# Alerting based on change of field values

**URL:** https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [October 15, 2020, 7:57pm UTC](https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264 "2020-10-15T19:57:56Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![anjana1](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@anjana1](https://discuss.elastic.co/u/anjana1)
#### Post date: [October 15, 2020, 7:57pm UTC](https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264/1 "2020-10-15T19:57:56Z")

</div>

**Kibana version** : 7.9

**Elasticsearch version** : 7.9

**APM Server version** : 7.9

**APM Agent language and version** : java 1.8

**Fresh install or upgraded from other version?** fresh install

**Is there anything special in your setup?** For example, are you using the Logstash or Kafka outputs? Are you using a load balancer in front of the APM Servers? Have you changed index pattern, generated custom templates, changed agent configuration etc. :-no

I have new scenario where I have to trigger an email when the value of a field changes.  
For example I have the service statuses as OK, WARN and CRITICAL.  
I have to trigger an email when the service status changes from WARN to CRITICAL .I tried to create alerts based on values of service statuses.

I I set up Alerting and I added a condition if the value is CRITICAL in the last 5 minutes send an alert. The trigger happened every minute. I keep getting the alert every minute. My use case is only if the value changes to a new value then send the alert .. How can that work . Currently it keeps sending the alert as it continuously matches the conditions. Only if the value changes an alert needs to be sent

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [October 15, 2020, 9:23pm UTC](https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264/2 "2020-10-15T21:23:27Z")

</div>

hi @anjana1,

I believe this is an outstanding enhancement request for the Kibana alerting-framework, but cannot find the issue. Can you create an ER here: [https://github.com/elastic/kibana/issues/new/choose](https://github.com/elastic/kibana/issues/new/choose)

---

<div class="post-metadata">

### Author: ![anjana1](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@anjana1](https://discuss.elastic.co/u/anjana1)
#### Post date: [October 21, 2020, 5:16am UTC](https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264/3 "2020-10-21T05:16:23Z")

</div>

@thomasneirynck Could you please let me know if this scenario is/or will be covered in the upcoming releases. Because this seems to be very common use case and does not understand why it is not in place yet.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 18, 2020, 5:16am UTC](https://discuss.elastic.co/t/alerting-based-on-change-of-field-values/252264/4 "2020-11-18T05:16:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
