# Log Stoppage alert from critical server - ELK7.12

**URL:** <https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting\
**Created:** [May 25, 2021, 9:47am UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915 "2021-05-25T09:47:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [May 25, 2021, 9:47am UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/1 "2021-05-25T09:47:26Z")

</div>

Hello Team,

Please help me to understand the best way to create the log stoppage alert for critical servers. It should be index specific.  
For example: Index "A" contains 3 Firewall device logs- fw1,fw2,fw3  
Need to get the email alert if Elasticsearch stop receiving logs from any of the 3 firewall logs for last 10minutes.

Can i use Security\>detection\>Threshold Rule type for this OR  
OBservability\>logs\>alert ?

Please help me with a sample.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 21, 2021, 7:49am UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/2 "2021-06-21T07:49:42Z")

</div>

Waiting for a feedback on above mentioned query.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [June 29, 2021, 6:50pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/3 "2021-06-29T18:50:55Z")

</div>

I think you could create this alert with the [index threshold alert](https://www.elastic.co/guide/en/kibana/current/rule-type-index-threshold.html).

The docs show an example similar to what you probably want. For yours, you'd want the condition to be the count of documents over a certain amount of time is zero (or less than you would expect).

The [elasticsearch query alert](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html) is also available, which allows for more customized queries.

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 29, 2021, 7:42pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/4 "2021-06-29T19:42:41Z")

</div>

Thank you @Patrick_Mueller for the valuable feedback.

If I have 50 servers(50 hostname fields) in the index. For getting alerts if any of the server stop sending logs for last 30minuts. Can I use threshold index alert as mentioned below?

INDEX Index\_name  
WHEN count()  
"GROUPED OVER top 50 'host.hostname'

Condition:  
IS BELOW OR EQUALS 0  
FOR THE LAST 30 minutes

Thanks in advance

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 30, 2021, 8:27am UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/5 "2021-06-30T08:27:00Z")

</div>

I have tried the above logic and its not triggering the alert when one of the hostname stop sending logs for more than 30minutes.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [June 30, 2021, 1:01pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/6 "2021-06-30T13:01:56Z")

</div>

Ah, I think there will be a problem with this due to the **lack** of data from these servers, when they are down. Probably the best you can do is have an alert that checks if the count is below some expected level - and that would only alert for a while; after the hostname is no longer logging, the alert will presumably recover. It _might_ be useful, hard to say. You could also look into using the [elasticsearch query alerting rule type](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html) - if you could fashion a query that would return the info you want.

Have you looked into using [Uptime Monitoring](https://www.elastic.co/uptime-monitoring) for this? Rather than use a general purpose alert, presumably an uptime alert may be more appropriate for this.

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 30, 2021, 3:04pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/7 "2021-06-30T15:04:29Z")

</div>

There is no option to aggregate the hostnames in Elasticsearch query alerting rule type.

Uptime Monitoring there is no option to query against a specific indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 3:04pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-from-critical-server-elk7-12/273915/8 "2021-07-28T15:04:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
