# I want to set up sending notifications about errors

**URL:** <https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287>\
**Category:** Logstash\
**Created:** [September 3, 2021, 2:00pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287 "2021-09-03T14:00:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 3, 2021, 2:00pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/1 "2021-09-03T14:00:18Z")

</div>

Hello. I want to set up sending notifications about errors (errors in the operation of Apache, MySQL, Nginx, as well as if the server is not available) from logstesh to e-mail. Wrote at ./logstash/pipeline/logstash.conf

```auto
input {
        beats {
                port => 5044
        }

        tcp {
                port => 5000
        }
}

## Add your filters / logstash plugins configuration here

output {
        elasticsearch {
                hosts => "https://elasticsearch:9200"
                ssl => true
                ssl_certificate_verification => false
                cacert => "/usr/share/logstash/config/ca.crt"
                user => "elastic"
                password => "passwd"
                ecs_compatibility => disabled
        }

        email {
                to => "user@domain.ru"
                from => "user@domain.ru"
                username => "user@domain.ru"
                password => "passwd"
                authentication => "plain"
                subject => "Alert - %{@hostname}"
                body => "Tags: %{@timestamp}\\n\\Content:\\n%{@message}"
                address => "mail.domain.ru"
                port => "587"
                use_tls => "true"
                via => "smtp"
        }

}

```

that's what, messages with the specified text go, but how to achieve the desired result for me? Thanks in advance for your reply.

---

<div class="post-metadata">

**Author:** ![marcus\_lhisp](https://avatars.discourse-cdn.com/v4/letter/m/4da419/32.png) [@marcus\_lhisp](https://discuss.elastic.co/u/marcus_lhisp)\
**Post date:** [September 3, 2021, 2:15pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/2 "2021-09-03T14:15:08Z")

</div>

Hi Sasha,

Is this maybe that what you are looking for? The Alerting is handled via Kibana Alerting rules.

> **[Alerting | Kibana Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html)**

Kind Regards,  
Marcus

---

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 3, 2021, 2:17pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/3 "2021-09-03T14:17:52Z")

</div>

I am using a basic license. This can become an obstacle to using this type of alert?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 3, 2021, 3:12pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/4 "2021-09-03T15:12:30Z")

</div>

You can parse the messages and tag them if they indicate an error. Then use a [conditional](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals) in the output section to send them using email only if they are tagged.

---

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 6, 2021, 1:44pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/5 "2021-09-06T13:44:35Z")

</div>

Thank you very much for your help. Configured the sending of notifications. But only messages appeared:  
`Unable to load connector types Request has been forbidden by antivirus`  
and kibana began to write an error in some dashboards.  
Could it be related to what I put in the xpack.encryptedSavedObjects.encryptionKey: just a 35 character string?

---

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 8, 2021, 1:17pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/6 "2021-09-08T13:17:25Z")

</div>

Configured sending metrics (configured from kibana). And how to force the system to send messages with the text of the error (for example, if an Apache error gets to the ELK, then send this text to e-mail)? I turned over all the documentation and just can't find what I need. I missed something. Do I understand correctly that it is necessary to update the message field value in the alert? But how?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 8, 2021, 1:31pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/7 "2021-09-08T13:31:03Z")

</div>

> [@sasha198407](#):
>
> I am using a basic license. This can become an obstacle to using this type of alert?

WIth the basic license you can't send alerts using e-mail, the only alerts available with the basic license are `index` and `logging`, the `index` one can write the alert into a new index, the `logging` one will just write the alert in the kibana logs.

If you want to send the alerts through e-mail you will need to write a tool to do that based on the available alerts or find a third-party tool that does that.

---

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 9, 2021, 12:47pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/8 "2021-09-09T12:47:33Z")

</div>

Thanks for the answer. Another question arose. Is it possible to manually start sending from logstash-output-email, is it possible to somehow adjust the frequency of sending messages from logstash-output-email, is it possible to configure sending messages from logstash-output-email on a specific event? Thanks in advance for your reply.

---

<div class="post-metadata">

**Author:** ![sasha198407](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasha198407/32/93866_2.png) [@sasha198407](https://discuss.elastic.co/u/sasha198407)\
**Post date:** [September 15, 2021, 6:13am UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/9 "2021-09-15T06:13:27Z")

</div>

If you believe the forum thread, then sending notifications in the base license is possible. Or has something changed? `https://discuss.elastic.co/t/alerts-in-elk/236763/2`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 6:14am UTC](https://discuss.elastic.co/t/i-want-to-set-up-sending-notifications-about-errors/283287/10 "2021-10-13T06:14:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
