# APM Alert - Add filter to http codes

**URL:** <https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092>\
**Category:** Elastic Observability\
**Created:** [September 1, 2021, 6:25pm UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092 "2021-09-01T18:25:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Renzo\_Joseph\_Arenaza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renzo_joseph_arenaza/32/80022_2.png) [@Renzo\_Joseph\_Arenaza](https://discuss.elastic.co/u/Renzo_Joseph_Arenaza)\
**Post date:** [September 1, 2021, 6:25pm UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/1 "2021-09-01T18:25:18Z")

</div>

Hi, we are creating alerts under the APM Errors Interface, but we want to just filter the errors with http code 500 or more. The interface doesn´t have that option. Do you know any workaround to do this?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eef36afce0a8eca87302a02fc6910798da6a3468.png)

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 1, 2021, 8:37pm UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/2 "2021-09-01T20:37:01Z")

</div>

Hi @Renzo_Joseph_Arenaza Welcome the community!

Yeah seem like the filter should be available there...

The Workaround today would be to use a DSL Query see [here](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html)

Your query will be something like

```auto
GET apm-*/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "http.response.status_code": {
              "gte": 500
            }
          }
        }
      ]
    }
  }
}

```

 ![Screen Shot 2021-09-01 at 1.31.20 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a383e67bb2432a828fff8baeaa56cbf8872a18e5.png)

 ![Screen Shot 2021-09-01 at 1.36.38 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2aa00880b0f3b73614382fe3542aa6e42f33a4ea.png)

---

<div class="post-metadata">

**Author:** ![Renzo\_Joseph\_Arenaza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renzo_joseph_arenaza/32/80022_2.png) [@Renzo\_Joseph\_Arenaza](https://discuss.elastic.co/u/Renzo_Joseph_Arenaza)\
**Post date:** [September 2, 2021, 2:14am UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/3 "2021-09-02T02:14:00Z")

</div>

Hi Stephen, thank you for your reply. It nice to see that there is an option.

I have one final question. I would like to add this filter just for one service. I know that the field is service.name. I've tried adding this value in the tags label but It hasn't worked. Do you know how to add this?

Regards.  
Renzo

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 2, 2021, 3:32am UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/4 "2021-09-02T03:32:12Z")

</div>

tags are just tags that are available for the alert output they do not filter.

Some alerts have a KQL filter (Kibana Query Language) others you build up with Conditions.

This is the Query DSL : You should probably look at [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html) to understand Query DSL a bit

so then to select a particular service you query would like

```auto
{
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "http.response.status_code": {
              "gte": 500
            }
          }
        },
        {
          "term": {
            "service.name": "my-service-name"
          }
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Renzo\_Joseph\_Arenaza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renzo_joseph_arenaza/32/80022_2.png) [@Renzo\_Joseph\_Arenaza](https://discuss.elastic.co/u/Renzo_Joseph_Arenaza)\
**Post date:** [September 15, 2021, 9:24pm UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/5 "2021-09-15T21:24:14Z")

</div>

Thank you very much @stephenb. We did what you suggested and it worked like a charm =D

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:32am UTC](https://discuss.elastic.co/t/apm-alert-add-filter-to-http-codes/283092/6 "2022-11-04T08:32:08Z")

</div>


