# Set system to maintenance in Hearbeat

**URL:** <https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526>\
**Category:** Beats\
**Tags:** heartbeat\
**Created:** [March 29, 2019, 11:40am UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526 "2019-03-29T11:40:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [March 29, 2019, 11:40am UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526/1 "2019-03-29T11:40:10Z")

</div>

Before Heartbeat was GA, I already set up a Logstash pipeline to monitor our application's HTTP endpoint for uptime/downtime/errors/...

I would like to switch to Hearbeat now, so I can also easily monitor the system on other levels (webserver/appserver/db/...) as well. However I don't see a way to implement one feature I use in my current Logstash pipeline: I can set a field called "maintenance" to true or false, to differentiate between planned downtimes (marked blue in our dashboard) and unplanned outages (red).

My current Logstash filter (simplified):

```auto
    ruby {
      code => 'event.set("maintenance", File.exists?("/tmp/"+event.get("[@metadata][name]")+"_maint"))'
    }

```

When I want to set a system to maintenance, e.g. our PROD environment, I just create a file /tmp/prod\_maint (`touch /tmp/prod_maint`), and remove it afterwards (`rm /tmp/prod_maint`). This is easy to do with various tools, and gives me great flexibility.

I don't think I can add this with a [simple processor](https://www.elastic.co/guide/en/beats/heartbeat/current/defining-processors.html), as those don't allow checking for files.

Does anyone have a good idea on how to do that?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 8, 2019, 8:27am UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526/2 "2019-04-08T08:27:57Z")

</div>

@BennyInc Sorry for the late answer. I think this is an interesting feature request. Could you open an issue for it on Github? [https://github.com/elastic/uptime](https://github.com/elastic/uptime)

Note: I linked the uptime repository instead of Beats as I'm thinking this could potentially also be a UI feature.

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [April 8, 2019, 12:25pm UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526/3 "2019-04-08T12:25:04Z")

</div>

I posted it here: [https://github.com/elastic/uptime/issues/17](https://github.com/elastic/uptime/issues/17)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [April 8, 2019, 12:38pm UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526/4 "2019-04-08T12:38:34Z")

</div>

Thanks 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 12:45pm UTC](https://discuss.elastic.co/t/set-system-to-maintenance-in-hearbeat/174526/5 "2019-05-06T12:45:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
