# "How can I divide a rule into specific time frames in Kibana?

**URL:** https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [July 26, 2024, 5:02am UTC](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815 "2024-07-26T05:02:54Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Marek\_Galbavy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marek_galbavy/32/132943_2.png) [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)
#### Post date: [July 26, 2024, 5:02am UTC](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815/1 "2024-07-26T05:02:54Z")

</div>

For example, if I want a rule to check logs every 10 hours and apply a 1-hour span for analysis, how would I set this up?"  
This is my rule:  
from logs-\*  
| WHERE (CIDR\_MATCH(source.ip, "10.0.0.0/8") OR CIDR\_MATCH(source.ip, "172.16.0.0/12") OR CIDR\_MATCH(source.ip, "192.168.0.0/16")) and url.domain is not null and @timestamp \>= now() - 60seconds  
| stats upload = sum(source.bytes) by url.domain, source.ip  
| where upload \>= 600

i want start this rule every hour but i want to sum data for minutes blocks.

In splunk exists span, but in kibana i dont kno about alternative.

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [July 29, 2024, 9:05pm UTC](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815/2 "2024-07-29T21:05:54Z")

</div>

@Patrick_Mueller / @ying.mao can we please get some help here?

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)
#### Post date: [July 29, 2024, 11:09pm UTC](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815/3 "2024-07-29T23:09:05Z")

</div>

For the Elasticsearch Query rule type, using ES|QL, you don't need to apply the `@timestamp >= now() - 60seconds` condition, as the rule adds a filter for this automatically, based on the **Time Window** parameter.

However, I'm guessing this may not work for your purpose anyway, as it sounds like you need some partitioning / grouping and I assume want to alert on individual partitions / groups.

Currently the rule generates an alert if the search returns ANY matches. So you would need to construct an ES|QL query to work in that fashion.

I can't really help on ES|QL directly, I've used it a bit but am far from an expert. I suggest you post a new question with ES|QL in the title, describing what you'd like to query, and hopefully we can get someone more knowledgeable to help out.
