# Near real time alerts for syslogs

**URL:** <https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160>\
**Category:** Elasticsearch\
**Created:** [May 29, 2013, 1:10am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160 "2013-05-29T01:10:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Palamara](https://avatars.discourse-cdn.com/v4/letter/r/ecc23a/32.png) [@Ryan\_Palamara](https://discuss.elastic.co/u/Ryan_Palamara)\
**Post date:** [May 29, 2013, 1:10am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/1 "2013-05-29T01:10:12Z")

</div>

I am using Elasticsearch combined with Logstash and Kibana for collecting  
log data from a number of different network devices. I just set it up in  
the past few days and so far it has been handling the load wonderfully. I  
would like to setup alerts for certain events that can be taken from the  
logs. Things like getting an alert after a certain amount of events in a  
time period or alerts for certain log events.

Now I am very new at this and have been searching through for some way to  
do this, but was hoping that someone could help point me in the right  
direction.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 29, 2013, 7:35am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/2 "2013-05-29T07:35:31Z")

</div>

I don't if you can do it with logstash, but from an Elasticsearch point of view, you should look at Percolator feature.  
It could help you to build alerting system based on prerecorded queries.

HTH

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 29 mai 2013 à 03:10, Ryan Palamara [ryan.palamara@gmail.com](mailto:ryan.palamara@gmail.com) a écrit :

> I am using Elasticsearch combined with Logstash and Kibana for collecting log data from a number of different network devices. I just set it up in the past few days and so far it has been handling the load wonderfully. I would like to setup alerts for certain events that can be taken from the logs. Things like getting an alert after a certain amount of events in a time period or alerts for certain log events.
> 
> ## Now I am very new at this and have been searching through for some way to do this, but was hoping that someone could help point me in the right direction.
> 
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Christophe\_Dontaine](https://avatars.discourse-cdn.com/v4/letter/c/5f9b8f/32.png) [@Christophe\_Dontaine](https://discuss.elastic.co/u/Christophe_Dontaine)\
**Post date:** [April 1, 2014, 10:48am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/3 "2014-04-01T10:48:24Z")

</div>

Hi David,

I have the same request but, as a new user of ES, I'm interested to know why the alerting process should be moved to the Logstash layer.

I'm thinking (on a white board for now) about a logstash layer (Log-\>ES) followed by an ES layer (index + alerting).  
I thought building requests via the percolate API to be able to centralize the alerting process instead of spanning the same "rules" on any logstash layer.

Is it so heavier in terms of CPU/IO/... on the ES layer side that you prefer move this on the Logstash layer ? Or because other reasons ?

Thanks in advance.

Christophe

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5e073c5a-7681-45db-a86d-cabefe2f4411%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5e073c5a-7681-45db-a86d-cabefe2f4411%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antoine\_Brun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antoine_brun/32/3774_2.png) [@Antoine\_Brun](https://discuss.elastic.co/u/Antoine_Brun)\
**Post date:** [April 2, 2014, 11:19am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/4 "2014-04-02T11:19:29Z")

</div>

Hello Ryan,

I am trying to build the same type of application (device log collecting)  
and I'm also very new to logstash and elasticsearch.  
I'm having a hard time setting up a lab environment that can sustain the  
load (2000 logs/sec, 1024ko logs) and only 60% of the logs are indexed (I  
count the number of lucene doucuments).

So maybe you can give me a few tips or advices on how you tuned you  
environment.

How do you start logstash? just with the script provided in the project?  
Are you using the syslog plugin to listen on port 514?  
How many elasticsearch nodes do you have?

I would really appreciate if you could take some time to share your  
experience on this.

Thank you,

Antoine Brun

Le mercredi 29 mai 2013 03:10:12 UTC+2, Ryan Palamara a écrit :

> I am using Elasticsearch combined with Logstash and Kibana for collecting  
> log data from a number of different network devices. I just set it up in  
> the past few days and so far it has been handling the load wonderfully. I  
> would like to setup alerts for certain events that can be taken from the  
> logs. Things like getting an alert after a certain amount of events in a  
> time period or alerts for certain log events.
> 
> Now I am very new at this and have been searching through for some way to  
> do this, but was hoping that someone could help point me in the right  
> direction.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/d4ca2099-86d2-4071-8359-565f902f390c%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d4ca2099-86d2-4071-8359-565f902f390c%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Lincoln\_Xiong](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@Lincoln\_Xiong](https://discuss.elastic.co/u/Lincoln_Xiong)\
**Post date:** [April 6, 2015, 5:42pm UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/5 "2015-04-06T17:42:47Z")

</div>

Did you find out any solution yet? I am at the same situation just like  
you. And one more important thing is I maybe will remove logstash from the  
stack in the future. So it will be idealy to get alerting system work with  
ES and Kibana (or any other plugins) only.

I found out a script running queries once period of time would work but  
this is not very neat. Percolator seems to act the part of this but I am  
still trying.

