# Observability logs - Alert log stoppage

**URL:** <https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414>\
**Category:** Logs\
**Tags:** elastic-stack-alerting\
**Created:** [August 13, 2021, 10:46pm UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414 "2021-08-13T22:46:35Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [August 13, 2021, 10:46pm UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/1 "2021-08-13T22:46:35Z")

</div>

Hello,

I am able to create log stoppage alert using threshold alert type in logs-ovservability.

Is there any way to add multiple index names in this observalibilty-logs settings?, so that I can create multiple alerts for log stoppage on each servers/devices in specific index.

Now I am able to add only one index.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 16, 2021, 9:24am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/2 "2021-08-16T09:24:00Z")

</div>

Hi @jancodenew,

currently the log threshold alerts are coupled to the Logs UI configuration in the active space. So within the same space there there unfortunately is no easy way to achieve that. As a workaround you could create additional spaces, configure the Logs UI to target different indices and create alerts in them.

Alternatively, maybe the more generic query threshold alert available from the "Stack Management" / "Rules and Connectors" UI can give you more flexibility within one space?

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [August 16, 2021, 9:35am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/3 "2021-08-16T09:35:17Z")

</div>

Thank you @weltenwort for your reply.

Sorry, I didn't understand the workaround mentioned by you. what do you meant by create additional spaces, configure the Logs UI to target different indices and create alerts in them?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 16, 2021, 9:45am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/4 "2021-08-16T09:45:35Z")

</div>

Kibana has the concept of "spaces", which are separate workspaces for Kibana entities like visualizations and dashboards. You can manage them via the corresponding Stack Management page:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8fcaabb1d49d9e465c207d761b9ecd523d462e1.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea526632f4bb9a7b83b4c78caa4fee417dec7614.png)

The alerts use the Logs UI settings from the space they are created in. So if you configure the Logs UI to target different indices in different spaces, the alerts created in the respective spaces will also target these indices:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46e68678834a67b94ab9dff2f50df35ecc6842d8.png)

The alternative I mentioned was to use an "Elasticsearch query" alert with a "below 1" threshold:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/e/cee5ee62139dd64026374044bf27f0fc4f4f7c73.png)

Hope that helps a bit 😬

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [August 16, 2021, 10:00am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/5 "2021-08-16T10:00:26Z")

</div>

@weltenwort Yea that really helps a lot.  
I have one more query for a clarification. I have more than 60 indices in the current ELK SIEM setup. Is it ok to create 60 spaces to handle this ?  
Will that make a impact to the platform?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 16, 2021, 10:22am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/6 "2021-08-16T10:22:36Z")

</div>

Not 100% sure, but intuitively I wouldn't expect that. A space is just a "passive" concept to partition Kibana entities so there shouldn't be a difference between 60 alerts in one space or one alert in 60 spaces each.

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [August 18, 2021, 6:40am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/7 "2021-08-18T06:40:47Z")

</div>

Hi @weltenwort

I have tried creating the log stoppage alert with the second option which you have mentioned("Elasticsearch query" alert with a "below 1" threshold).

Could you please share a sample query here to group by host.hostname in Elasticsearch query?

Log stoppage alert Rule Logic: Log stoppage for last 15min from each hostname should be triggered.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 18, 2021, 9:09am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/8 "2021-08-18T09:09:33Z")

</div>

That is not possible with the "Elasticsearch query". In general, alerting for missing log data on dynamic groups is problematic. How would the alert know that a host exists if it is not sending data?

The Logs Threshold performs some dirty tricks to work around that by looking at a larger time range to determine the groups, but then evaluate the conditions for a smaller time window. This is at the cost of performance, of course.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2021, 9:09am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414/9 "2021-09-15T09:09:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
