# Log stoppage alert using Machine learning in ELK 7.12

**URL:** <https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [May 26, 2021, 6:05pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105 "2021-05-26T18:05:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [May 26, 2021, 6:05pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/1 "2021-05-26T18:05:03Z")

</div>

Hi,

Please help to create a log stoppage alert for critical devices using machine learning.

For example: Index "A" contains 10 Active directory server logs.  
Need to generate an email alert if Elasticsearch stop receiving logs from any of the 10 AD servers IPs for last 10minutes.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [May 26, 2021, 6:56pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/2 "2021-05-26T18:56:27Z")

</div>

Relevant: [Creating job: anomaly in the event rate of beats](https://discuss.elastic.co/t/creating-job-anomaly-in-the-event-rate-of-beats/261889)

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 21, 2021, 6:13pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/3 "2021-06-21T18:13:39Z")

</div>

Hi Thank you @richcollier for sharing the above details.

Still i am not able to create the advanced ml job to alert the low event rate on each AD servers. I have doubt on adding the terms aggregation(hostname) in ml job.

Is there any easier sample example to understand this?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 21, 2021, 11:50pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/4 "2021-06-21T23:50:15Z")

</div>

Can do just a simple multi-metric job, pick the `low_count` function and pick the hostname as the split field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a5fd7914b19aed020df8e545b9724974f7996a4d.png)

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [June 22, 2021, 4:58am UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/5 "2021-06-22T04:58:18Z")

</div>

Thank you @richcollier for the swift response.

Above mentioned multi-metric will help only to detect the low event rate right? what if one of the host stopped sending logs? will this multi-metric detect that?

For example: Index "A" contains 10 Active directory server logs.  
Need to generate an email alert if Elasticsearch stop receiving logs from any of the 10 AD server IPs for last 1hour.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 22, 2021, 2:02pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/6 "2021-06-22T14:02:06Z")

</div>

A host stopping sending logs **_IS_** a "low event rate" 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2021, 2:02pm UTC](https://discuss.elastic.co/t/log-stoppage-alert-using-machine-learning-in-elk-7-12/274105/7 "2021-07-20T14:02:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
