# Monitor logs and create alert

**URL:** <https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495>\
**Category:** Kibana\
**Created:** [April 15, 2022, 9:45am UTC](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495 "2022-04-15T09:45:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bdaniel7](https://avatars.discourse-cdn.com/v4/letter/b/439d5e/32.png) [@bdaniel7](https://discuss.elastic.co/u/bdaniel7)\
**Post date:** [April 15, 2022, 9:45am UTC](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495/1 "2022-04-15T09:45:34Z")

</div>

Hi,

Is there a way to monitor incoming logs (from fluent-bit, in my case) and trigger an alert when specific keywords appear in logs?

I'm just beginning to use the ELK stack, so forgive me if I say silly things.

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [April 15, 2022, 10:04am UTC](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495/2 "2022-04-15T10:04:52Z")

</div>

Hi @bdaniel7

Welcome

First you need to get the logs a Data Shipper like Beats or Elastic-Agent and the parse it if needed (more complex parsing can be dine via Logstash)

Once the logs are in Elasticsearch you can use the Watcher for Alerting, is the simple answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2022, 10:05am UTC](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495/3 "2022-05-13T10:05:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
