# How to Setup custom alerting in kibana for logs

**URL:** <https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 18, 2020, 12:16pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103 "2020-05-18T12:16:05Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [May 18, 2020, 12:16pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/1 "2020-05-18T12:16:05Z")

</div>

Hey Guys,  
I have setup an Alert for my backup Monitoring where in message Field if it says "Network related issue"  
with a threshold reached it gives me an alert. The alert contains the contents severity and the message from the message field. I also have server IP field which contains the IP.

My question is, How do i include my server IP here along with the message field to be alerted to my mail.  
is there any custom way to set it up.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 19, 2020, 9:24pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/2 "2020-05-19T21:24:36Z")

</div>

Are you using Watcher?

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [May 20, 2020, 10:00am UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/3 "2020-05-20T10:00:30Z")

</div>

Hey tyler  
I am not using watcher

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 20, 2020, 1:39pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/4 "2020-05-20T13:39:30Z")

</div>

What are you using to manage the alerts?

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [May 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/5 "2020-05-20T15:20:36Z")

</div>

Actually I am using Elasticsearch opensource provided in AWS, for alerting we intergrate with the AWS SNS and send the mail.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 20, 2020, 3:57pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/6 "2020-05-20T15:57:11Z")

</div>

You will have to reach out to them about their alerting system and how to include additional information in the message.

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [May 20, 2020, 4:52pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/7 "2020-05-20T16:52:22Z")

</div>

Thanks for you concern. Actually , I dint really dig deep into AWS about their options but, I found an another way by using ElastAlert, I was able to achieve what i was up to.

---

<div class="post-metadata">

**Author:** ![Vikas\_Rathore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_rathore/32/70471_2.png) [@Vikas\_Rathore](https://discuss.elastic.co/u/Vikas_Rathore)\
**Post date:** [June 16, 2020, 3:51pm UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/8 "2020-06-16T15:51:38Z")

</div>

Hey Rahul, I am having the exact same issue. how did you manage to add alert on aws elastic serarch? any document?

---

<div class="post-metadata">

**Author:** ![Rahul\_Ravichandran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahul_ravichandran/32/53882_2.png) [@Rahul\_Ravichandran](https://discuss.elastic.co/u/Rahul_Ravichandran)\
**Post date:** [June 17, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/9 "2020-06-17T08:37:14Z")

</div>

Hey Vikas,  
I used ElastAlert To create a custom alert rule. Here are the links which i followed

[![](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4bc106378d6f90d5963d3bc7cfe445f5e1eb6ede.jpeg "[Elasticsearch 9] Elasticsearch Email alerting using Elastalert") ](https://www.youtube.com/watch?v=vhRxUrg2OxM)

> <https://github.com/justmeandopensource/elk/blob/master/docs/elastic-kibana-filebeat-elastalert-notes.md>

you can refer the YouTube for the steps to installation and GitHub for the commands.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-to-setup-custom-alerting-in-kibana-for-logs/233103/10 "2020-07-15T08:37:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
