# Elastic Log Threshold rule problem

**URL:** <https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [April 3, 2023, 1:19pm UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213 "2023-04-03T13:19:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![amityahav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amityahav/32/119362_2.png) [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Post date:** [April 3, 2023, 1:19pm UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213/1 "2023-04-03T13:19:51Z")

</div>

Hey there, i've been experimenting with log threshold type of rules recently and i've encountered some strange behaviors. Elastic version is 8.6.2

given a log threshold rule with action connector of some index.

1. When disabling i would expect that a 'resolve' event would be sent to the connector for each active alert that lived while the rule was enabled. Isn't it the case?

2. When enabling the rule, actions are being triggered and events are written to the index, everything is working fine, but when i disable and then re-enable the alert become active again but it has no start date and duration in the kibana ui -  

Thanks

---

<div class="post-metadata">

**Author:** ![amityahav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amityahav/32/119362_2.png) [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Post date:** [April 3, 2023, 1:27pm UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213/2 "2023-04-03T13:27:34Z")

</div>

This is the rule:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/2/92a932af5a6e7a9656d385626acf90e0048ded2c.jpeg)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4abb418d857a91e683bf51a13ebce6d1167ceb7.jpeg)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3e67235c344d62497201d4a6693561e1d3f7482.png)

---

<div class="post-metadata">

**Author:** ![faisal-k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisal-k/32/103817_2.png) [@faisal-k](https://discuss.elastic.co/u/faisal-k)\
**Post date:** [April 4, 2023, 12:10pm UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213/3 "2023-04-04T12:10:20Z")

</div>

Hi @amityahav, welcome to the Elastic community!

Regarding your questions:

> 1. When disabling i would expect that a 'resolve' event would be sent to the connector for each active alert that lived while the rule was enabled. Isn't it the case?

Disabling the rule, will not allow the rule to rerun and check the status of the alerts, whether they are `Active`/`Recovered`. So the alerts stay at their last state and no event is sent via connectors.

> 1. When enabling the rule, actions are being triggered and events are written to the index, everything is working fine, but when i disable and then re-enable the alert become active again but it has no start date and duration in the kibana ui -

The screenshot you posted is not very clear to know from which page it has been taken, but I aussme it's from the Stack Mangement \> Rules page.

For Observability rule types, I would suggest using the Alerts pages under Observability.

 ![Screenshot 2023-04-04 at 14.03.13](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0ddc0516ac26e99d23a5cf4d39d74bb6c0cf161f.png)

You would have the Alerts table with all the info you might look for.

 ![Screenshot 2023-04-04 at 14.03.59](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3cdad5bb614576c4eae12f07aab4aec65fdc12dd.png)

I hope that will help!

Faisal

---

<div class="post-metadata">

**Author:** ![amityahav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amityahav/32/119362_2.png) [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Post date:** [April 5, 2023, 10:08am UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213/4 "2023-04-05T10:08:00Z")

</div>

Hey thanks for the reply,  
basically what i don't understand is why after re-enabling the rule and the condition is satisfied, nothing is written to my index connector

---

<div class="post-metadata">

**Author:** ![benakansara](https://avatars.discourse-cdn.com/v4/letter/b/c2a13f/32.png) [@benakansara](https://discuss.elastic.co/u/benakansara)\
**Post date:** [April 11, 2023, 10:03am UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213/5 "2023-04-11T10:03:40Z")

</div>

Hi @amityahav ,

There is a known issue regarding Start time and Duration being empty in the UI in the Stack Management \> Rules \> Rule Name \> Alerts.

> <https://github.com/elastic/kibana/issues/144929>
>
> While looking at some live data, I happened to notice that we are storing framew…ork-required data in the alert task state, which is designed to be used only by the rule executors.
> 
> Here's an example:
> 
> \<details\>
> \<summary\>example task state JSON blob\</summary\>
> 
> \`\`\`json
> {
> "alertInstances": {
> "host-1": {
> "state": {
> "start": "2022-11-08T21:34:59.929Z",
> "duration": "0"
> },
> "meta": {
> "lastScheduledActions": {
> "group": "threshold met",
> "date": "2022-11-08T21:34:59.942Z"
> }
> }
> },
> "host-2": {
> "state": {
> "start": "2022-11-08T21:34:59.929Z",
> "duration": "0"
> },
> "meta": {
> "lastScheduledActions": {
> "group": "threshold met",
> "date": "2022-11-08T21:35:00.682Z"
> }
> }
> }
> },
> "previousStartedAt": "2022-11-08T21:34:59.474Z"
> }
> \`\`\`
> 
> \</details\>
> 
> The fields \`alertInstances.\*.state\` is for rules to store alert-specific state for the next run, and \`alertInstances.\*.meta\` is for the alerting framework to store it's own alert task state.
> 
> However, the \`start\` and \`duration\` fields are generated by the framework, and should be in \`meta\`, not \`state\`.
> 
> Those fields are currently populated here: https://github.com/elastic/kibana/blob/bf3ee9e393b00bce2095ccf7ad6c8693ea1837ca/x-pack/plugins/alerting/server/lib/process\_alerts.ts#L70-L83
> 
> To make matters worse, rule types use the \`.replaceState()\` API themselves, which will usually end up removing our fields. For instance, the ES query rule does that here:
> 
> https://github.com/elastic/kibana/blob/64c3c63e21009719a99e5cebe47859d0c63ce93b/x-pack/plugins/stack\_alerts/server/rule\_types/es\_query/executor.ts#L87-L90
> 
> The result of this is that we don't write the correct start/duration to the event log, so subsequent queries against the event log won't have the data and display blank. For example, in the alerts page of a rule - the alert is listed, but there is no duration or start time. Hacking that code real quick to copy the existing \`start\` and \`duration\` into the \`replaceState()\` will get the start and duration to show up in that UX.
> 
> Some obvious things we will need to do:
> 
> \- update the \`meta\` type to include \`start\` and \`duration\`
> \- migration to move any existing \`start\` and \`duration\` fields from \`state\` to \`meta\`
> \- change the code to write to \`meta\` instead of \`state\`
> 
> There is likely a quicker fix if we want to get something out sooner which isn't a complete fix but would likely get the start / duration in the event log, and alerts UX working. The idea would be to modify \`replaceStart()\` to always copy over existing \`start\` and \`duration\` fields, if they exist in the current state. Not sure it's worth doing this, since it's not a complete fix - and I'm just guessing this would work and wouldn't cause additional problems :-)

The reason nothing is being written to index connector is that the alert is technically still active in your case even though it shows "recovered" in UI when you disable the rule. When the rule is enabled again, the same alert's status is changed to "active". It is not a new alert. Only if the status of the alert actually changed to "recovered" in the meantime (below threshold), it will be written to the index connector as per rule configuration (Notify = On status changes). You could change "Notify" option to "On check intervals" to receive notification to the index connector at every check regardless of the status (this will result in more number of notifications).

I would recommend to use Observability \> Alerts to view correct start/duration of the alerts. The status of the alert remains as is (Active/Recovered) when the rule is disabled which is more accurate indication as the rule is no longer running to check the status.

I hope that helps.

-Bena
