# Create rule using KQL query

**URL:** <https://discuss.elastic.co/t/create-rule-using-kql-query/333859>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [May 19, 2023, 10:23am UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859 "2023-05-19T10:23:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nitisha](https://avatars.discourse-cdn.com/v4/letter/n/6de8d8/32.png) [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Post date:** [May 19, 2023, 10:23am UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859/1 "2023-05-19T10:23:02Z")

</div>

Hi ,

We are using metricbeat to monitor containers in our environment. We need to create an email alert to get triggered when any container's CPU usage exceeds 70%.

I was trying to create a rule under "Alerts and Insights" using "Rules and Connectors", however, in the section where it asks to define the Elasticsearch query its only allowing Query DSL not KQL. I watched one video where there was an option to define Elasticsearch query in KQL.

Has KQL been removed from "Rules and Connectors"? If has been removed, is there any tool/way I can convert KQL to QDSL?

My intended KQL is "container.name : \* and docker.cpu.total.pct \>= 0.7". We're running ELK 8.1.

Thanks,  
Nitish

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 19, 2023, 11:39pm UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859/2 "2023-05-19T23:39:44Z")

</div>

Hi @nitisha

For your alert you should try metric threshold it should cover the case, in fact it is specifically made for this case and is MORE powerful / flexible that just a DSL Alert  
You can have critical and warning levels  
Filter by KQL  
Group by etc

Here is a sample I don't have docker on this cluster but should point out how

 ![Screenshot 2023-05-19 at 4.30.50 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fef87c0c479080c26cd0226fc02115ecfa33591b.png)

 ![Screenshot 2023-05-19 at 4.36.42 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2bba3768ca9c988ff6d4bbefdc4e8ff08b24153e.png)

 ![Screenshot 2023-05-19 at 4.37.29 PM](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a905a66e89c1ba2ce224c4b38e831c59d5b67b05.png)

Try that ... much better...

> [@nitisha](#):
>
> I watched one video where there was an option to define Elasticsearch query in KQL.

I think that came with a newer version not sure which it is in 8.7 for sure.. i just checked, but you should really try the metric threshold

---

<div class="post-metadata">

**Author:** ![nitisha](https://avatars.discourse-cdn.com/v4/letter/n/6de8d8/32.png) [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Post date:** [May 22, 2023, 11:04am UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859/4 "2023-05-22T11:04:37Z")

</div>

Hi Stephen,

Thanks for the prompt response. I tried it out, however, it didn't work.

I got it working with "Inventory" using the following config. with filter name as agent.hostname : _name of the dockerhost_.

![Image 22-05-23 at 4.31 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/3/8381625fec57fbc4aa3748a0d32b2ee87d9c9dfd.jpeg)

(used low values just for testing purposes)

Another query which I have is, while specifying "Actions", is it mandatory to use pre-defined actions like {{ context.something }}? Reason being, currently the logs are showing container.id when I used {{ context.group }}, I would rather like to display container.name. How can we customise our own actions ?

Thanks,  
Nitish

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2023, 11:05am UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859/5 "2023-06-19T11:05:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
