# Combine a few rules into 1 rule

**URL:** <https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [March 28, 2024, 9:27am UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375 "2024-03-28T09:27:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 28, 2024, 9:27am UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/1 "2024-03-28T09:27:15Z")

</div>

Hello guys,

I have a case about alerting here. so, the condition to trigger this alert is so simple.  
there are 3 codes that I watched using this alert which are 68, 40, X5  
if code 68 appeared 10 times in 1 minute, then trigger the alert  
if code 40 appeared 10 times in 1 minute, then trigger the alert and so on for X5

and I tried to use the elasticsearch query because it needs to point to an index in my cluster and the query looks like this:

```auto
"aggs": {
    "0": {
      "terms": {
        "field": "responseCode.keyword",
        "order": {
          "_count": "desc"
        },
        "size": 5
      }
    }
  },
  "size": 0,
"query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "bool": {
            "should": [
              {
                "bool": {
                  "should": [
                    {
                      "match": {
                        "responseCode": "68"
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              },
              {
                "bool": {
                  "should": [
                    {
                      "match": {
                        "responseCode": "X5"
                      }
                    }
                  ],
                  "minimum_should_match": 1
                }
              }
            ],
            "minimum_should_match": 1
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  }

```

after I set the threshold and tested the query, I got the sum result from each code. it gives me 18 documents matching the condition. but this "18" was obtained from the sum between code 68 and X5 while the real values are Code 68 has 9 records and Code X5 also has 9 records. if you look at the condition that I mentioned above, this situation should not trigger the alert. but because it sums up each response code record, it triggers the alert.

How can I combine those conditions into 1 rule? because there would be so many rules I need to create if I make 1 condition for 1 rule. is it possible to separate the record of each response code and match them separately too with the threshold?

Thanks

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2024, 2:58pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/2 "2024-03-28T14:58:35Z")

</div>

well certainly you can accomplish this pretty easily in [ES|QL](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql.html) (requires latest version)

Here's an example:

```auto
from kibana_sample_data_logs
| stats r404=count(response.keyword == "404" or NULL), r503=count(response.keyword == "503" or NULL) 
| where r404 > 500 or r503 > 800

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f712499bee9d012fdb3a52d445008f376628ad29.png)

Then build an alert off of this (Alert menu at top right)

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 28, 2024, 3:45pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/3 "2024-03-28T15:45:15Z")

</div>

So based on your example, the only thing that triggered from the alert is r404?

Pada Kam, 28 Mar 2024 22.08, rich collier via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2024, 4:17pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/4 "2024-03-28T16:17:42Z")

</div>

correct

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2024, 5:57pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/5 "2024-03-28T17:57:05Z")

</div>

Are you planning to use Kibana Alerts or Watcher?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 28, 2024, 10:29pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/6 "2024-03-28T22:29:47Z")

</div>

Kibana alert, actually

Pada Jum, 29 Mar 2024 01.07, rich collier via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2024, 10:30pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375/7 "2024-04-25T22:30:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
