# Logstash Error Notification System

**URL:** <https://discuss.elastic.co/t/logstash-error-notification-system/176178>\
**Category:** Logstash\
**Created:** [April 10, 2019, 8:55am UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178 "2019-04-10T08:55:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![muratcelebiler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muratcelebiler/32/43845_2.png) [@muratcelebiler](https://discuss.elastic.co/u/muratcelebiler)\
**Post date:** [April 10, 2019, 8:55am UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/1 "2019-04-10T08:55:38Z")

</div>

Hello Guys;  
I have to sending data with RabbitMQ-Logstash-Elasticsearch tree. I would like watch to the logstash's errors and if logstash has a error then I want send notification to me (slack or etc.). What do I configure system(rabbitmq or logstash or elasticsearch yml file)?  
For example below warning

 ![2019-04-10%2011_52_01-Termius%20-%20Elasticsearch%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61c38b7e6c1fbce4a06668cb30c34b24b89ca6b2.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2019, 11:48am UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/2 "2019-04-10T11:48:01Z")

</div>

You could use filebeat or a logstash file input to consume the logstash log, and there exists a [slack](https://github.com/logstash-plugins/logstash-output-slack) output that you could use. It sounds doable.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [April 10, 2019, 2:39pm UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/3 "2019-04-10T14:39:05Z")

</div>

@muratcelebiler, do you have any other monitoring tools running on the machine where Logstash runs? I use Sensu (similar to Nagios) and I have checks in place to find the Logstash logs for errors and also a check that checks the Logstash [Monitoring API](https://www.elastic.co/guide/en/logstash/6.7/monitoring.html) health.

What Badger suggested should also work.

---

<div class="post-metadata">

**Author:** ![muratcelebiler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muratcelebiler/32/43845_2.png) [@muratcelebiler](https://discuss.elastic.co/u/muratcelebiler)\
**Post date:** [April 10, 2019, 3:18pm UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/4 "2019-04-10T15:18:12Z")

</div>

@A_B use Kibana for monitoring. But we would like notifications. Because we can't look at the monitor every time 🙂

---

<div class="post-metadata">

**Author:** ![muratcelebiler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muratcelebiler/32/43845_2.png) [@muratcelebiler](https://discuss.elastic.co/u/muratcelebiler)\
**Post date:** [April 10, 2019, 3:22pm UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/5 "2019-04-10T15:22:34Z")

</div>

@Badger I can't work the logstash's plugin. Filebeat sounds good. Don't anything with Logstash this case? (yml configuration or etc.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2019, 3:22pm UTC](https://discuss.elastic.co/t/logstash-error-notification-system/176178/6 "2019-05-08T15:22:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
