# Alert and action -- Less than condition is not working

**URL:** <https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 1, 2020, 9:36am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069 "2020-09-01T09:36:53Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 1, 2020, 9:36am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/1 "2020-09-01T09:36:54Z")

</div>

Hi All,

Thank you for this great support where we get reply in few minutes. We're very grateful to all of you guys.

We're using latest version of ELK. In alert and action \> Log Threshold, less than feature doesn't work as highlighted in the screenshot

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c91277a5fda69f1a5742c8a79034c36f7cc7a392.png)

We're intended to get alert when a logsource stop sending logs, here if we change it with _more than_ X number of logs entries then it works and trigger an alert but less than doesn't work.

Here are two observations:  
1st observation, if logsource i.e host.name **wp-pri** stop sending logs then in realtime **wp-pri** will not be appearing in the realtime logs that's why my condition becomes false. It make sense.

But here I'm doing it like **wp-pri** hostname is appreaing in the real time logs. I know in last 30 minutes this hostname doesn't have more than 2000 json documents, it should have trigger an alert now. When I change it like if **more than** 1000 logs occur then it trigger an alert successfully.

Please help me what's happening here and how can I accomplish my goal.

Thank you.

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 1, 2020, 6:57pm UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/2 "2020-09-01T18:57:19Z")

</div>

Hi Community,

Can anyone please reply on this. Intention is to get alert if logsource stops sending logs

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 4:57am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/3 "2020-09-02T04:57:22Z")

</div>

What version of Kibana and what type of alert are you creating?  
Is that a Log Threshold Alert?

Also what action type are you using?

One thing I notice you are filtering by host.name and group by host.name ...

What happens if you change group by to Nothing

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 2, 2020, 5:04am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/4 "2020-09-02T05:04:44Z")

</div>

Sir,

Kibana version is 7.9.0 and I'm creating log threshold alert.

Alert Type: Log Threshold  
Action Type: Index

P.S: There is no problem with index. I have verified that alert json document save on the index.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 5:21am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/5 "2020-09-02T05:21:48Z")

</div>

I just wrote this is the less than and it worked

 ![Screen Shot 2020-09-01 at 10.19.40 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b03905b8a5748cfc76adb6479c1b05b95b85215.png)

And the Alert Fired

```
  {
    "_index" : "alerts",
    "_type" : "_doc",
    "_id" : "XwE_TXQBsa3bYJU-EdKd",
    "_score" : 1.0,
    "_source" : {
      "context_message" : "",
      "alert_id" : "8315ad77-4eb1-4dca-b112-fc2fbb97a819",
      "alert_name" : "test-log",
      "alert_instance_id" : "*",
      "@timestamp" : "2020-09-02T05:16:53.020Z"
    }
  },
```

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 2, 2020, 5:21am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/6 "2020-09-02T05:21:58Z")

</div>

> [@stephenb](#):
>
> One thing I notice you are filtering by host.name and group by host.name ...
> 
> What happens if you change group by to Nothing

Sir, it didn't effect, now I have group by Nothing

I don't think group by cause any effect because in kibana visualization, we filter any field and then we can group by on that field too.

Here group by is working ok. I could have seen all logsource names in host.name but now it's \* when after making changes on group by to Nothing.

Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 5:28am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/7 "2020-09-02T05:28:24Z")

</div>

Did you go to Discover set time range to 30 mins and filter on the `host.name : "wp-pri" and type : "auditd"` you get a count of less than 2000 if so the alert should fire or perhaps wrong in the logic.

Curious where that `type` field came from?

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 2, 2020, 5:35am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/8 "2020-09-02T05:35:47Z")

</div>

Sir, I had made it sure before creating rule. I'm sorry, don't know why it doesn't work for me.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de590dbdad6bbc63580fd205c276653301d4318c.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 6:07am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/9 "2020-09-02T06:07:42Z")

</div>

Hmmm there is something interesting going on. It is late where I am at, I will need to take a look tomorrow and perhaps ask for some guidance.

The logic is not working as I understand it... we are trying to mix positive and negative logic.

It appears that perhaps since there are no / 0 documents that match the `type` and `host.name` conditions that those conditions are then `false` and since all the conditions are ANDed that the overall condition is false and thus the alert does not fire.

Your discover showed 0 documents matching... so I think that is what is happening.

I think if there were a couple documents that matched that perhaps the alert would fire.

I will do my best to check, or see if I can get someone else to take a look.

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [September 2, 2020, 6:21am UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/10 "2020-09-02T06:21:13Z")

</div>

Thank you sir for you reply and great support!

I have created another connector and assigned that connector to this alert. It worked.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2020, 2:44pm UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/11 "2020-09-02T14:44:38Z")

</div>

Hi @msszafar

Thanks for the response and issues ...

A couple things...

1. I did verify that if you filter on a term like `host.name IS wp-pri` and that filter results in 0 Documents you can not use `GROUP BY host.name` you can not group by the field that returns 0 results.

2. Can you please post / show your current / working / solution please we are interested.

3. The team actually created an issue related to your request if you want to take a look

> <https://github.com/elastic/kibana/issues/76511>
>
> Currently a log threshold alert can be configured to be less than 1, ultimately 0. 0 means that there is no...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 2:44pm UTC](https://discuss.elastic.co/t/alert-and-action-less-than-condition-is-not-working/247069/12 "2020-09-30T14:44:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
