# Logstash conf file for Email Alert

**URL:** <https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914>\
**Category:** Logstash\
**Created:** [November 28, 2022, 7:40am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914 "2022-11-28T07:40:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravi\_Vishwakarma](https://avatars.discourse-cdn.com/v4/letter/r/58956e/32.png) [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Post date:** [November 28, 2022, 7:40am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/1 "2022-11-28T07:40:16Z")

</div>

Hi,

Can anyone help me with this I have created two conf file under /etc/logstash/conf.d/

1. syslog.conf === Working fine

```auto
input {
    beats {
        port => "5044"
    }
}
filter {
    grok {
        match => { "message" => "%{SYSLOGLINE}"}

    }
    geoip {
        source => "clientip"
    }
}
output {
    elasticsearch {
    hosts => ["192.168.0.119:9200"]
    user => "${ES_USER}"
    password => "${ES_PWD}"
   }
}

```

1. Output.conf for Email alert but not working .

```auto
if "ERROR" in [LEVEL]
{
elasticsearch {
  hosts=>"192.168.0.119:9200"
  user =>"${ES_USER}"
  password =>"${ES_PWD}"
  }
  }
  email {
        options => [ "smtpIporHost", "smtp.gmail.com",
         "port", "587",
         "userName", "username",
         "password", "Password",
         "authenticationType", "plain",
         "starttls","true"
           ]
            from => "transmitter"
            subject => "logstash alert"
            to => "receiver"
            via => "smtp"
            body => "Here is the event line that occured: %{message}"
       }
stdout { }
}

```

Request if anyone can help me to get this work.

Regards,  
Ravi

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 29, 2022, 4:27am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/2 "2022-11-29T04:27:06Z")

</div>

> [@Ravi\_Vishwakarma](#):
>
> Output.conf for Email alert but not working

What exactly does "not working" mean? Are you getting error messages on either the logstash or SMTP server side?

---

<div class="post-metadata">

**Author:** ![Ravi\_Vishwakarma](https://avatars.discourse-cdn.com/v4/letter/r/58956e/32.png) [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Post date:** [November 29, 2022, 7:51am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/3 "2022-11-29T07:51:24Z")

</div>

Hi Badger,

Thanks for the reply..  
No email receiving for logstash when we use above setting.

for your information I am using ELK with basic license.  
just wanted know the steps which I am following is correct for receiving email notification or is there any other way to get email notification in ELK with Basic license.

Please suggest for the same and if possible please share the steps.

Regards,  
Ravi

---

<div class="post-metadata">

**Author:** ![Ravi\_Vishwakarma](https://avatars.discourse-cdn.com/v4/letter/r/58956e/32.png) [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Post date:** [December 6, 2022, 5:40am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/4 "2022-12-06T05:40:10Z")

</div>

Hi,

Please help me to configure the same.

Regards,  
Ravi

---

<div class="post-metadata">

**Author:** ![Ravi\_Vishwakarma](https://avatars.discourse-cdn.com/v4/letter/r/58956e/32.png) [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Post date:** [December 7, 2022, 5:08am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/5 "2022-12-07T05:08:46Z")

</div>

Hi,

Can anyone help me to configure the same.

Regards,  
Ravi

---

<div class="post-metadata">

**Author:** ![Ravi\_Vishwakarma](https://avatars.discourse-cdn.com/v4/letter/r/58956e/32.png) [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Post date:** [December 20, 2022, 7:42am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/6 "2022-12-20T07:42:19Z")

</div>

Hi,

Can any one help me on this?  
email alert with logstash pipeline already using logstash for syslog.

Regards,  
Ravi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2023, 7:43am UTC](https://discuss.elastic.co/t/logstash-conf-file-for-email-alert/319914/7 "2023-01-17T07:43:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
