# Not able to configure Alerts in Kibana

**URL:** https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [May 31, 2021, 4:12pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533 "2021-05-31T16:12:20Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 4:12pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/1 "2021-05-31T16:12:20Z")

</div>

Hi, I'm using a docker compose file for ELK setup and using the latest version (above 7) for kibana. Now I set the **xpack.encryptedSavedObjects.encryptionKey** parameter in the kibana.yml so that i can use the alert and actions feature. But even after that I'm not able to create alert. Can anyone help me please?

 ![Screenshot (112)](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4ac142c682434f93a6084ec382fae8e16d5141c4.png)

PS. I genertaed the 32 character encryption key using python uuid module

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 4:54pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/2 "2021-05-31T16:54:48Z")

</div>

Hi @Akanksha_Pandey Welcome to the community

Exactly which version of Kibana are you using? I ask because the image above is not a very recent version. The version can be found on the Stack Management home screen.

Also I assume you restarted Kibana after you made the change, and you shift reloaded the Kibana App in the browser.

Just FYI, In newer / lastest versions enabling security / TLS is required to use Kibana Alerts.

It is still OK to use some of these older versions... but if you are interested in Kibana alerts **a lot** of new capabilities have been added since they were Beta.

The current version of the Elastic Stack is 7.13.0

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 5:48pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/3 "2021-05-31T17:48:55Z")

</div>

Hi @stephenb Thanks for responding.

My Kibana version is 7.9.2

Yes, I restarted Kibana after making the changes and reloaded the Kibana App in the browser as well.

Please tell me what should I do/what I'm doing wrong. It's very urgent

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 5:54pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/4 "2021-05-31T17:54:00Z")

</div>

Can you share your `kibana.yml`

Just as a reminder this is a volunteer forum, so there is no gauruntee of any / or a timely answer.

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 5:59pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/5 "2021-05-31T17:59:07Z")

</div>

sure. Here, I have removed elasticsearch username, password, encryption key due to security purpose.

 ![Screenshot (114)](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0364bdf6e30d1a052e9fc08d5ca082efa0ccc27.png)

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 6:08pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/6 "2021-05-31T18:08:25Z")

</div>

In the future please don't paste screenshots as they are hard to read and cannot be searched on, and do not show up on all devices.

Plus I cannot tell if that's the whole file.

It looks correct assuming you put the encryption key back in.

Did you restart elasticsearch as well?

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:10pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/7 "2021-05-31T18:10:58Z")

</div>

Sorry for the inconvenience.

Yes, I restarted elastic search as well and encryption key was also present.

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:11pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/8 "2021-05-31T18:11:32Z")

</div>

And this is the whole kibana.yml file

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 6:22pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/9 "2021-05-31T18:22:34Z")

</div>

Hmmmm then there is something else going on as I just took a fresh 7.9.2 stack and only added this line and it came up fine. And Alerts are allowed.

`xpack.encryptedSavedObjects.encryptionKey: "asdflkjs-asds-sadf-sadf-sadfasdfsadf"`

Seems like your perhaps docker compose is perhaps not picking up the latest `kibana.yml`

Here is my compose how I do it.

```
---
version: '3'
services:
  elasticsearch:
    container_name: es01
    image: docker.elastic.co/elasticsearch/elasticsearch:${TAG}
    environment: ['ES_JAVA_OPTS=-Xms2g -Xmx2g','bootstrap.memory_lock=true','discovery.type=single-node']
    ports:
      - 9200:9200
    networks:
      - elastic
    ulimits:
      memlock:
        soft: -1
        hard: -1
      nofile:
        soft: 65536
        hard: 65536

  kibana:
    image: docker.elastic.co/kibana/kibana:${TAG}
    container_name: kib01
    environment:
      XPACK_APM_SERVICEMAPENABLED: "true"
      XPACK_ENCRYPTEDSAVEDOBJECTS_ENCRYPTIONKEY: aslkdjfhs-sdfsd-safd-sffd-sdfsadffsafdsdf
    ports:
      - 5601:5601
    networks:
      - elastic

networks:
  elastic:
```

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:35pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/10 "2021-05-31T18:35:06Z")

