# Alerts on kubernetes.node.status. fields

**URL:** <https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780>\
**Category:** Metrics\
**Created:** [December 2, 2021, 3:09pm UTC](https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780 "2021-12-02T15:09:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hakim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakim/32/98012_2.png) [@Hakim](https://discuss.elastic.co/u/Hakim)\
**Post date:** [December 2, 2021, 3:09pm UTC](https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780/1 "2021-12-02T15:09:28Z")

</div>

Hi Elastic team, I'm looking to add alerts on boolean fields of kubernetes nodes starting with `kubernetes.node.status.` but when I try to create alerte rule for these fields there is no condition in Metric threshold for the boolean values, I also tried with Log threshold rules but the fields are not available in the proposed list, any idea how can I monitor these metrics?

 ![Screenshot 2021-12-02 at 22.04.12](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb43d63457f5748b33c0c4b414a8c081fc01175e.png)

Thank's in advance,

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [December 2, 2021, 4:11pm UTC](https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780/2 "2021-12-02T16:11:45Z")

</div>

How about creating an alert for each status field where the condition is `document count > 0 FOR THE LAST 1 minute` and the filter is set to `kubernetes.node.status.disk_pressure: true` grouping by `kubernetes.node.name`? Here is an example of what that would look like in the UI (ignore the missing chart data)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f4fe9878fe5709031ca114795bcd688c810fe27.png)

---

<div class="post-metadata">

**Author:** ![Hakim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hakim/32/98012_2.png) [@Hakim](https://discuss.elastic.co/u/Hakim)\
**Post date:** [December 2, 2021, 4:49pm UTC](https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780/3 "2021-12-02T16:49:33Z")

</div>

Hi @ [simianhacker](https://discuss.elastic.co/u/simianhacker)

This solution sounds good for me 🙂

Thanks a lot for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2021, 4:50pm UTC](https://discuss.elastic.co/t/alerts-on-kubernetes-node-status-fields/290780/4 "2021-12-30T16:50:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
