Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Alert on nginx 5xx Error Rate

Monitor nginx 5xx response rate from the access log and alert Slack when it exceeds your ceiling.

Categories
CloudInfrastructureinfrastructure

Error rates spike silently between dashboards. This blueprint samples the trailing nginx access log lines, computes the 5xx share, and alerts Slack past your ceiling every ten minutes.

How it works

  1. rate_errors (io.kestra.plugin.scripts.shell.Commands on Alpine) tails the log, counts 5xx status codes, and emits the rate via the ::{"outputs": ...}:: protocol. Missing log or empty sample reports 100%.
  2. rate_breached (io.kestra.plugin.core.flow.If) branches to alert_high_rate or log_ok.
  3. The errors block alerts on failure.
  4. Trigger: a disabled */10 Schedule.

What you get

  • A fast spike signal without standing up Prometheus.
  • The rate in the execution history as a trend.

Who it's for

  • Teams whose only telemetry is the nginx log.
  • Quick triage during a bad rollout.

Why orchestrate this with Kestra

grep counts 5xx lines; the flow turns it into a decision on a cadence, with alerts and history. The next step (rollback trigger, upstream restart, page on-call) is one task away.

Prerequisites

  • A Kestra Worker with read access to the nginx access log.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for breach and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set log_path, window_lines, max_error_rate_percent.
  3. Run once and read error_rate_percent.
  4. Enable the schedule.

How to extend

  • Break down by upstream or by status code.
  • Parse JSON-formatted logs instead of the combined format.
  • Alert on 4xx spikes the same way.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.