# Send email alerts if log level == ERROR in more than one index

**URL:** <https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [October 2, 2021, 6:59pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750 "2021-10-02T18:59:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chandrakant\_Naik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandrakant_naik/32/79430_2.png) [@Chandrakant\_Naik](https://discuss.elastic.co/u/Chandrakant_Naik)\
**Post date:** [October 2, 2021, 6:59pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/1 "2021-10-02T18:59:24Z")

</div>

i have ingested python logs in Elasticsearch. Sample of my logs given below

```auto
[2021-10-01 23:54:39,752] [INFO] [run][MainThread] [xxxxxxxxx] [function_name:line no] : updating user request mapping for the request xxxxxxx
[2021-10-01 23:54:50,021] [ERROR] [run][request_thread] [xxxxxxxxx] [function_name:line no] : Exception occurred.
 stacktrace...
 ......

```

When my logs contain log level == ERROR i want to send a mail to the pdl with the error adn stacktrace.

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [October 7, 2021, 3:14pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/2 "2021-10-07T15:14:14Z")

</div>

Hi @Chandrakant_Naik,

This sounds like a great use case for the logs threshold rule: [Create a logs threshold rule | Observability Guide [master] | Elastic](https://www.elastic.co/guide/en/observability/master/logs-threshold-alert.html). You can create this rule and then attach an email action to the rule in order to be notified.

Thanks,

---

<div class="post-metadata">

**Author:** ![Chandrakant\_Naik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandrakant_naik/32/79430_2.png) [@Chandrakant\_Naik](https://discuss.elastic.co/u/Chandrakant_Naik)\
**Post date:** [October 10, 2021, 3:46pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/3 "2021-10-10T15:46:12Z")

</div>

i'm runnign kibana on my localhost:5601, unable to access alerts, it says u need to enable TLS and i'm unable to do it.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 10, 2021, 4:30pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/4 "2021-10-10T16:30:08Z")

</div>

Well you will either need to enable Security/ TLS to use alerts or perhaps a very small Elastic Cloud instance. Alerting feature requires Security / TLS to be setup up.

[https://cloud.elasti.co](https://cloud.elasti.co)

I wrote a step-by-step How To to secure a single Elasticsearch / Kibana on a single host, it should take you about 15 minutes

See [Here](https://github.com/bvader/howtos/blob/master/basic-security-elasticsearch/README.md)

---

<div class="post-metadata">

**Author:** ![Chandrakant\_Naik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandrakant_naik/32/79430_2.png) [@Chandrakant\_Naik](https://discuss.elastic.co/u/Chandrakant_Naik)\
**Post date:** [October 10, 2021, 7:39pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/5 "2021-10-10T19:39:11Z")

</div>

Without using the cloud instance, how do i enable Security/TLS in my localhost.. is there any write up on that. Under config folder i have the .p12 file and have enabled following configurations in Elasticsearch.yml file

```auto
discovery.type: single-node

# Enable security
xpack.security.enabled: true

# Enable auditing if you want, uncomment
# xpack.security.audit.enabled: true

# SSL Settings
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elastic-stack-ca.p12
xpack.security.http.ssl.truststore.path: elastic-stack-ca.p12

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-stack-ca.p12
xpack.security.transport.ssl.truststore.path: elastic-stack-ca.p12

```

Post all this, i restarted Elasticsearch it just got stuck and it gives me following mesage -  
`recieved plaintext http traffic on an https channel`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 10, 2021, 10:04pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/6 "2021-10-10T22:04:52Z")

</div>

In the post above I provided a link to a step by step instructions.

> [@stephenb](#):
>
> I wrote a step-by-step How To to secure a single Elasticsearch / Kibana on a single host, it should take you about 15 minutes
> 
> See [https://github.com/bvader/howtos/blob/master/basic-security-elasticsearch/README.md](https://github.com/bvader/howtos/blob/master/basic-security-elasticsearch/README.md)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2021, 10:05pm UTC](https://discuss.elastic.co/t/send-email-alerts-if-log-level-error-in-more-than-one-index/285750/7 "2021-11-07T22:05:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
