directly for `status: "offline"` is stable and recommended
3. Whether there's a built-in rule type or future feature planned to support this natively in Fleet

Any help, shared rule examples, or recommended methods would be greatly appreciated!

Thanks in advance 🙏

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 17, 2025, 2:57am UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/2 "2025-06-17T02:57:42Z")

</div>

Hello and welcome,

Considering that Fleet unfortunately still does not have any built-in alerts for individual agents I don't think that there are any recommended approachs on how to alert on offline agents.

So you may use what works better for you.

There are nothing official, so you need to build some custom monitoring by doing queries on the fleet internal indices or using the Fleet API.

I use the Fleet API to get information about the agents and index it on a custom index, then I create alerts on the data of this custom index.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [June 17, 2025, 8:54am UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/3 "2025-06-17T08:54:28Z")

</div>

Thanks @leandrojmp for sharing the details.

Could you please share what is the API you are using to capture the agent details?

With this API below will be the flow?

Custom API Integration \> Ingest Pipeline \> Index events \> on this index =\> Dashboard & Rules/Alerts, right?

Thanks!!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 17, 2025, 12:49pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/4 "2025-06-17T12:49:27Z")

</div>

> [@Tortoise](#):
>
> Could you please share what is the API you are using to capture the agent details?

I'm using the Fleet API for Agent status, this [one](https://www.elastic.co/docs/api/doc/kibana/group/endpoint-elastic-agent-status).

> [@Tortoise](#):
>
> With this API below will be the flow?
> 
> Custom API Integration \> Ingest Pipeline \> Index events \> on this index =\> Dashboard & Rules/Alerts, right?

I do not use custom API integrations, I prefer to write a custom python script to get and write the data.

---

<div class="post-metadata">

**Author:** ![bakhtiyar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bakhtiyar/32/143724_2.png) [@bakhtiyar](https://discuss.elastic.co/u/bakhtiyar)\
**Post date:** [June 17, 2025, 7:29pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/5 "2025-06-17T19:29:34Z")

</div>

Thanks for sharing your approach!  
Just to clarify — are you running the Fleet API queries on a scheduled basis (like via a cron job or scheduled task), or are you using something like Watcher or another tool to handle the automation? Would love to know what’s worked best for you in terms of keeping the data up-to-date.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 17, 2025, 8:15pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/6 "2025-06-17T20:15:11Z")

</div>

I use a python code that run via a cron job.

---

<div class="post-metadata">

**Author:** ![Nima\_Rezainia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nima_rezainia/32/88626_2.png) [@Nima\_Rezainia](https://discuss.elastic.co/u/Nima_Rezainia)\
**Post date:** [June 19, 2025, 5:20am UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/7 "2025-06-19T05:20:38Z")

</div>

Providing off-shelf alerting rules on agents is a high priority roadmap item for us. We should be able to show something in this regard soon. Currently what exists for agents is highlighted here: [Monitor Elastic Agents | Fleet and Elastic Agent Guide [8.18] | Elastic](https://www.elastic.co/guide/en/fleet/8.18/monitor-elastic-agent.html#fleet-alerting)

Unfortunately this doesn't give the user a granular alert on a per agent basis - which is what we will be addressing.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 19, 2025, 1:22pm UTC](https://discuss.elastic.co/t/how-to-alert-when-elastic-agent-goes-offline/379222/8 "2025-06-19T13:22:58Z")

</div>

Yeah, I commented my use case on the Github issue that implemented tha alerting by count.

This has no use for us as we have user workstations as well and the number of agents will flutuate during the day.

So it was required to build a custom monitoring.

Good to know that this is coming !
