Create a TLS certificate ruleedit

Within the Uptime app, you can create a rule that notifies you when one or more of your monitors has a TLS certificate expiring within a specified threshold, or when it exceeds an age limit.

  1. To access this page, go to ObservabilityUptime.
  2. At the top of the page, click Alerts and rulesCreate rule.
  3. Select TLS rule.
Conditionsedit

The threshold values for each condition are configurable on the Settings page.

You can specify the following thresholds for your rule.

Expiration threshold

The expiration threshold specifies when you are notified about certificates that are approaching expiration dates.

Age limit

The age threshold specifies when you are notified about certificates that have been valid for too long.

Let’s create a rule to check every 6 hours and notify us when any of the TLS certificates on sites we’re monitoring are close to expiring.

Monitor status rule
Action typesedit

Extend your rules by connecting them to actions that use the following supported built-in integrations. Actions are Kibana services or integrations with third-party systems that run as background tasks on the Kibana server when rule conditions are met.

You can configure action types on the Settings page.

Some connector types are paid commercial features, while others are free. For a comparison of the Elastic subscription levels, go to the subscription page.

After you select a connector, you must set the action frequency. You can choose to create a summary of alerts on each check interval or on a custom interval. Alternatively, you can set the action frequency such that you choose how often the action runs (for example, at each check interval, only when the alert status changes, or at a custom action interval). In this case, you must also select the specific threshold condition that affects when actions run: Uptime TLS Alert or Recovered. For example, send a notification when an alert status changes:

Configure when a rule is triggered

In this example, actions are not repeated when an alert remains active across checks. Actions run only when the alert status changes.

Action variablesedit

Use the default notification message or customize it. You can add more context to the message by clicking the icon above the message text box and selecting from a list of available variables.

Default notification message for TLS rules with open "Add variable" popup listing available action variables
Alert recoveryedit

To receive a notification when the alert recovers, select Run when Recovered. Use the default notification message or customize it. You can add more context to the message by clicking the icon above the message text box and selecting from a list of available variables.

Default recovery message for TLS certificate rules with open "Add variable" popup listing available action variables