# Setup Elasticsearch SlowLog Alerts in Elastic Cloud

**URL:** <https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085>\
**Category:** Elastic Tips and Common Fixes\
**Created:** [September 1, 2021, 5:06pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085 "2021-09-01T17:06:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stef\_Nestor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stef_nestor/32/85483_2.png) [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Post date:** [September 1, 2021, 5:06pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085/1 "2021-09-01T17:06:18Z")

</div>

Is there a way to setup email alerts for SlowLogs in Elasticsearch on Elastic Cloud?

---

<div class="post-metadata">

**Author:** ![Stef\_Nestor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stef_nestor/32/85483_2.png) [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Post date:** [September 1, 2021, 5:07pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085/2 "2021-09-01T17:07:28Z")

</div>

1. Setup monitoring via our [blog: How to set up Elastic Cloud Advice from Elastic Support](https://www.elastic.co/blog/how-to-set-up-elastic-cloud-advice-from-elastic-support)

2. Enable [Slow Logs](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-slowlog.html). E.g. using `kibana_sample_data*`

3. (Wait for natural event to occur or) induce Slow Log

4. We can use these fields to generate a query filter to view only these logs:

5. Now, we'll go to create a [Kibana Alert](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html) of type [Elasticsearch query](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html) with our query. More info: [general rule details](https://www.elastic.co/guide/en/kibana/current/create-and-manage-rules.html#defining-rules-general-details). I'll just do an [index write](https://www.elastic.co/guide/en/kibana/current/index-action-type.html), but many customers point their [Actions](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html#_add_action_variables_2) to their [Email Connectors](https://www.elastic.co/guide/en/kibana/current/email-action-type.html).

6. Since our alert's marked `executionStatus.status:active`, we can check to see our test fired. Once confirmed we're good to go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2021, 5:08pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085/3 "2021-09-29T17:08:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![Stef\_Nestor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stef_nestor/32/85483_2.png) [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Post date:** [October 18, 2021, 4:38pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085/4 "2021-10-18T16:38:02Z")

</div>

If you want to do #5 via [Watcher](https://www.elastic.co/guide/en/elasticsearch/reference/current/how-watcher-works.html) to output the actual response body, local [executions](https://www.elastic.co/guide/en/elasticsearch/reference/current/watcher-api-execute-watch.html) would look something like

```auto
PUT _watcher/watch/_execute
{ "watch": {
  "trigger": {"schedule": {"interval": "1h"}},
  "input": { "search": { "request": {
    "search_type": "query_then_fetch",
    "indices": ["elastic-cloud-logs*"],
    "rest_total_hits_as_int": true,
    "body": {
      "query": { "bool": { "must": { "query_string": { "analyze_wildcard": true,
        "query": "event.dataset:elasticsearch.slowlog AND log.level:WARN"}},
        "filter": [{"range": {"@timestamp": {
          "gte": "now-1h",
          "lte": "now"}}}]}}}}}},
  "condition": {"compare": {"ctx.payload.hits.total": {"gt": 0 }}},
  "actions": { "log" : { "logging" : {
    "text" : """SlowLogs: {{#ctx.payload.hits.hits}} 
      message: {{_source.message}} 
      {{/ctx.payload.hits.hits}}""",
    "level": "warn"}}}}}

```
