# Add filter for Elastic rules

**URL:** <https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643>\
**Category:** Kibana\
**Created:** [May 17, 2023, 9:33am UTC](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643 "2023-05-17T09:33:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sara\_YB](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Post date:** [May 17, 2023, 9:33am UTC](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643/1 "2023-05-17T09:33:22Z")

</div>

I am trying to add some filters to one of the created rules in kibana 8.6.  
Before adding any filters, it is showing that there are 173 monitors as indicated below:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d3e6fc4de7199cf55263af42b07dd51afd29a2a.png)

When I add one filter only, the outcome changes of course, which is perfect. The below screenshot indicates the filter outcome:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bde78ca57078371f095d8630ab1af073ea4f2c2.png)

Now, I am trying to add more conditions in this filter to be more specific. So, I added a second condition as indicated below:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69cdb925bf4c7ade06f81c4fe54b63363fa10e4e.png)

Could I know the reason behind this??

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [May 30, 2023, 1:14pm UTC](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643/2 "2023-05-30T13:14:09Z")

</div>

The UI is using `monitor.name` to compute those results, not the identifiers you you need to check your data sources.

I'd suggest to create a Data View from the monitor data stream or indices, and check with Lens or Discover to ensure that the issue is at the alerting form. Are you sure your query is correct and those queries outside of the form return the same cardinality?

In my case (version `8.8.0` of the stack) I created a Data View joining data from the different `Synthetics` data streams:

 ![2023-05-30-14-57-10-screenshot](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ed6578078669441666e3ca84333163c38eeb36d.png)

And with that I can use Lens to generate a simple metric to count the different `monitor.name` values on my streams for the last 3 hours

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/85481012d10acacd546ded8ff4b9e83ce0026580.png)

And the queries run as expected:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6a35ebc1a444f4de8262392fa6d49d5f3d92f06f.png)

Conistent with the alerting UI:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/8/382bab08b0102425fe14403feb381e11b8df7fbf.png)

and with the same filter

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0fb4a8672e86bea704285af4035e0346775982b8.png)

Hope it helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2023, 1:14pm UTC](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643/3 "2023-06-27T13:14:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
