# Alerting - Search Threshold/ES Query Rule

**URL:** <https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553>\
**Category:** Kibana\
**Created:** [March 1, 2024, 7:47pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553 "2024-03-01T19:47:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [March 1, 2024, 7:47pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/1 "2024-03-01T19:47:26Z")

</div>

Hello,  
So I created a rule with filters to alert me if a specific document comes. This is working as expected.

I was wondering since I am using `{{context.hits}}` to read through the documents. I was wondering how can I create an alert per each document in `{{context.hits}}`.

The reason is I have the alert condition looking at the checking every 1 minute but 2 documents might come in the last 1 minute. Decreasing the check interval is actually not the best way as Elastic says "Intervals less than 1 minute are not recommended due to performance considerations." I know there's "Set the number of documents to send" can be set to 1, but that will not alert on the 2nd document.

To simplify what I am trying to say, I want to be alerted per document, while showing document variables within the alert body. If there are 3 documents, I want 3 separate alerts.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2024, 6:39pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/2 "2024-03-02T18:39:17Z")

</div>

Hi @erikg

What version are you on?

Can you share your alert? Exactly which Alert Type are you using?

The only way I know to get separate alerts is using group by which is only available is certain rules.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [March 8, 2024, 4:45pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/3 "2024-03-08T16:45:44Z")

</div>

@stephenb I am using Elasticsearch Query.  
And yes you are correct, there's no group by in Elasticsearch Query rule,  
I tried Metric Threshold and Index Threshold and they work with the group by.  
The issue is you can't do much with the email body in terms of variables you can use.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 8, 2024, 7:48pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/4 "2024-03-08T19:48:29Z")

</div>

What version are you on?

> [@erikg](#):
>
> The issue is you can't do much with the email body in terms of variables you can use.

In some ways, you have competing requirements...

You want to Group, which is an Aggregation of documents, but you want Individual documents to report on...

Not saying that is unreasonable... but a bit orthogonal.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [March 8, 2024, 9:29pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/5 "2024-03-08T21:29:17Z")

</div>

Hey @stephenb ,

yeah you are right! I just realized that I am trying to do aggregation by grouping them. Therefore there will be no individual documents to pass through. A Threshold rule would be better suit for this.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [March 8, 2024, 9:33pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/6 "2024-03-08T21:33:00Z")

</div>

This can be closed but now I have another post that clarifies my question on what I want to do with the alert variables:

[Custom Threshold Rule - Email Body - Elastic Stack / Kibana - Discuss the Elastic Stack](https://discuss.elastic.co/t/custom-threshold-rule-email-body/355055)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2024, 9:33pm UTC](https://discuss.elastic.co/t/alerting-search-threshold-es-query-rule/354553/7 "2024-04-05T21:33:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
