Alerting via Watcher

Get Notified So You Don't Miss A Thing

CPU usage is unexpectedly increasing. Application response time is spiking. 503 errors are skyrocketing. Elasticsearch indexing rate has plummeted. But you're on top of it before anyone notices because X-Pack keeps you in the know with the alerts you need.

Set your first alert with this X-Pack intro. Watch Video
New Know what alerts are firing and take actions faster than ever. Easily create, view and manage all of your alerts from a single UI.

Detect Changes in Your Data

The alerting features in X-Pack give you the full power of the Elasticsearch query language to identify changes in your data that are interesting to you.

In other words, if you can query something in Elasticsearch, you can alert on it. For instance, you can be notified when:


The same user logged in from 3 different locations within an hour, so you can proactively address possible intrusion attempts.


#YourProduct is trending on social media, and you need to prepare to meet the demand.

Bionic Leg

A component of a bionic leg is nearing its end of life and it's time to replace it so the six-million-dollar woman can keep running.

Credit Card

Credit card numbers are visible in your application logs and that's a compliance nightmare. It's time to talk with the application team.


Your Elasticsearch indexing rate has plummeted due to changes in your web server log file location, so you know to update your Filebeat configuration.

Go beyond rule-based alerting for the things that are harder to define using the machine learning features in X-Pack.

Get Notified, Your Way

How would you like to be notified? Pick from many alerting options with built-in integrations for email, PagerDuty, Slack, and HipChat. It also comes with a powerful webhook output for integration with your existing monitoring infrastructure or any third-party system.

It's also configurable to include relevant information from your search in the notification and ships with simple template support.

Manage and Monitor Your Alerts

Take control of your alerts, by viewing, creating, and managing all of them from a single UI. Stay in the know with real-time updates on which alerts are running and what actions were taken.

Learn from Your Alert History

X-Pack stores a complete history of all alert executions in Elasticsearch for easy tracking and visualization in Kibana. Are my alerts executing? How often are my conditions being met? What actions were taken? Your alert history also enables nested alerts.

Install Alerting for the Elastic Stack

Now, you try. Set your first alert and then wait for it...wait for it…