# Monitoring Oracle Alert log by using Logstash

**URL:** <https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889>\
**Category:** Logstash\
**Created:** [August 2, 2023, 6:57am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889 "2023-08-02T06:57:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Debasis\_Mallick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debasis_mallick/32/123723_2.png) [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Post date:** [August 2, 2023, 6:57am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889/1 "2023-08-02T06:57:17Z")

</div>

Hi Team,

We had one requirement to monitor oracle alert log by using ELK stack. Could someone guide me . In my environment ELK stack running with 8.x version.

Thanks,  
Debasis

---

<div class="post-metadata">

**Author:** ![Debasis\_Mallick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debasis_mallick/32/123723_2.png) [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Post date:** [August 3, 2023, 6:52am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889/2 "2023-08-03T06:52:41Z")

</div>

Hi Team,

Any one could you please help me with the above requirement.

Thanks,  
Debasis

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 3, 2023, 8:01am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889/3 "2023-08-03T08:01:45Z")

</div>

Hello Debasis,

i have only done a rudimentary parsing with an ingest-pipeline so you will have to convert this into a logstash pipeline yourself:

> <https://gist.github.com/Shaoranlaos/7c79a25a269c54bb227fcaeec2254376>

It can parse the alert and listener log of an oracle db. It will also add an "error" tag to the document if it detects an ORA or TNS error in the log.

I read the logs via a Fleet managed Elastic Agent and the Custom Logs Integration.

BR  
Christian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2023, 8:02am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889/4 "2023-08-31T08:02:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
