Search Guard - Enterprise Security for Elasticsearch
  • Documentation
  • Changelogs
    • Search Guard
    • Kibana
    • TLS Tool
  • Versions
    • FLX
    • 7x-53
    • 7x-52
    • 7x-51
    • 7x-50
    • 7x-49
    • 7x-48
    • 7x-47
    • 7x-46
    • 7x-45
    • 7x-43
    • 7x-42
    • 7x-41
    • 7x-40
    • 7x-38
    • 7x-37
    • 7x-36
    • 7x-35
    • 6x-25
    • 6x-24
    • 6x-23
    • 6x-22
    • 6x-21
    • 6x-20
    • v5
    • v2
  • Forum
  • Contact Us
  • Security
    • Introduction to Search Guard
      • Overview
      • Main Concepts
    • Quickstart
      • Demo Installer (Linux/Mac)
      • Manual Installation
      • Guided Tour
        • Adding users
        • Configuring roles
        • Mapping users to Search Guard roles
        • Testing the configuration
    • Search Guard Versions
      • Releases
      • Community Edition
      • Enterprise and Compliance Edition
      • Academic and Scientific Licensing
      • OEM Licensing
      • End of life policy
    • Installing Search Guard
      • Search Guard Installation
      • Updating Search Guard
      • Disabling or Removing Search Guard
      • Search Guard Compatibility
      • Migrating from Classic to FLX
        • Migrating to FLX
        • Quick Start
        • Production
        • FLX release notes
        • Feature map
      • Upgrading Search Guard
        • Upgrade from FLX 1.x to 2.x
        • Upgrade from SearchGuard 7.x to 8.x
    • TLS Setup
      • Generating Certificates
        • Search Guard Installer
        • Offline TLS Tool
      • Configuring TLS
      • Production environments
      • Certificate revocation
      • TLS hot-reload
    • Search Guard Configuration
      • Overview
      • Using sgctl
        • Basic Usage
        • Examples
        • Configuration changes
        • System Administration
      • Search Guard configuration GUI
      • Configuration variables
      • Configuration index maintenance
    • Authentication
      • Overview
      • General Configuration
        • Introduction to sg_authc
        • Advanced user mapping
        • Other advanced options
      • Password-based Authentication
        • Overview
        • Internal users database
      • Active Directory and LDAP
        • Quick Start
        • Advanced Configuration
      • Kerberos / SPNEGO
      • JWT
        • Quick Start
        • Advanced Configuration
      • Proxy authentication
        • Quick Start
        • Advanced Configuration
      • Client certificate authentication
      • Anonymous authentication
      • Search Guard Auth Tokens
    • Authorization
      • Demo users and roles
      • Mapping users to Search Guard roles
      • Permissions and action groups
      • Search Guard roles
      • Search Guard roles (2.x and below)
      • Role mapping modes
      • Runtime index privilege evaluation
      • Advanced topics
        • User impersonation
        • Snapshot and restore
    • Document-level security
      • Basics
      • Attribute-based authorization
      • Advanced topics
    • Field-level security
      • Field-level security
      • Field anonymization
    • Audit Logging
      • Configuring Audit Logging
      • Storage Types
      • Event routing
      • Field Reference
      • Read History Audit Logging
      • Write History Audit Logging
      • Configuration change tracking
      • System change tracking
      • Immutable indices
    • Rest API
      • Access Control
      • Usage and return values
      • Internal users API
      • Roles API
      • Roles mapping API
      • Action groups API
      • Blocks API
      • Tenants API
      • License API
      • Cache API
      • Advanced Topics
        • Bulk Requests
        • Reserved and hidden resources
    • Kibana
      • Installing the Plugin
      • Authentication
        • Overview
        • Password-based Authentication
          • Quick Start
          • Customizing the login page
        • OIDC
          • Quick Start
          • Advanced Configuration
        • SAML
          • Quick Start
          • Advanced Configuration
          • Troubleshooting
      • Proxy
      • Kerberos
      • Multi-Tenancy
      • Advanced Topics
        • Using multiple authentication methods
        • Read Only mode
        • Using the Kibana API
        • JWT URL Parameters
        • Anonymous Authentication
        • Kibana in IFrame
    • Integrations
      • Logstash
      • Cross Cluster Search
      • X-Pack Monitoring
      • X-Pack Alerting
      • X-Pack Machine Learning
      • Cerebro
      • Fluentd
      • Grafana
    • OEM Features
      • SSL only mode
      • Search Guard index restore
      • Inter-node traffic evaluator
      • Custom Principal Extractor
      • Injecting an SSLContext
    • Troubleshooting
      • Setting the log level
      • TLS
      • Users and Roles
      • Permissions
      • Kibana
      • Multi Tenancy
  • Alerting
    • Getting started with Signals Alerting
    • How Signals Alerting works
    • Sample Watches
    • Execution chain and payload
    • Triggers
      • Triggers Overview
      • Schedule Triggers
      • Handling Timezones
    • Inputs
      • Inputs Overview
      • Static Input
      • Search Input
      • HTTP Input
    • Transformations
      • Transformations Overview
      • Transformations
      • Calculations
    • Conditions
    • Severity Levels
    • Actions
      • Actions Overview
      • Index Actions
      • Email Actions
      • Webhook Actions
      • Slack Actions
      • Pagerduty Actions
      • JIRA Actions
    • Accounts
    • Scripting
    • Throttling and Acknowledgement
    • Trust Stores
    • Proxies
    • REST API
      • REST API Overview
      • Get Watch
      • Put Watch
      • Delete Watch
      • Search Watch
      • Activate and Deactivate Watch
      • Execute Watch
      • Acknowledge Watch
      • Acknowledge And Get
      • Un-acknowledge Watch
      • Un-acknowledge Watch And Get
      • Convert ES Watch
      • Get Watch State
      • Search Watch States
      • Get Account
      • Put Account
      • Search Accounts
      • Delete Account
      • Create or replace a trust store
      • Get all trust stores
      • Get one trust store
      • Delete trust store
      • Create or replace a proxy
      • Get all proxies
      • Get one proxy
      • Delete proxy
      • Get Settings
      • Put Settings
      • Activate and Deactivate Tenant
      • Activate and Deactivate Signals
    • Security Integration
      • Security Integration Overview
      • Signals Indices
      • Permissions
      • Execution context
      • Multi-Tenancy
    • Status and Logging
    • Administration
    • Advanced Topics
      • Watch overview page query params
  • Index Management
    • How Automated Index Management Works
    • Conditions
      • Age Condition
      • Doc Count Condition
      • Conditions Overview
      • Size Condition
    • Actions
      • Actions Overview
      • Allocation Action
      • Close Action
      • Delete Action
      • Force Merge Action
      • Rollover Action
      • Set Priority Action
      • Set Read Only Action
      • Set Replica Count Action
      • Snapshot Action
    • REST API
      • Put Policy
      • Get Policy
      • Delete Policy
      • Policy Instance State
      • Policy Instance Execute
      • Policy Instance Retry
      • Put Settings
      • Get Settings
      • Delete Settings
      • Security Integration
      • Settings
  • Encryption at Rest
    • Introduction
Version: SG FLX
  1. Home
  2. Alerting

