# Logstash email alerts dynamically from multiple log files

**URL:** <https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009>\
**Category:** Logstash\
**Created:** [July 7, 2015, 6:15am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009 "2015-07-07T06:15:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 7, 2015, 6:15am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/1 "2015-07-07T06:15:08Z")

</div>

I have the logstash config file in which i have written the mail alert for particular text present in the message then automatically send an email with the message. Please find the configuration file (logstash.conf).

input {  
file {  
path =\> ["\IP Address\logs/LMS.log.\*\_bak"]  
start\_position =\> "beginning"  
}  
}

output {  
elasticsearch {  
bind\_host =\> "127.0.0.1"  
port =\> "9200"  
protocol =\> http  
}  
if "ERROR" in [message] {  
email {  
from =\> "logstash.alert@nowhere.com"  
subject =\> "logstash alert"  
to =\> "test.lms@gmail.com"  
via =\> "smtp"  
body =\> "Here is the event line that occured: %{message}"  
}  
}  
}  
Here i am not not getting any email from that configuration.So anyone please find that configuration give the solution for me thanks...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2015, 6:52am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/2 "2015-07-07T06:52:58Z")

</div>

Is there anything interesting in the Logstash logs? What if you turn up the logging with `--verbose` or `-debug`? Are you getting data into Elasticsearch? Is new data being added to the log files?

Break down the problem and isolate the factors. What if you skip the conditional around the email output and the elasticsearch output and use a stdin input to feed messages one by one. Does it send any email messages then? If yes, reintroduce things until you get to a stage where it doesn't work again.

---

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 7, 2015, 6:59am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/3 "2015-07-07T06:59:00Z")

</div>

HI Magnusbaeck,

Thanks for replying me, am waiting from last 20 min for your valuable response.

Yes exactly i tried with --debug option, logs are loaded from logstash and for email giving this response.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/24b4a7465fb1114131586cebdb5ae7ea44a8eec4.png)

But, am not getting any emails.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2015, 7:33am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/4 "2015-07-07T07:33:53Z")

</div>

Is new data being added to the files you're monitoring? Logstash will only read old logfiles from the beginning under certain circumstances.

Next time, please copy/paste from logs. Don't use screenshots.

---

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 7, 2015, 8:32am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/5 "2015-07-07T08:32:05Z")

</div>

Actually i added some logs to the location of old logs present. Logstash automatically updated with the new logs but mails are not coming. Elastic search also automatically update the new logs into their storage.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2015, 9:00am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/6 "2015-07-07T09:00:12Z")

</div>

Okay. Then proceed with isolating the issue as I described earlier.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2015, 11:50am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/10 "2015-07-07T11:50:33Z")

</div>

Wait, have you verified that your SMTP server hasn't received the messages? The problem could just as well be that Gmail won't accept the messages. Your SMTP server's log will contain clues.

---

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 7, 2015, 1:20pm UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/11 "2015-07-07T13:20:03Z")

</div>

Yes @magnusbaeck, I have the error like this. Sorry for uploading the image,but am unable to tell the problem with you...

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/bb1c2988fce7767696538bfce1fb5b82ad67d54f.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2015, 1:25pm UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/12 "2015-07-07T13:25:43Z")

</div>

By default Logstash tries to send SMTP messages to localhost:25. It seems you don't have an SMTP server listening on that port. The smtp output documentation isn't too good (see [bug #24](https://github.com/logstash-plugins/logstash-output-email/issues/24)) so see [http://stackoverflow.com/questions/25481252/notifying-log-errors-via-email-using-logstash](http://stackoverflow.com/questions/25481252/notifying-log-errors-via-email-using-logstash) for a complete example. That said, I think you should set up an SMTP server on the Logstash machine to make sure thta Logstash can always load off messages. Otherwise an SMTP server outage would halt the Logstash pipeline.

---

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 7, 2015, 1:39pm UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/13 "2015-07-07T13:39:13Z")

</div>

Thank you very much @magnusbaeck. You are so helpful to me. I seen from last 2 days about your posts and finally i got the solution with your help. Thank you man......

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009/14 "2017-07-06T05:35:23Z")

</div>