</div>

I added the encryption key in docker-compose.yaml file but it still didn't work

```auto
services: 
  elasticsearch: 
    build:
      context: elasticsearch/
    container_name: elasticsearch
    volumes:
      - type: bind
        source: ./elasticsearch/conf/elasticsearch.yml
        target: /usr/share/elasticsearch/conf/elasticsearch.yml
        read_only: true
      - type: volume
        source: elasticsearch
        target: /usr/share/elasticsearch/data
    ports:
      - "9200:9200"
    environment:
      ES_JAVA_OPTS: "-Xmx2g -Xms2g"
      ELASTIC_PASSWORD: 
      ELASTIC_USERNAME : 
      # Use single node discovery in order to disable production mode and avoid bootstrap checks.
      # see: https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html
      discovery.type: single-node
    networks:
      - elastic
    restart: always
  
  logstash:
    container_name: logstash
    build: 
      context: logstash/
    # command: logstash -f /conf/logstash.conf
    volumes:
      - type: bind
        source: ./logstash/conf/logstash.yml
        target: /usr/share/logstash/conf/logstash.yml
        read_only: true
      - type: bind
        source: ./logstash/pipeline
        target: /usr/share/logstash/pipeline
        read_only: true
    ports:
     - "5043:5043"
     - "5044:5044"
    environment:
      LS_JAVA_OPTS: "-Xmx1g -Xms1g"
    networks:
      - elastic
    depends_on:
     - elasticsearch
    restart: always

  kibana:
    build:
      context: kibana/
    container_name: 
    environment:
      XPACK_APM_SERVICEMAPENABLED: "true"
      XPACK_ENCRYPTEDSAVEDOBJECTS_ENCRYPTIONKEY: " "
    volumes:
      - type: bind
        source: ./kibana/conf/kibana.yml
        target: /usr/share/kibana/conf/kibana.yml
        read_only: true
    ports:
      - "5601:5601"
    networks:
        - elastic
    depends_on:
      - elasticsearch
    restart: always

```

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:37pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/11 "2021-05-31T18:37:58Z")

</div>

Is there any other way to add the encryption key- maybe using the devtools in the Kibana app?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 6:40pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/12 "2021-05-31T18:40:15Z")

</div>

With your docker compose are you using `start / stop` or `up / down`

Try bring `down` then `up` **(You will lose your DATA)**

You are doing this right... you have something else going on.

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:43pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/13 "2021-05-31T18:43:44Z")

</div>

I'm using this command: docker-compose up --build

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:44pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/14 "2021-05-31T18:44:56Z")

</div>

This is a production server. If I bring it down- data will be lost

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 6:47pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/15 "2021-05-31T18:47:53Z")

</div>

Should I try this: `docker-compose stop` and then start the container?

I used Ctrl-C to stop the container and started by using this command: `docker-compose up --build `

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 6:50pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/16 "2021-05-31T18:50:34Z")

</div>

`docker-compose down`  
This will destroy the containers  
then wait  
`docker-compose up`  
This will re-create them.

`up` = Create  
`down` = Destroy  
`start` = Start  
`stop` = Stop

The typical sequence is to do `up`

Then you can stop with a control c

Then you can use `stop` and `start` as many times as you want

Then you use `down` to destroy the container when you're done

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [May 31, 2021, 7:02pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/17 "2021-05-31T19:02:15Z")

</div>

How to bring down the 3 containers (kibana, logstash, elasticsearch) using docker-compose down? And there are other conatiners as well running on the server. Will they be also stopped?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 7:05pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/18 "2021-05-31T19:05:14Z")

</div>

I don't know your entire docker architecture / infrastructure

Perhaps you need to read more about docker, I'm not a docker expert.

I use

`docker-compose -f my-compose.yml [up, down,start, stop]`

I can't really comment on the other containers etc if you use the `-f` option it should apply just that docker compose

If you want new containers you need to use `down`

My suspicion when you're just using `stop` and `start` it's not picking up the new settings because the container is already built.

Or yes you can rebuild it I think but but the settings are not part of that so I think just `down` then `up` should work

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 31, 2021, 9:31pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/19 "2021-05-31T21:31:03Z")

</div>

@Akanksha_Pandey  
BTW I was just working on another issues and for me confirmed the settings did not get picked up unless destroyed the container and recreated it i.e.  
`docker-compose down`  
then  
`docker-compose up`

---

<div class="post-metadata">

### Author: ![Akanksha\_Pandey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akanksha_pandey/32/89539_2.png) [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)
#### Post date: [June 1, 2021, 5:00pm UTC](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533/20 "2021-06-01T17:00:22Z")

</div>

@stephenb Sorry for the late response as my limit to send messages here was exceeded. I was prompted to send the message after 22 hours

Yes, you are right. That was the actual issue. I'm able to create the alert when I put the encryption key in **docker-compose.yaml** file instead of kibana.yml. And recreated the container using `docker-compose up -d` then ` docker-compose up --build`

Thanks a lot! You saved me 🙂

[Next page](https://discuss.elastic.co/t/not-able-to-configure-alerts-in-kibana/274533.md?page=2)