On Tuesday, May 28, 2013 at 9:10:12 PM UTC-4, Ryan Palamara wrote:

> I am using Elasticsearch combined with Logstash and Kibana for collecting  
> log data from a number of different network devices. I just set it up in  
> the past few days and so far it has been handling the load wonderfully. I  
> would like to setup alerts for certain events that can be taken from the  
> logs. Things like getting an alert after a certain amount of events in a  
> time period or alerts for certain log events.
> 
> Now I am very new at this and have been searching through for some way to  
> do this, but was hoping that someone could help point me in the right  
> direction.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/55f5a22d-ecb6-4464-ac54-a514a8641076%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/55f5a22d-ecb6-4464-ac54-a514a8641076%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Gabriel\_Rosca](https://avatars.discourse-cdn.com/v4/letter/g/e19adc/32.png) [@Gabriel\_Rosca](https://discuss.elastic.co/u/Gabriel_Rosca)\
**Post date:** [April 7, 2015, 12:33am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/6 "2015-04-07T00:33:21Z")

</div>

Take a look at logstash throttle plugin

> **[Throttle filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-throttle.html)**

Also you can use output to zabbix, nagios or email directly.

Regards,  
Gabriel

On Tuesday, May 28, 2013 at 9:10:12 PM UTC-4, Ryan Palamara wrote:

> I am using Elasticsearch combined with Logstash and Kibana for collecting  
> log data from a number of different network devices. I just set it up in  
> the past few days and so far it has been handling the load wonderfully. I  
> would like to setup alerts for certain events that can be taken from the  
> logs. Things like getting an alert after a certain amount of events in a  
> time period or alerts for certain log events.
> 
> Now I am very new at this and have been searching through for some way to  
> do this, but was hoping that someone could help point me in the right  
> direction.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/605da3a2-6a25-4340-a74d-1e0ec42cae99%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/605da3a2-6a25-4340-a74d-1e0ec42cae99%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Lincoln\_Xiong](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@Lincoln\_Xiong](https://discuss.elastic.co/u/Lincoln_Xiong)\
**Post date:** [April 7, 2015, 1:53pm UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/7 "2015-04-07T13:53:38Z")

</div>

Thanks for the tips, Gabriel! So the idea is not recommend to set alert at  
ES/Kibana side but on Logstash side?

On Monday, April 6, 2015 at 8:33:21 PM UTC-4, Gabriel Rosca wrote:

> Take a look at logstash throttle plugin
> 
> [Throttle filter plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/filters/throttle)
> 
> Also you can use output to zabbix, nagios or email directly.
> 
> Regards,  
> Gabriel
> 
> On Tuesday, May 28, 2013 at 9:10:12 PM UTC-4, Ryan Palamara wrote:
> 
> > I am using Elasticsearch combined with Logstash and Kibana for collecting  
> > log data from a number of different network devices. I just set it up in  
> > the past few days and so far it has been handling the load wonderfully. I  
> > would like to setup alerts for certain events that can be taken from the  
> > logs. Things like getting an alert after a certain amount of events in a  
> > time period or alerts for certain log events.
> > 
> > Now I am very new at this and have been searching through for some way to  
> > do this, but was hoping that someone could help point me in the right  
> > direction.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Gabriel\_Rosca](https://avatars.discourse-cdn.com/v4/letter/g/e19adc/32.png) [@Gabriel\_Rosca](https://discuss.elastic.co/u/Gabriel_Rosca)\
**Post date:** [April 7, 2015, 3:28pm UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/8 "2015-04-07T15:28:19Z")

</div>

Well,

Depends on your needs. I like to use LS for that to take advantage of  
Nagios and zabbix plugins and let the monitoring system start the  
escalations procedures and log the incident.

Regards,  
Gabriel

On Tue, Apr 7, 2015 at 9:53 AM, Lincoln Xiong [xiong.huanglin@gmail.com](mailto:xiong.huanglin@gmail.com)  
wrote:

> Thanks for the tips, Gabriel! So the idea is not recommend to set alert at  
> ES/Kibana side but on Logstash side?
> 
> On Monday, April 6, 2015 at 8:33:21 PM UTC-4, Gabriel Rosca wrote:
> 
> > Take a look at logstash throttle plugin
> > 
> > [Throttle filter plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/filters/throttle)
> > 
> > Also you can use output to zabbix, nagios or email directly.
> > 
> > Regards,  
> > Gabriel
> > 
> > On Tuesday, May 28, 2013 at 9:10:12 PM UTC-4, Ryan Palamara wrote:
> > 
> > > I am using Elasticsearch combined with Logstash and Kibana for  
> > > collecting log data from a number of different network devices. I just set  
> > > it up in the past few days and so far it has been handling the load  
> > > wonderfully. I would like to setup alerts for certain events that can be  
> > > taken from the logs. Things like getting an alert after a certain amount of  
> > > events in a time period or alerts for certain log events.
> > > 
> > > Now I am very new at this and have been searching through for some way  
> > > to do this, but was hoping that someone could help point me in the right  
> > > direction.
> > 
> > --  
> > You received this message because you are subscribed to a topic in the  
> > Google Groups "elasticsearch" group.  
> > To unsubscribe from this topic, visit  
> > [https://groups.google.com/d/topic/elasticsearch/9l59dNQIALk/unsubscribe](https://groups.google.com/d/topic/elasticsearch/9l59dNQIALk/unsubscribe).  
> > To unsubscribe from this group and all its topics, send an email to  
> > [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/08e506cb-a30c-4edf-9efc-02abb8ba90ed%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALtJ1PvguZDDYzf9%3DV%3DZC\_He%3DLohuTi6Xb-hT-Ggv7py2LmvEg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALtJ1PvguZDDYzf9%3DV%3DZC_He%3DLohuTi6Xb-hT-Ggv7py2LmvEg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:21am UTC](https://discuss.elastic.co/t/near-real-time-alerts-for-syslogs/12160/9 "2017-07-06T00:21:07Z")

</div>


