# How to make alarm dashboard on standard system log errors

**URL:** <https://discuss.elastic.co/t/how-to-make-alarm-dashboard-on-standard-system-log-errors/87679>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 31, 2017, 6:52am UTC](https://discuss.elastic.co/t/how-to-make-alarm-dashboard-on-standard-system-log-errors/87679 "2017-05-31T06:52:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rottis](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@rottis](https://discuss.elastic.co/u/rottis)\
**Post date:** [May 31, 2017, 6:52am UTC](https://discuss.elastic.co/t/how-to-make-alarm-dashboard-on-standard-system-log-errors/87679/1 "2017-05-31T06:52:54Z")

</div>

Hi. I am wondering if the following is possible using X-pack and kibana.  
I have a large amount of system logs coming into elasticsearch trough logstash from different stacks.  
I want to get the dashboard to display for example a notification in case of errors and and in that case be able to click to view each error log separately. I have written a watcher alarm as shown below.

```
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "logstash*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "error OR level:ERROR"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-10s"
                    }
                  }
                }
              ]
            }
          },
          "_source": [
            "message"
          ],
          "sort": [
            {
              "@timestamp": {
                "order": "desc"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gt": 0
      }
    }
  },
  "actions": {
    "log": {
      "logging": {
        "level": "info",
        "text": "{{#ctx.payload.hits.hits}}{{_source.message}}{{/ctx.payload.hits.hits}}"
      }
    }
  },
  "throttle_period_in_millis": 9
}

```

which will show me the error logs, but I have trouble displaying the logs properly in the dashboard.  
-In case of multiple hits, it will display all the messages in the same row  
-This action will write the output in elasticsearch master node's logs. It is unnecessary.  
I am wondering if the logging action is proper for this use case. Is there any other way to display the log messages in the dashboard? Also, is there a way to trigger these alarms checked via the dashboard, i.e. delete these alarms once confirmed?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 6, 2017, 12:17pm UTC](https://discuss.elastic.co/t/how-to-make-alarm-dashboard-on-standard-system-log-errors/87679/2 "2017-06-06T12:17:03Z")

</div>

Hey,

consider the `logging` for debugging purposes, but not for a real production use case. It's much better to use one of the other outputs like sending a message to slack/hipchat - in which you could provide a link to a dashboard that contains information about errors.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2017, 12:17pm UTC](https://discuss.elastic.co/t/how-to-make-alarm-dashboard-on-standard-system-log-errors/87679/3 "2017-07-04T12:17:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
