It only takes a few minutes to add an ElastAlert server to any of your Logit ELK stacks. Once enabled, you'll be able to edit and setup alerting rules for all your stacks.
Provision your ElastAlert server
When you login in your stacks are displayed on the dashboard. To enable alerts for a stack, choose the 'Settings' button.
Next, choose 'Alerts' and then click 'Provision ElastAlert for this stack'
Then create your ElastAlert rule
Use the code block below to quickly get started with your Slack alert.
name: Production App Errors
## Receive an alert for every single match
# The alert used when a match is found
## Live alerts channel
- “[YOUR SLACK HOOK]”
How to use the code
Paste the code into the alert replacing any existing rule.
Then just edit the code to match the filter query you need, in this case we are looking for matches on "type:error".
Replace [YOUR SLACK HOOK] with your slack hook url.
Choose test to run the rule against your data over the last 24hrs.
Once happy, choose update to apply and save the rule.
Now you're all set to send alerts to Slack from Logit!
Learn more about ElastAlert rules: if you'd like to learn more about ElastAlert rules from the people that built it, check out their cheat sheet.
Read Logit's Introduction to alerting
Learn how to send alerts to Email from your Logit stacks.
Learn how to send alerts to PagerDuty from your Logit stacks.