# Alerting - OR condition in Log threshold rule type

**URL:** <https://discuss.elastic.co/t/alerting-or-condition-in-log-threshold-rule-type/327458>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [March 10, 2023, 1:59pm UTC](https://discuss.elastic.co/t/alerting-or-condition-in-log-threshold-rule-type/327458 "2023-03-10T13:59:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [March 10, 2023, 1:59pm UTC](https://discuss.elastic.co/t/alerting-or-condition-in-log-threshold-rule-type/327458/1 "2023-03-10T13:59:24Z")

</div>

We are currently migrating from the 3.party [Elastalert](https://elastalert.readthedocs.io/en/latest/) package for alerting on data in Elasticsearch to the native Kibana Alerting capabilities. On that path we have come across the issue that it does not seem possible to have **OR** conditions in the log threshold rule type. Any workaround to achieve this ?

An example of an Elastalert query we would like to bring into the native platform would be "_(message: busy AND message: "5:011") OR (message: status AND message: "6:091") OR (message: Status AND message:"Terminal Offline")_"

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 10, 2023, 4:31pm UTC](https://discuss.elastic.co/t/alerting-or-condition-in-log-threshold-rule-type/327458/2 "2023-03-10T16:31:25Z")

</div>

The short answer is yes. Create the search in Discover and then click Alerts to create a "Search Threshold Rule"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b06ae65d1ac9c8942201e3bcb90a82710862d53f.jpeg)
