# Alerting - Filter Query not working

**URL:** https://discuss.elastic.co/t/alerting-filter-query-not-working/370612
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [November 15, 2024, 3:20pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612 "2024-11-15T15:20:43Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)
#### Post date: [November 15, 2024, 3:20pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612/1 "2024-11-15T15:20:43Z")

</div>

Hello,  
I was testing out the Metric Threshold to alert on disk usage.  
I want to exclude some hosts from the alert, but I seem to get this error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/2796c05be1317e7432e4e93ea27312164234cb4f.png)

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 15, 2024, 3:40pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612/2 "2024-11-15T15:40:39Z")

</div>

Hi @erikg

I see the same thing on 8.15.3 (what version are you on?) it is trying to tell you it does not like that filter I am not sure why that does not work

 ![Screenshot 2024-11-15 at 7.37.29 AM](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc7a8d513ed7ddc04cb13439bcd763879e75efbf.png)

But I solved it by just using the KQL syntax in the KQL bar right there in this form

`not host.name : (hostname-1 or hostname-2)`

---

<div class="post-metadata">

### Author: ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)
#### Post date: [November 15, 2024, 3:44pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612/3 "2024-11-15T15:44:14Z")

</div>

Hey @stephenb  
Yes, same I am on 8.15.3

Thanks for the workaround, I kind of hate writing in KQL syntax in the KQL bar because if I want to continue to exclude hosts, it will be an endless string

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 15, 2024, 3:59pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612/4 "2024-11-15T15:59:55Z")

</div>

> [@erikg](#):
>
> Thanks for the workaround, I kind of hate writing in KQL syntax in the KQL bar because if I want to continue to exclude hosts, it will be an endless string.

Perhaps you could consider some tagging mechanism on the hosts to exclude a group of hosts.

The filter button creates a long string in code under the covers as well 🙂 .... not sure why the filter does not work, you could open an Issue against the Kibana repo.
