# Need help on Elastalert

**URL:** <https://discuss.elastic.co/t/need-help-on-elastalert/49295>\
**Category:** Elasticsearch\
**Created:** [May 5, 2016, 1:27pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295 "2016-05-05T13:27:52Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![vmankala](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vmankala](https://discuss.elastic.co/u/vmankala)\
**Post date:** [May 5, 2016, 1:27pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/1 "2016-05-05T13:27:52Z")

</div>

I have setup ELK environment. Installed filebeat on few servers and installed logstash on separate single server -10-192-4-253. I have setup Elastalert configuration in logstash server. Below is "/example\_frequency.yaml" at "/opt/logstash/python/elastalert" location

type: frequency  
index: logstash-\*  
num\_events: 50  
timeframe:  
hours: 4  
filter:

- term:  
type: "stdout"  
alert:
- "email"  
alert\_text: |  
"ElastAlert has detected suspicious activity for {0} \< b\>ElastAlert has detected suspicious activity for {0}\< /b\>"  
At {1}, an {2} error occured. Do something about it!

alert\_text\_args:

- email
- host
- type  
email:

In the alert mail I am also getting the json code as follow

"ElastAlert has detected suspicious activity for \< b\>ElastAlert has detected suspicious activity for \< /b\>"  
At ip-10-169-1-48.ec2.internal, an stdout error occured. Do something about it!

At least 50 events occurred between 2016-05-05 03:36 EDT and 2016-05-05 07:36 EDT

(following is json code)  
@timestamp: 2016-05-05T11:36:32.022Z  
@version: 1  
\_id: AVSAtIJ5Ydfq7dPgG\_SL  
\_index: logstash-2016.05.05  
\_type: stdout  
beat: {  
"hostname": "ip-10-169-1-48.ec2.internal",  
"name": "ip-10-169-1-48.ec2.internal"  
}  
count: 1  
fields: {  
"environment": "NA-DEV",  
"platform": "RSDMT"  
}  
host: ip-10-169-1-48.ec2.internal  
input\_type: log  
message: 07:36:29,391 |-INFO in ch.qos.logback.core.joran.action.AppenderAction - About to instantiate appender of type [ch.qos.logback.core.rolling.RollingFileAppender]  
offset: 510957  
source: /opt/tomcat/logs/stdout.log  
tags: [  
"beats\_input\_codec\_plain\_applied"  
]  
type: stdout

How do I need to omit above json code from alert mail. Please suggest.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 5, 2016, 10:59pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/2 "2016-05-05T22:59:51Z")

</div>

You will probably need to ask the authors directly, I don't believe they hang out on these forums.

---

<div class="post-metadata">

**Author:** ![vmankala](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vmankala](https://discuss.elastic.co/u/vmankala)\
**Post date:** [May 6, 2016, 6:03am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/3 "2016-05-06T06:03:46Z")

</div>

In which forum do I get help regarding elastalert. Or could you please let me know the right place to get help

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 6, 2016, 6:04am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/4 "2016-05-06T06:04:08Z")

</div>

Try their github repository?

---

<div class="post-metadata">

**Author:** ![vmankala](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vmankala](https://discuss.elastic.co/u/vmankala)\
**Post date:** [May 6, 2016, 6:06am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/5 "2016-05-06T06:06:47Z")

</div>

Ok, thankyou

---

<div class="post-metadata">

**Author:** ![vmankala](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vmankala](https://discuss.elastic.co/u/vmankala)\
**Post date:** [May 6, 2016, 7:43am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/6 "2016-05-06T07:43:12Z")

</div>

Just one more help.

Could you please let me know how to deal with below error message on logstash server

[root@ip-10-192-4-253 bin]# /opt/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf  
Settings: Default pipeline workers: 4  
An unexpected error occurred! {:error=\>#\<Errno::EADDRINUSE: Address already in use - bind - Address already in use\>, :class=\>"Errno::EADDRINUSE", :backtrace=\>["org/jruby/ext/socket/RubyTCPServer.java:118:in `initialize'", "org/jruby/RubyIO.java:853:in`new'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.7/lib/lumberjack/beats/server.rb:51:in `initialize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-beats-2.2.7/lib/logstash/inputs/beats.rb:119:in`register'",

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 6, 2016, 8:01am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/7 "2016-05-06T08:01:43Z")

</div>

> [@vmankala](#):
>
> EADDRINUSE

Whatever your config is trying to do, it looks like there is something else already using the address/port.

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [May 6, 2016, 11:27pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/8 "2016-05-06T23:27:01Z")

</div>

Try `use_count_query: true` in your rule, it should omit the json data from events.

---

<div class="post-metadata">

**Author:** ![vmankala](https://avatars.discourse-cdn.com/v4/letter/v/96bed5/32.png) [@vmankala](https://discuss.elastic.co/u/vmankala)\
**Post date:** [May 9, 2016, 8:10am UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/9 "2016-05-09T08:10:27Z")

</div>

thankyou 🙂  
it worked partially. I mean the JSON script is omitted but the email contents are not as expected. anyways i used "alert\_text\_type: alert\_text\_only" to solve it.

---

<div class="post-metadata">

**Author:** ![taurs](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@taurs](https://discuss.elastic.co/u/taurs)\
**Post date:** [March 5, 2017, 3:29pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/11 "2017-03-05T15:29:40Z")

</div>

Is it possible to send the data to Kafka Topic ? (the json message data to kafka topic)

The json data message to kafka topic using the rules configuration?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:02pm UTC](https://discuss.elastic.co/t/need-help-on-elastalert/49295/12 "2017-07-05T22:02:35Z")

</div>


