# Setting up alerts

**URL:** <https://discuss.elastic.co/t/setting-up-alerts/17840>\
**Category:** Elasticsearch\
**Created:** [May 31, 2014, 3:01am UTC](https://discuss.elastic.co/t/setting-up-alerts/17840 "2014-05-31T03:01:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joshua\_Hall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_hall/32/1448_2.png) [@Joshua\_Hall](https://discuss.elastic.co/u/Joshua_Hall)\
**Post date:** [May 31, 2014, 3:01am UTC](https://discuss.elastic.co/t/setting-up-alerts/17840/1 "2014-05-31T03:01:55Z")

</div>

I am working on a demo using Elasticsearch, Logstash, Kibana and one of the  
key features that I am looking for is the ability to setup alerts to send  
out emails.

Specifically I want to setup an alert to be emailed when a log is recorded  
with "severity=error" and "category=category1" occurs more than 20 times in  
15 minutes.

I am limited to a windows only solution so that may limit some things.

I have considered the following approaches

1. An app/service that simply does a search to get the number of results  
every minute or so
2. Doing something with logstash
3. Doing something with Percolator (Logstash or an app)

I really don't understand the percolator so I am not sure if it is even a  
viable approach for what doing this.

Is there any guide / general guidance for doing something similar to this?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [May 31, 2014, 6:18am UTC](https://discuss.elastic.co/t/setting-up-alerts/17840/2 "2014-05-31T06:18:25Z")

</div>

Hello Joshua ,

Percolater is the usual choice here.  
You can register queries against poercolator and when you index some feed ,  
the peorcolater informs you that such a search query matches against your  
index.  
This information is passed when indexing.

With logstash , I am not sure how this can be done.

Thanks  
Vineeth

On Sat, May 31, 2014 at 8:31 AM, Joshua Hall [joshuadeanhall@gmail.com](mailto:joshuadeanhall@gmail.com)  
wrote:

> I am working on a demo using Elasticsearch, Logstash, Kibana and one of  
> the key features that I am looking for is the ability to setup alerts to  
> send out emails.
> 
> Specifically I want to setup an alert to be emailed when a log is recorded  
> with "severity=error" and "category=category1" occurs more than 20 times in  
> 15 minutes.
> 
> I am limited to a windows only solution so that may limit some things.
> 
> I have considered the following approaches
> 
> 1. An app/service that simply does a search to get the number of  
> results every minute or so
> 2. Doing something with logstash
> 3. Doing something with Percolator (Logstash or an app)
> 
> I really don't understand the percolator so I am not sure if it is even a  
> viable approach for what doing this.
> 
> Is there any guide / general guidance for doing something similar to this?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5%3D3dP5FcLHDevgZeOmYsAhvReUAQPLm1Nh\_651a0Kjt1Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5%3D3dP5FcLHDevgZeOmYsAhvReUAQPLm1Nh_651a0Kjt1Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Joshua\_Hall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_hall/32/1448_2.png) [@Joshua\_Hall](https://discuss.elastic.co/u/Joshua_Hall)\
**Post date:** [May 31, 2014, 5:11pm UTC](https://discuss.elastic.co/t/setting-up-alerts/17840/3 "2014-05-31T17:11:20Z")

</div>

Vinneth thanks for your response.

I guess I don't understand how the percolater works. I get that you store  
a query, In my case I think I would want to store a query that looks at the  
fields I want for a specific value over the last timeperiod.

Does the percolater actually attach to an index and run against all new  
documents added to the index?

When I look at the documentation and see this I get very confused

curl -XGET 'localhost:9200/my-index/message/\_percolate' -d '{  
"doc" : {  
"message" : "A new bonsai tree in the office"  
}  
}'

To me this looks like asking the percolator if this message matches a  
percolator, but what I want to know is the count of the number of documents  
added to an index in the last 15 minutes matches a percolator.

I would have expected to see something more similiar to

curl -XGET 'localhost:9200/index/type/\_percolate/count'

Hopefully this makes sense as I am very confused about how this works,  
looks to me like it is just a simple does this document match any of the  
predefined queries and what I think I am after is does any documents in  
this index match this predefined query.

