# Logstash email alerts

**URL:** <https://discuss.elastic.co/t/logstash-email-alerts/236416>\
**Category:** Logstash\
**Created:** [June 9, 2020, 9:26pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416 "2020-06-09T21:26:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hiba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hiba/32/110919_2.png) [@hiba](https://discuss.elastic.co/u/hiba)\
**Post date:** [June 9, 2020, 9:26pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416/1 "2020-06-09T21:26:18Z")

</div>

Hi,  
I'm trying to configure logstash to send mail . But it seems doesn't work.  
my config file :  
input {  
http\_poller {  
urls =\> {  
url =\> "xxxl"  
}  
request\_timeout =\> 60  
schedule =\> { every =\> "60s" }  
codec =\> "json"  
}  
}  
filter {  
split { field =\> "[bookings]" }  
split { field =\> "[bookings][rooms]" }  
mutate {  
rename =\> {  
"[bookings][bookingId]" =\> "bookingId"  
"[bookings][status]" =\> "status"  
"[bookings][hotelId]" =\> "hotelId"  
"[bookings][hotelName]" =\> "hotelName"  
"[bookings][hotelCity]" =\> "hotelCity"  
"[bookings][hotelCountry]" =\> "hotelCountry"  
"[bookings][arrDate]" =\> "arrDate"  
"[bookings][depDate]" =\> "depDate"  
"[bookings][price]" =\> "price"  
"[bookings][currency]" =\> "currency"  
"[bookings][purchasePrice]" =\> "purchasePrice"  
"[bookings][partnerName]" =\> "partnerName"  
"[bookings][partnerId]" =\> "partnerId"  
"[bookings][firstName]" =\> "firstName"  
"[bookings][lastName]" =\> "lastName"  
"[bookings][channel]" =\> "channel"  
"[bookings][supplierName]" =\> "supplierName"  
"[bookings][rooms][board]" =\> "board"  
"[bookings][rooms][paxes][adults]" =\> "adults"  
"[bookings][rooms][paxes][infant]" =\> "infant"  
"[bookings][rooms][paxes][children]" =\> "children"  
"[bookings][rooms][quantity]" =\> "quantity"  
"[bookings][rooms][room]" =\> "room"   
}  
remove\_field =\> ["confirmedDate", "bookingRef", "bookings", "createdDate", "hotelAddress", "hotelPhonearrDate", "customerId", "title", "email", "city", "mobile", "supplierId","paxe", "payments", "options", "isXML"]  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "bookingstest"  
action =\> "update"  
doc\_as\_upsert =\> "true"  
document\_id =\> "%{bookingId}"  
}  
if [http\_poller\_metadata][code] != 200 {  
stdout {  
email {  
from =\> ""[logstash.alert@example.com](mailto:logstash.alert@example.com)""  
subject =\> "logstash alert"  
to =\> "[test@gmail.com](mailto:test@gmail.com)"  
via =\> "smtp"  
body =\> "Here is the event line that occured"  
}  
}  
}  
stdout { codec =\> rubydebug }  
}

i use ELK 7.7.0

please what are the steps to receive the mail.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 9, 2020, 10:32pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416/2 "2020-06-09T22:32:06Z")

</div>

> [@hiba](#):
>
> if [http\_poller\_metadata][code] != 200 {  
> stdout {  
> email {

The default metadata target for http\_poller is @metadata, not http\_poller\_metadata, so that field will not exist.

Also, I would expect logstash not to start if you try to nest an email output inside a stdout output.

---

<div class="post-metadata">

**Author:** ![hiba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hiba/32/110919_2.png) [@hiba](https://discuss.elastic.co/u/hiba)\
**Post date:** [June 10, 2020, 1:30pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416/3 "2020-06-10T13:30:48Z")

</div>

i get this error:

[2020-06-10T15:28:51,205][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

i change the config file :

output {  
if [@metadata][code] == 200 {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "bookingstest"  
action =\> "update"  
doc\_as\_upsert =\> "true"  
document\_id =\> "%{bookingId}"  
}  
}  
else {  
email {  
from =\> "[logstash.alert@nowhere.com](mailto:logstash.alert@nowhere.com)"  
subject =\> "logstash alert"  
to =\> "xxxx"  
via =\> "smtp"  
body =\> "Here is the event line that occured:{message}"  
}  
}

```
stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2020, 5:28pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416/4 "2020-06-10T17:28:11Z")

</div>

If you are getting a 401 (unauthorized) error when connecting to elasticsearch then I suspect you need to set the user and password options on the output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2020, 5:34pm UTC](https://discuss.elastic.co/t/logstash-email-alerts/236416/5 "2020-07-08T17:34:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
