# Creating alerts in Kibana for a specific query

**URL:** https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [October 1, 2020, 8:44pm UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740 "2020-10-01T20:44:47Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![vpurushottam](https://avatars.discourse-cdn.com/v4/letter/v/6a8cbe/32.png) [@vpurushottam](https://discuss.elastic.co/u/vpurushottam)
#### Post date: [October 1, 2020, 8:44pm UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/1 "2020-10-01T20:44:48Z")

</div>

Hi,

I am struggling with creating an alert on Kibana. I have the license and have Slack notification connected. I have logs coming in from a HIDS and from those logs, which has logs for many different kind of activities, I only need to extract information regarding any new file created. I am assuming here that I will be using a 'Metric Threshold' alerting here to trigger an alert if the alert mechanism detects a log for any new file created in let's say, past 5 minutes.

How can I create an alert for that because in the 'Metric Threshold' settings option I don't see an option to put in a query that can help the mechanism to extract only the new file added logs from the entire set.

I saw a filter option where I can add in KQL, but I don't know how to add the index value in KQL because again, in setting I don't find an option for select index.

Kibana: 7.7.1

Please help

Thanks  
Vish

---

<div class="post-metadata">

### Author: ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)
#### Post date: [October 2, 2020, 8:14am UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/2 "2020-10-02T08:14:01Z")

</div>

So if I understood correctly, you need to use the Log Threshold. To be able to see the fields from your index, make sure it is included in the Logs application settings.

---

<div class="post-metadata">

### Author: ![vpurushottam](https://avatars.discourse-cdn.com/v4/letter/v/6a8cbe/32.png) [@vpurushottam](https://discuss.elastic.co/u/vpurushottam)
#### Post date: [October 2, 2020, 4:38pm UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/3 "2020-10-02T16:38:26Z")

</div>

Hi,

Thank you @admlko for your reply. Where can I setup log threshold alerting cause the one I have only show index and metric threshold.

 ![Screen Shot 2020-10-02 at 9.36.50 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8eeba0323d8058d20b965a27eb46f2772766c0b1.png)

-- Vish

---

<div class="post-metadata">

### Author: ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)
#### Post date: [October 4, 2020, 10:35am UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/4 "2020-10-04T10:35:23Z")

</div>

Sorry but I think you have to update.  
I cannot seem to find it quickly which version introduced the feature, but at least the latest has it 🙂

---

<div class="post-metadata">

### Author: ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)
#### Post date: [October 4, 2020, 12:13pm UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/5 "2020-10-04T12:13:06Z")

</div>

Kibana v7.x

> **[Alerting and Actions | Kibana Guide \[7.x\] | Elastic](https://www.elastic.co/guide/en/kibana/7.x/alerting-getting-started.html#alerting-setup-prerequisites)**

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 1, 2020, 12:13pm UTC](https://discuss.elastic.co/t/creating-alerts-in-kibana-for-a-specific-query/250740/6 "2020-11-01T12:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
