# Slack Integration with ELK stack

**URL:** <https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657>\
**Category:** Elasticsearch\
**Created:** [August 11, 2023, 4:40pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657 "2023-08-11T16:40:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 11, 2023, 4:40pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/1 "2023-08-11T16:40:40Z")

</div>

Hi

I have installed the ELK Stack 8.9.0 in AWS Ubuntu Instance. I was configured the elk stack and it's working fine. So, I want to integrate the slack with elk stack and send the alert to slack channel if any 500 status code occurs in the apache logs.

I configured the filebeat in apache server and enabled and configured the apache module.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 16, 2023, 4:26pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/2 "2023-08-16T16:26:58Z")

</div>

Hi experts,

Can anyone let me know regarding the slack configuration. I was running my elk stack in EC2 instance.

I tried to add the below code to` kibana.yml` for adding the slack connector as per the document, but it's not working..

```auto
xpack.actions.preconfigured:
  my-slack:
    name: preconfigured-slack-webhook-connector-type
    actionTypeId: .slack
    secrets:
      webhookUrl: 'https://hooks.slack.com/services/xxxx/xxxx/xxxx'

```

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 25, 2023, 6:16pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/3 "2023-08-25T18:16:55Z")

</div>

Hi

Is anyone configured like this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 25, 2023, 6:30pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/4 "2023-08-25T18:30:29Z")

</div>

> [@sanjeev1895](#):
>
> I tried to add the below code to` kibana.yml` for adding the slack connector as per the document, but it's not working..

Do you have any error? What do you have in Kibana logs? What is not working?

Also, do you have a paid license? The Slack webhook needs a paid license.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 25, 2023, 6:50pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/5 "2023-08-25T18:50:50Z")

</div>

Yes, I have the logs in kibana. My apache, haproxy, cakephp and other services logs are maintaining in kibana. The flow is filebeat-logstash-elasticsearch-kibana.  
This is working fine.  
What i need is i want to integrate the my slack webhook with this. So that i can receive the alert.  
Am i configured the elk stack in aws ec2 ubuntu instance.  
I don't have any license for elk stack.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 25, 2023, 6:55pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/6 "2023-08-25T18:55:11Z")

</div>

> [@sanjeev1895](#):
>
> What i need is i want to integrate the my slack webhook with this. So that i can receive the alert.  
> Am i configured the elk stack in aws ec2 ubuntu instance.  
> I don't have any license for elk stack.

The webhook won't work on the Basic Free license.

The only [connectors](https://www.elastic.co/guide/en/kibana/current/action-types.html#action-types) that work with the Basic Free license are the [index connector](https://www.elastic.co/guide/en/kibana/current/index-action-type.html) and the [server log connector](https://www.elastic.co/guide/en/kibana/current/server-log-action-type.html).

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 25, 2023, 6:58pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/7 "2023-08-25T18:58:51Z")

</div>

Okay. Actually In my 1st post i followed the official document to add the slack connector. But it's not working.

Can you please tell me how to add the slack connector and where to add this.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 25, 2023, 7:54pm UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/8 "2023-08-25T19:54:47Z")

</div>

> [@sanjeev1895](#):
>
> Can you please tell me how to add the slack connector and where to add this.

There is not much to configure besides what you already did, it is exactly as explained in the [documentation](https://www.elastic.co/guide/en/kibana/current/slack-action-type.html), you just need to change the value of the `webhookUrl`.

But as already mentioned this connector needs a **paid** license, it won't work without it.

If you do not have a **paid** license you nee to be using the _trial_ license, which has a duration of 30 days, if you want to test it.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 26, 2023, 1:05am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/9 "2023-08-26T01:05:56Z")

</div>

Okay. Thank you so much for the response.

---

<div class="post-metadata">

**Author:** ![sanjeev1895](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Post date:** [August 26, 2023, 1:41am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/10 "2023-08-26T01:41:16Z")

</div>

@leandrojmp

Can you clarify this one doubt, Am I running this elk stack in my aws ec2 Ubuntu as a on-premise. I didn't used any elk stack cloud.

So is on-premise also have the paid license. If yes, could you please share the on-premise setup with license documentation.

Thanks.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 26, 2023, 2:02am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/11 "2023-08-26T02:02:40Z")

</div>

License is paid you would need to [contact sales](https://www.elastic.co/contact)

You can try a 30 Day Trial

Kibana - Stack Management - License  
And enable the Trial License

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2023, 2:03am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657/12 "2023-09-23T02:03:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
