# How to get report of before and after 5 lines of log when message match = my-error to my email in x-pack in elasticsearch in plain text format

**URL:** <https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [January 1, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572 "2019-01-01T14:36:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 1, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/1 "2019-01-01T14:36:44Z")

</div>

PUT \_xpack/watcher/watch/log\_error\_watch  
{  
"trigger" : { "schedule" : { "interval" : "10s" }},  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["filebeat-\*"],  
"body" : {  
"query" : {  
"bool" : {  
"must" : [  
{ "match" : { "message": "error" }},  
{ "range" : { "result.execution\_time" : { "from" : "now-10s" }}}  
]  
}  
}  
}  
}  
}  
},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"email\_admin" : {  
"email": {  
"to": "John Doe [john.doe@example.com](mailto:john.doe@example.com)",  
"attachments" : {  
"data.yml" : {  
"data" : {  
"format" : "yaml"  
}  
}  
}  
}  
}  
}  
}

Here I want to get before and after 5 lines and host.name only when the message matches error in email using x-pack in elasticsearch in the form of plain text format. Please, anyone, help me here.

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [January 2, 2019, 7:43pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/2 "2019-01-02T19:43:39Z")

</div>

You can put together something like this using [the Search transform](https://www.elastic.co/guide/en/elastic-stack-overview/current/transform-search.html) to query for logs within a time bound around the timestamp on the error message, say +/- 5 seconds using a range query. Getting _exactly_ 5 lines before and after is a bit more difficult. You might be able to trim the results with a [Script transform](https://www.elastic.co/guide/en/elastic-stack-overview/current/transform-script.html) as part of a [Chain transform](https://www.elastic.co/guide/en/elastic-stack-overview/current/transform-chain.html), though, if it's critical.

---

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 3, 2019, 12:36pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/3 "2019-01-03T12:36:39Z")

</div>

@gbrown thanks for you replay. Can you please provide code for +/-5 sec. I've requirement like above.

---

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 4, 2019, 6:24am UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/4 "2019-01-04T06:24:50Z")

</div>

@gbrown please give me the code for after matching the message. I'nt once match the pattern message display before and after +/-5 lines of the error match lines to be print . and let me how to get report to my mail. Please tell me any one .

---

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 7, 2019, 7:26am UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/5 "2019-01-07T07:26:17Z")

</div>

@here some one help me above my problem. please.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 7, 2019, 9:41am UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/6 "2019-01-07T09:41:06Z")

</div>

Hey,

I think the tough part here is to come up with a definition of what 5 lines above or below something means. This could mean you want the same five lines in the same logfile, but if it is a syslog file, those messages might actually be from a completely different service. If it is from an apache log, those next lines might be from a completely different IP address. So you need to define first for yourself what exactly this means. Do you want to filter by IP, by host, by service, by log level. And only after doing this one can come up with a query.

This is also the reason, why it is super hard for anyone external to your usecase to come up with concrete queries.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 7, 2019, 10:42am UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/7 "2019-01-07T10:42:25Z")

</div>

Yes. I'm monitoring both syslogs as well as apache, JBOSS and my app logs. Can you please provide the x-pack notification script.

---

<div class="post-metadata">

**Author:** ![balamelangi](https://avatars.discourse-cdn.com/v4/letter/b/c77e96/32.png) [@balamelangi](https://discuss.elastic.co/u/balamelangi)\
**Post date:** [January 7, 2019, 12:54pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/8 "2019-01-07T12:54:12Z")

</div>

@here some one help me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2019, 12:54pm UTC](https://discuss.elastic.co/t/how-to-get-report-of-before-and-after-5-lines-of-log-when-message-match-my-error-to-my-email-in-x-pack-in-elasticsearch-in-plain-text-format/162572/9 "2019-02-04T12:54:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
