# Custom Threshold not triggering alert to index

**URL:** https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531
**Category:** Kibana
**Tags:** elastic-stack-alerting, detection-rules
**Created:** [April 25, 2025, 6:04pm UTC](https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531 "2025-04-25T18:04:51Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Dave\_Houser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dave_houser/32/72517_2.png) [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)
#### Post date: [April 30, 2025, 1:00pm UTC](https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531/2 "2025-04-30T13:00:34Z")

</div>

I upgraded to 8.18. same problem.  
The only thing that seems to work is setting the alert action frequency from "For each alert - on status changes" to "Summary of alerts - on check intervals"  
But this will just keep sending an alert to the index if the alert is triggered.  
I don't want that.  
I want just one alert sent to the index if the alert happens. And once its resolved send another alert.  
Does anyone else have this issue? Am I the only one?  
Can anyone help please?

I created a ticket for this on Kibana github, a while back. I just updated the post here

> <https://github.com/elastic/kibana/issues/219299>
>
> \*\*Describe the bug:\*\*
> Custom Thresholds are not triggering alerts to Indexes
> 
> \*\*…Kibana/Elasticsearch Stack version:\*\*
> 8.18
> 
> \*\*Server OS version:\*\*
> \<Pod based\>
> 
> \*\*Browser and Browser OS versions:\*\*
> MS Edge Version 135.0.3179.54
> 
> \*\*Elastic Endpoint version:\*\*
> N/A?
> 
> \*\*Original install method (e.g. download page, yum, from source, etc.):\*\*
> pod deployment
> 
> \*\*Functional Area (e.g. Endpoint management, timelines, resolver, etc.):\*\*
> alerting / rules
> 
> \*\*Steps to reproduce:\*\*
> 
> 1. Created an rule to alert on, made method "custom threshold"
> 2. Conditional, if all logs are \< 100 logs p/s, alert for \`logs-\*\` data-view
> 3. Made alert trigger to write to an index. Index contents\`\`\`
> \`\`\`
> {
> "@timestamp": "{{date}}",
> "alert\_id": "{{alert.id}}",
> "rule\_name": "{{rule.name}}",
> "foo": "bar"
> }
> \`\`\`
> 3. Manually created index with direct mappings.
> 
> \*\*Current behavior:\*\*
> Alert shows active when conditional is true, but index does no documents. If I go to the connector, and run a test, the index gets a document. There is some disconnect from the alert trigger to the index. 
> 
> \*\*Expected behavior:\*\*
> Alert should show active, and the index should get a document per alert. 
> 
> \*\*Screenshots (if relevant):\*\*
> 
> \*\*Errors in browser console (if relevant):\*\*
> 
> \*\*Provide logs and/or server output (if relevant):\*\*
> 
> \*\*Any additional context (logs, chat logs, magical formulas, etc.):\*\*
> 
> I tried testing with a different method. I tried using Log threshold, and that works fine. Alert becomes active, and the trigger happens and the index is populated. Note I tried the same setup on a completely separate cluster, same thing happens.

---

_[View the full topic](https://discuss.elastic.co/t/custom-threshold-not-triggering-alert-to-index/377531)._
