# ELK 8.x Unable to create "Log threshold" Alert Rule for new Index - "There aren't any options available"

**URL:** <https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 22, 2022, 10:02am UTC](https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933 "2022-09-22T10:02:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cezary](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@Cezary](https://discuss.elastic.co/u/Cezary)\
**Post date:** [September 22, 2022, 10:02am UTC](https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933/1 "2022-09-22T10:02:47Z")

</div>

Hello Guys,

- Fresh install of ELK 8.x
- New index syslog-\* created via logstash

Logstash config:

```auto
input {
  tcp {
    port => 5000
    type => syslog
    mode => "server"
    ssl_enable => true
    ssl_verify => false
    ssl_cert => "/etc/logstash/ssl/logstash.crt"
    ssl_key => "/etc/logstash/ssl/logstash.key"
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["ip", "%{[@metadata][input][tcp][source][ip]}" ]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://localhost:9200"]
    user => "logstash_internal"
    password => "password"
    ssl => true
    ssl_certificate_verification => false
    index => "logs-%{+YYYY.MM.dd}"
  }
  file {
    path => "/log/%{+YYYY.MM.dd}/%{syslog_hostname}/%{syslog_hostname}-%{ip}.gzip"
    gzip => true
  }

}

```

Logstash user role:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46b8b830924e6c05c068ae1d0c9319c3823c4029.png)

Kibana rule creation issue:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/2217a7de64b046e60b2007e8fd145be49afddbaa.png)

Data view:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/396ddefc93ea9abcbec9ff4c3f3414fe3c8a2289.png)

- However when I setup Logstash output to default kibana "Data view" - logs-\* then I'm able to create Alert Rule.

Am I missing something?  
Please help!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 22, 2022, 7:27pm UTC](https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933/2 "2022-09-22T19:27:24Z")

</div>

Hi @Cezary Welcome to the community!

So the Logs Threshold is Aligned with the Logs viewer / Streaming etc...

Pretty Sure you need to add your index pattern to the logs settings comma separated _ **no spaces** _ for the alerts to work the way you want

Or you can add it as a data view (but you can only add 1 data view)

 ![Screen Shot 2022-09-22 at 12.23.09 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2ea971377b4e5414aed6a02a71df29bce29f1011.png)

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 30, 2022, 3:43pm UTC](https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933/3 "2022-09-30T15:43:11Z")

</div>

Had the same issue, that helped. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2022, 3:43pm UTC](https://discuss.elastic.co/t/elk-8-x-unable-to-create-log-threshold-alert-rule-for-new-index-there-arent-any-options-available/314933/4 "2022-10-28T15:43:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
