# Notify if Index Has 0 Logs in X Minutes

**URL:** <https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181>\
**Category:** Logs\
**Created:** [April 11, 2024, 4:08am UTC](https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181 "2024-04-11T04:08:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![SomeRobot](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Post date:** [April 11, 2024, 4:08am UTC](https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181/1 "2024-04-11T04:08:25Z")

</div>

We have many indexes, and are consistently adding more to our cluster. We need to know when an index doesn't receive any documents in X number of minutes. For instance, if logs-foo hasn't received any documents in 1 hour, we want an alert to fire. Or if logs-bar hasn't received a document in 1 hour, fire an alert. The issue is we can set a watcher for this for each individual index, but not a generic catch-all. This is not scalable if we have to create a watcher for each index. Is there no way to create a watcher rule that looks at all indexes, and if there has been 0 documents ingested in X minutes in any one index, fire an alert specifying which index has not received documents?

---

<div class="post-metadata">

**Author:** ![abdulz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdulz/32/97601_2.png) [@abdulz](https://discuss.elastic.co/u/abdulz)\
**Post date:** [April 29, 2024, 9:10pm UTC](https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181/2 "2024-04-29T21:10:57Z")

</div>

Hi @SomeRobot ,

Are you using the [Logs Threshold Rule](https://www.elastic.co/guide/en/observability/current/logs-threshold-alert.html) to setup alerts? It, in its default configuration covers the whole `logs-*` pattern while also allowing you to change it to your own defined data view.
