# Alert for multiple indices without summing them up

**URL:** <https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721>\
**Category:** Kibana\
**Created:** [February 7, 2024, 10:00am UTC](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721 "2024-02-07T10:00:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vymk](https://avatars.discourse-cdn.com/v4/letter/v/7bcc69/32.png) [@vymk](https://discuss.elastic.co/u/vymk)\
**Post date:** [February 7, 2024, 10:00am UTC](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721/1 "2024-02-07T10:00:01Z")

</div>

Hi,

I'd like to have alerts if indices don't receive any new documents for a few minutes, therefore I have a rule like this:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee04564b272c2f099aa5f558ff4a818bfc541f55.png)  
Now if I add another index to the rule, they get summarized, so as long as one index receives data, an error in the other one wouldn't be detected.  
Is there another way to make the rule work for each index independently without having to create a separate rule for each index?

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [February 8, 2024, 3:46pm UTC](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721/2 "2024-02-08T15:46:15Z")

</div>

Have you checked the new [ES|QL language](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql-getting-started.html)?

You can create a rule from something like this:

```auto
# Add some sample data

PUT discuss-352807-index-1
{
  "mappings": {
    "properties": {
      "@timestamp": { "type": "date"},
      "metric": { "type": "integer"}
    }
  }
}

PUT discuss-352807-index-2
{
  "mappings": {
    "properties": {
      "@timestamp": { "type": "date"},
      "metric": { "type": "integer"}
    }
  }
}

PUT discuss-352807-index-3
{
  "mappings": {
    "properties": {
      "@timestamp": { "type": "date"},
      "metric": { "type": "integer"}
    }
  }
}

POST discuss-352807-index-1/_bulk
{ "index": {}}
{"@timestamp": "2024-02-05", "metric": 10}
{ "index": {}}
{"@timestamp": "2024-02-06", "metric": 10}
{ "index": {}}
{"@timestamp": "2024-02-07", "metric": 10}
{ "index": {}}
{"@timestamp": "2024-02-08", "metric": 10}

POST discuss-352807-index-2/_bulk
{ "index": {}}
{"@timestamp": "2024-02-05", "metric": 3}
{ "index": {}}
{"@timestamp": "2024-02-06", "metric": 3}
{ "index": {}}
{"@timestamp": "2024-02-07", "metric": 3}

POST discuss-352807-index-3/_bulk
{ "index": {}}
{"@timestamp": "2024-02-05", "metric": 1}
{ "index": {}}
{"@timestamp": "2024-02-06", "metric": 1}

```

Define an alert rule that runs this ES|QL query to get the number of indices with at least one document. The rule will trigger if there's at least one index that passes the first `where` condition and it will not trigger if there's no new data in **all** indices.

```auto
from discuss-352807-index-* [METADATA _index]
| stats indexCount = count(_index) by _index
| where indexCount > 0
| stats totalIndices = count(indexCount)
| where totalIndices > 0

```

In the alert rule this will be triggered by the configured time window so all the indices need to share the same time field.

Does this make sense?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2024, 3:46pm UTC](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721/3 "2024-03-07T15:46:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
