# How to get more filter in the "alarm" system

**URL:** <https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429>\
**Category:** Kibana\
**Created:** [June 16, 2022, 3:14pm UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429 "2022-06-16T15:14:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zarzaparro](https://avatars.discourse-cdn.com/v4/letter/z/7ea924/32.png) [@Zarzaparro](https://discuss.elastic.co/u/Zarzaparro)\
**Post date:** [June 16, 2022, 3:14pm UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/1 "2022-06-16T15:14:11Z")

</div>

Hello! I'm working with Kibana and I need to know if something I need can be done.

I'm creating alerts from the system, and as I can see I only can create on single filter (see the screenshot attached)

![2022-06-16_17h09_12](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28855f7ef23e64e23fbfed9f9bde46b457627a6c.png)

I would need somewho to get this done:

Get an alarm raised when an error 503 appears in the logs 3 or more times, in a proper field (for this example: http\_status\_code field is 503). BUT if I do this, I get lots of false alarms, because this error can come from various "hosts" defined in other field called "host".

I can set the trigger to raise and alarm when 3 or more 503 errors appear in the logs, but I need the system to separate the host when an error appears.

Example:

For the last 5 minutes I get logs from two hosts with this information:

Host:number 1  
http\_status\_code: 503  
Host:number 1  
http\_status\_code: 503

Host:number two  
http\_status\_code: 503  
Host:number two  
http\_status\_code: 503

Now I will get an alarm, becasuse I got 4 errors 503, but I don't want that, because I only want the alarm to rise when I get this error 3 or more times in THE SAME host.

Can this be done somehow?

Any help?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [June 17, 2022, 7:23pm UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/2 "2022-06-17T19:23:19Z")

</div>

@Patrick_Mueller / @ying.mao can we please get some help? Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [June 21, 2022, 11:46am UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/3 "2022-06-21T11:46:30Z")

</div>

The UX here doesn't appear to be Kibana - is this OpenSearch? If this does happen to be Kibana, what rule type is this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2022, 11:46am UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/4 "2022-06-21T11:46:30Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![Zarzaparro](https://avatars.discourse-cdn.com/v4/letter/z/7ea924/32.png) [@Zarzaparro](https://discuss.elastic.co/u/Zarzaparro)\
**Post date:** [June 21, 2022, 2:16pm UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/5 "2022-06-21T14:16:24Z")

</div>

> [@Patrick\_Mueller](#):
>
> OpenSearch

Yes, it's OpenSearch. Sorry about that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2022, 2:16pm UTC](https://discuss.elastic.co/t/how-to-get-more-filter-in-the-alarm-system/307429/7 "2022-07-19T14:16:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
