# How is Alert Recovery Decided?

**URL:** <https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [December 22, 2023, 6:39pm UTC](https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874 "2023-12-22T18:39:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![shiktec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shiktec/32/122280_2.png) [@shiktec](https://discuss.elastic.co/u/shiktec)\
**Post date:** [December 22, 2023, 6:39pm UTC](https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874/1 "2023-12-22T18:39:42Z")

</div>

Hi Guys,  
Have a scenario based questions on alerting , How does ES decides if an alert is "recovered"? Whats the core logic ?  
i am setting Airflow DAG failure alerts , i receive a document which contains fields ` DAG:xyz State: Failed` and i create a search alert rule saying i need to search for any document which contains "State: Failed" for all the DAGs for the last 30 minutes , and i run this check every 15 minutes.  
The condition is met and the ALERT is in ACTIVE state. But after 30 minutes ( 2 runs) i can see that the ALERT is "RECOVERED" , but the last run of my dag is still failed , because there is no success or another failure there is no new document after 30 minutes which the search could find and i think because of that it has marked it "RECOVERED", Is this the right way to mark any alert recovered ?

how do i set this alert correctly

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6a736bd41290de6ef03cf064c701ec7eaee1abfe.jpeg)

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [December 24, 2023, 2:16pm UTC](https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874/2 "2023-12-24T14:16:42Z")

</div>

> [@shiktec](#):
>
> Hi Guys,  
> Have a scenario based questions on alerting , How does ES decides if an alert is "recovered"? Whats the core logic ?  
> i am setting Airflow DAG failure alerts , i receive a document which contains fields ` DAG:xyz State: Failed` and i create a search alert rule saying i need to search for any document which contains "State: Failed" for all the DAGs for the last 30 minutes , and i run this check every 15 minutes.  
> The condition is met and the ALERT is in ACTIVE state. But after 30 minutes ( 2 runs) i can see that the ALERT is "RECOVERED" , but the last run of my dag is still failed , because there is no success or another failure there is no new document after 30 minutes which the search could find and i think because of that it has marked it "RECOVERED", Is this the right way to mark any alert recovered ?
> 
> how do i set this alert correctly

Hi,

To keep the alert active until the DAG run is successful, you need to adjust your alert condition. Instead of checking for "State: Failed" documents in the last 30 minutes, you could check for the absence of a "State: Success" document for the specific DAG in the last 30 minutes. This way, the alert will remain active until a successful run of the DAG.

Regards
