# ElastAlert : multiple query against multiple indices in same rule file

**URL:** <https://discuss.elastic.co/t/elastalert-multiple-query-against-multiple-indices-in-same-rule-file/82700>\
**Category:** Elasticsearch\
**Created:** [April 18, 2017, 10:54am UTC](https://discuss.elastic.co/t/elastalert-multiple-query-against-multiple-indices-in-same-rule-file/82700 "2017-04-18T10:54:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [April 18, 2017, 10:54am UTC](https://discuss.elastic.co/t/elastalert-multiple-query-against-multiple-indices-in-same-rule-file/82700/1 "2017-04-18T10:54:37Z")

</div>

Hi,  
I have created 2 separate rule files , which are as follows:-  
//--------------------------------------------------------  
realert:  
&nbsp;&nbsp;minutes: 5  
from\_addr: [test@email.com](mailto:test@email.com)  
es\_host: xx.xx.xxx.xx  
index: topbeat-\*  
smtp\_host: [ismtp.corp.company.com](http://ismtp.corp.company.com)  
type: frequency  
es\_port: 9200  
filter:  
&nbsp;-&nbsp;range:  
&nbsp;&nbsp;&nbsp;&nbsp;mem.used\_p:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;from: 0.70  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;to: 1.0  
&nbsp;-&nbsp;term:  
&nbsp;&nbsp;&nbsp;&nbsp;beat.hostname: xxxxx  
timeframe:  
&nbsp;&nbsp;minutes: 30  
alert: email  
name: 9\_\_server\_\_xxxxx\_\_mem.used\_p\_\_0.70\_\_30  
email: ["user@email.com"]  
num\_events: 1  
//------------------------------------------------------------  
//------------------------------------------------------------  
realert:  
&nbsp;&nbsp;minutes: 5  
from\_addr: [test@email.com](mailto:test@email.com)  
es\_host: xx.xx.xxx.xx  
index: packetbeat-\*  
smtp\_host: [ismtp.corp.company.com](http://ismtp.corp.company.com)  
type: frequency  
es\_port: 9200  
filter:  
&nbsp;-&nbsp;term:  
&nbsp;&nbsp;&nbsp;&nbsp;http.code: 404  
&nbsp;-&nbsp;term:  
&nbsp;&nbsp;&nbsp;&nbsp;beat.hostname: yyyyy  
timeframe:  
&nbsp;&nbsp;minutes: 30  
alert: email  
name: 25\_\_app\_\_yyyyy\_\_http.code\_\_404\_\_1\_\_30  
email: ["user@email.com"]  
num\_events: 1  
//------------------------------------------------------------

Both rule files are generating emails as per their definition.

Is there any way to have these two rule files as a single rule file.  
where I might need to define, index:topbeat-,packetbeat-  
Then in that case how I need to write filters, so that mem.used\_p is queried against topbeat-\* for server xxxxx and http.code is queried against packetbeat-\* for server yyyyy. ???

---

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [April 19, 2017, 1:36pm UTC](https://discuss.elastic.co/t/elastalert-multiple-query-against-multiple-indices-in-same-rule-file/82700/2 "2017-04-19T13:36:14Z")

</div>

Hi,  
Can anybody please reply for the above issue.  
Is it possible in elastalert that we query topbeat-\* index for some condition1  
and packetbeat-\* index for some other condition2, and generate mail only if both condtion are satisfied.  
If yes, then what will be the syntax for that approach ??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2017, 1:40pm UTC](https://discuss.elastic.co/t/elastalert-multiple-query-against-multiple-indices-in-same-rule-file/82700/3 "2017-05-17T13:40:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