Alerting

Browse all documentation pages in the Alerting category:

  • Getting started with Signals Alerting
  • How Signals Alerting works
  • Sample Watches
  • Execution chain and payload
  • Triggers
    • Triggers Overview
    • Schedule Triggers
    • Handling Timezones
  • Inputs
    • Inputs Overview
    • Static Input
    • Search Input
    • HTTP Input
  • Transformations
    • Transformations Overview
    • Transformations
    • Calculations
  • Conditions
  • Severity Levels
  • Actions
    • Actions Overview
    • Index Actions
    • Email Actions
    • Webhook Actions
    • Slack Actions
    • Pagerduty Actions
    • JIRA Actions
  • Accounts
  • Scripting
  • Throttling and Acknowledgement
  • Trust Stores
  • Proxies
  • REST API
    • REST API Overview
    • Get Watch
    • Put Watch
    • Delete Watch
    • Search Watch
    • Activate and Deactivate Watch
    • Execute Watch
    • Acknowledge Watch
    • Acknowledge And Get
    • Un-acknowledge Watch
    • Un-acknowledge Watch And Get
    • Convert ES Watch
    • Get Watch State
    • Search Watch States
    • Get Account
    • Put Account
    • Search Accounts
    • Delete Account
    • Create or replace a trust store
    • Get all trust stores
    • Get one trust store
    • Delete trust store
    • Create or replace a proxy
    • Get all proxies
    • Get one proxy
    • Delete proxy
    • Get Settings
    • Put Settings
    • Activate and Deactivate Tenant
    • Activate and Deactivate Signals
  • Security Integration
    • Security Integration Overview
    • Signals Indices
    • Permissions
    • Execution context
    • Multi-Tenancy
  • Status and Logging
  • Administration
  • Advanced Topics
    • Watch overview page query params

Questions? Drop us a note!

Not what you were looking for? Try the search.

Search Guard is a trademark of floragunn GmbH, registered in the U.S. and in other countries.

Elasticsearch, Kibana, Logstash, and Beats are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.
  • Blog
  • Forum
  • Partners
  • Integrators
  • Licensing

© 2025 floragunn GmbH - All Rights Reserved
Search Guard