# CPU usage alert reason is incorrect

**URL:** <https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964>\
**Category:** Metrics\
**Created:** [October 5, 2021, 11:09pm UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964 "2021-10-05T23:09:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dyadav](https://avatars.discourse-cdn.com/v4/letter/d/9fc348/32.png) [@dyadav](https://discuss.elastic.co/u/dyadav)\
**Post date:** [October 5, 2021, 11:09pm UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/1 "2021-10-05T23:09:28Z")

</div>

I have configured email alerts if CPU usage is above or equals 80% for last 2 minutes. Below is the content configured in my alert:

{{alertName}} - {{context.group}} is in a state of {{context.alertState}}

Reason:  
{{context.reason}}

I am getting email when CPU usage is above 80% but the content is not correct in mail. Below is example email:

Non-Prod Infra Alerts -Hostname is in a state of ALERT  
Reason: CPU usage is less than a threshold of 80 (current value is 99.3%)

It should say CPU usage is more than a threshold.

Please suggest.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 6, 2021, 9:31am UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/2 "2021-10-06T09:31:17Z")

</div>

Hi @dyadav,

could you tell us which version of the Elastic Stack you're seeing this in? I am trying to reproduce it on my end.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 6, 2021, 11:07am UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/3 "2021-10-06T11:07:56Z")

</div>

It seems to be a known issue, which is tracked in [Alert and Actions - context.reason shows wrong text · Issue #88585 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/88585). Thanks for bringing it to our attention again! Since the fix looked trivial I created a PR for it at [[Metrics UI] Fix metric threshold alert reason message for gte/lte comparator by weltenwort · Pull Request #114080 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/114080).

This problem only seems to occur for the "less/greater or equal" case. Until the fix is merged and released you could try to work around it by using the "greater than" with a slightly smaller threshold (e.g. 79% instead of 80%).

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 7, 2021, 2:54pm UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/4 "2021-10-07T14:54:41Z")

</div>

ℹ The fix has been merged and should hopefully be released in 7.15.1.

---

<div class="post-metadata">

**Author:** ![dyadav](https://avatars.discourse-cdn.com/v4/letter/d/9fc348/32.png) [@dyadav](https://discuss.elastic.co/u/dyadav)\
**Post date:** [October 12, 2021, 4:30pm UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/5 "2021-10-12T16:30:11Z")

</div>

Thank you so much Felix for the update. I have configured using the work around for now.

Will wait for it to be released in new version.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 4:30pm UTC](https://discuss.elastic.co/t/cpu-usage-alert-reason-is-incorrect/285964/6 "2021-11-09T16:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
