# Create a Kibana Rule

**URL:** <https://discuss.elastic.co/t/create-a-kibana-rule/348333>\
**Category:** Kibana\
**Tags:** painless, kql-kibana-query-language, detection-rules, kibana-plugin-development, eql-elastic-query-language\
**Created:** [November 30, 2023, 1:02pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333 "2023-11-30T13:02:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Claudia\_Tavares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudia_tavares/32/123860_2.png) [@Claudia\_Tavares](https://discuss.elastic.co/u/Claudia_Tavares)\
**Post date:** [November 30, 2023, 1:02pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333/1 "2023-11-30T13:02:19Z")

</div>

Kibana: version 7.17.3

I am trying to create a Rule in Kibana Alerts and Insights, but I'm having some difficults.  
To contextualize:  
1- I want to calculate the total of documents in last 5 minutes  
2- Calculate the number of documents with response\_code field \> 400  
3- Alert should be activated when the number of documents with response\_code field \> 400 is above 2% of total documents

What I have for now:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b4f9d163a47d06b00be749c5232106b0edc9452.png)

My query is:

```auto
{
  "aggs": {
    "total_requests": {
      "value_count": {
        "field": "id_request"
      }
    },
    "errors": {
      "filter": {
        "range": {
          "response_code": {
              "gte": 400,
              "lt": 500
          }
        }
      },
      "aggs": {
        "total_errors": {
          "value_count": {
            "field": "id_request"
          }
        }
      }
    }
  },
  "script_fields": {
    "percentual_errors": {
      "script": {
        "source": "params._source['errors.total_errors'] / params._source['total_requests.value']",
        "lang": "painless"
      }
    }
  },
  "query": {
    "match_all": {}
  },
  "post_filter": {
    "script": {
      "script": {
        "source": "params.percentual_errors > 0.02",
        "lang": "painless"
      }
    }
  }
}

```

My problem is that kibana is expecting that I select an number of documents that should match, but I only want to activate the query when the condition is true.

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [November 30, 2023, 2:32pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333/2 "2023-11-30T14:32:41Z")

</div>

As you are on 7.17 the [ratio threshold rule](https://www.elastic.co/guide/en/observability/7.17/logs-threshold-alert.html#ratio-alerts) might provide a solution to you.

You could use query a to be one with the 400 response code. Query b the total and configure the ratio to be more then 0.2:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c5f5b3c8d77181b09c34f9067e9b059c7ebacab.png)

---

<div class="post-metadata">

**Author:** ![Claudia\_Tavares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/claudia_tavares/32/123860_2.png) [@Claudia\_Tavares](https://discuss.elastic.co/u/Claudia_Tavares)\
**Post date:** [November 30, 2023, 3:05pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333/3 "2023-11-30T15:05:54Z")

</div>

@sholzhauer Thank you so much for your help.

Actually I already have looked to this type of rule but my fields are empty, maybe I need some extra configuration for these. Can you give me more details?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81943aa48341c0a1181872276c5617c212f8ad3f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2023, 3:06pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333/4 "2023-12-28T15:06:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
