# How to create alert when some component stopped to send data

**URL:** <https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048>\
**Category:** Elasticsearch\
**Created:** [August 23, 2017, 10:10am UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048 "2017-08-23T10:10:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vitaly\_il](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaly_il/32/130964_2.png) [@Vitaly\_il](https://discuss.elastic.co/u/Vitaly_il)\
**Post date:** [August 23, 2017, 10:10am UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048/1 "2017-08-23T10:10:36Z")

</div>

I'm thinking about using X-Pack Watcher for alerting when some of our components stopped to send data to ELK.  
I.e. there is no new data from certain source recently.

- There is quick&dirty solution by just create individual watcher per data source (i.e. "host", "type", ...). Seems really ugly.
- Combine different sources in one watcher using array. A little better, but still static list.
- "We saw messages from these sources in the past - let's check if we see them recently" - I'm not sure what is the best way to implement this logic.
- ML ? How?

What do you think?  
I'm curious if someone already implemented similar thing.  
TIA,  
Vitaly

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [August 23, 2017, 11:16am UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048/2 "2017-08-23T11:16:59Z")

</div>

Hi,  
If you have data that should get into the cluster regulary you may build a watcher that check how old is the timestamp of the last inserted entry. If \> than x then fire alarm.

pts0

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [August 23, 2017, 12:55pm UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048/3 "2017-08-23T12:55:27Z")

</div>

ML can easily do this with a job that would use the `low_count` detector. If the data source is a single index, then a Single Metric job will do the trick.

If there are multiple "types" in the index, then the Multi-metric Job is the right choice, splitting on the `type` field (or whatever you want to split on)

Also, in v5.5, ML makes it easy to create Watches from the Single-Metric and Multi-metric jobs. See this blog: [https://www.elastic.co/blog/alerting-on-machine-learning-jobs-in-elasticsearch-v55](https://www.elastic.co/blog/alerting-on-machine-learning-jobs-in-elasticsearch-v55)

---

<div class="post-metadata">

**Author:** ![Vitaly\_il](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaly_il/32/130964_2.png) [@Vitaly\_il](https://discuss.elastic.co/u/Vitaly_il)\
**Post date:** [August 24, 2017, 9:54am UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048/4 "2017-08-24T09:54:56Z")

</div>

Many thanks, this article is really good.  
I started to play with ML. I'll use Multi Metric job, split by type, as you suggested.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2017, 9:55am UTC](https://discuss.elastic.co/t/how-to-create-alert-when-some-component-stopped-to-send-data/98048/5 "2017-09-21T09:55:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