On Saturday, May 31, 2014 2:18:33 AM UTC-4, vineeth mohan wrote:

> Hello Joshua ,
> 
> Percolater is the usual choice here.  
> You can register queries against poercolator and when you index some feed  
> , the peorcolater informs you that such a search query matches against your  
> index.  
> This information is passed when indexing.
> 
> With logstash , I am not sure how this can be done.
> 
> Thanks  
> Vineeth
> 
> On Sat, May 31, 2014 at 8:31 AM, Joshua Hall \<[joshuad...@gmail.com](mailto:joshuad...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > I am working on a demo using Elasticsearch, Logstash, Kibana and one of  
> > the key features that I am looking for is the ability to setup alerts to  
> > send out emails.
> > 
> > Specifically I want to setup an alert to be emailed when a log is  
> > recorded with "severity=error" and "category=category1" occurs more than 20  
> > times in 15 minutes.
> > 
> > I am limited to a windows only solution so that may limit some things.
> > 
> > I have considered the following approaches
> > 
> > 1. An app/service that simply does a search to get the number of  
> > results every minute or so
> > 2. Doing something with logstash
> > 3. Doing something with Percolator (Logstash or an app)
> > 
> > I really don't understand the percolator so I am not sure if it is even a  
> > viable approach for what doing this.
> > 
> > Is there any guide / general guidance for doing something similar to this?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [June 3, 2014, 6:11pm UTC](https://discuss.elastic.co/t/setting-up-alerts/17840/4 "2014-06-03T18:11:36Z")

</div>

With logstash, you can use either the email or pagerduty outputs. You can  
setup a conditional for your specific log entries.

> **[Email output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-email.html)**

> **[Pagerduty output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-pagerduty.html)**

--  
Ivan

On Sat, May 31, 2014 at 10:11 AM, Joshua Hall [joshuadeanhall@gmail.com](mailto:joshuadeanhall@gmail.com)  
wrote:

> Vinneth thanks for your response.
> 
> I guess I don't understand how the percolater works. I get that you store  
> a query, In my case I think I would want to store a query that looks at the  
> fields I want for a specific value over the last timeperiod.
> 
> Does the percolater actually attach to an index and run against all new  
> documents added to the index?
> 
> When I look at the documentation and see this I get very confused
> 
> curl -XGET 'localhost:9200/my-index/message/\_percolate' -d '{  
> "doc" : {  
> "message" : "A new bonsai tree in the office"  
> }  
> }'
> 
> To me this looks like asking the percolator if this message matches a  
> percolator, but what I want to know is the count of the number of documents  
> added to an index in the last 15 minutes matches a percolator.
> 
> I would have expected to see something more similiar to
> 
> curl -XGET 'localhost:9200/index/type/\_percolate/count'
> 
> Hopefully this makes sense as I am very confused about how this works,  
> looks to me like it is just a simple does this document match any of the  
> predefined queries and what I think I am after is does any documents in  
> this index match this predefined query.
> 
> On Saturday, May 31, 2014 2:18:33 AM UTC-4, vineeth mohan wrote:
> 
> > Hello Joshua ,
> > 
> > Percolater is the usual choice here.  
> > You can register queries against poercolator and when you index some feed  
> > , the peorcolater informs you that such a search query matches against your  
> > index.  
> > This information is passed when indexing.
> > 
> > With logstash , I am not sure how this can be done.
> > 
> > Thanks  
> > Vineeth
> > 
> > On Sat, May 31, 2014 at 8:31 AM, Joshua Hall [joshuad...@gmail.com](mailto:joshuad...@gmail.com)  
> > wrote:
> > 
> > > I am working on a demo using Elasticsearch, Logstash, Kibana and one of  
> > > the key features that I am looking for is the ability to setup alerts to  
> > > send out emails.
> > > 
> > > Specifically I want to setup an alert to be emailed when a log is  
> > > recorded with "severity=error" and "category=category1" occurs more than 20  
> > > times in 15 minutes.
> > > 
> > > I am limited to a windows only solution so that may limit some things.
> > > 
> > > I have considered the following approaches
> > > 
> > > 1. An app/service that simply does a search to get the number of  
> > > results every minute or so
> > > 2. Doing something with logstash
> > > 3. Doing something with Percolator (Logstash or an app)
> > > 
> > > I really don't understand the percolator so I am not sure if it is even  
> > > a viable approach for what doing this.
> > > 
> > > Is there any guide / general guidance for doing something similar to  
> > > this?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/82b6748d-0de9-4de0-92f3-65fcaeb69d3d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/98e8ec88-7ef9-45e6-875b-e72f72a4731a%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQDCoV\_vpb9uT2F\_7Xzg%2ByMfgHx6qpkU6vqC6%2BAWcbL-ag%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQDCoV_vpb9uT2F_7Xzg%2ByMfgHx6qpkU6vqC6%2BAWcbL-ag%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:24am UTC](https://discuss.elastic.co/t/setting-up-alerts/17840/5 "2017-07-06T01:24:53Z")

</div>


