# How to only send an alert when severity is high

**URL:** https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263
**Category:** SIEM
**Created:** [December 21, 2020, 2:02pm UTC](https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263 "2020-12-21T14:02:28Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)
#### Post date: [December 21, 2020, 4:05pm UTC](https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263/2 "2020-12-21T16:05:44Z")

</div>

Hi @willemdh!

This definitely sounds like really useful functionality. I found a few resources that may be of use here and could satisfy the behavior you are looking for.

Have you heard of building block rules? In your stated case, you could mark the rule in your example as a building block rule. This would still create the alerts but hide them from the UI so that they don't create unnecessary noise. Then you could create a rule that searches the alerts index for those with high severity. You can find info on building block rules [here](https://www.elastic.co/guide/en/security/current/building-block-rule.html).

This other forum [post](https://discuss.elastic.co/t/siem-threshold-unique-values/246606) might also be of help.

Let us know if those resources address your use case or if we can be of any further help.

Best,  
Yara

---

_[View the full topic](https://discuss.elastic.co/t/how-to-only-send-an-alert-when-severity-is-high/259263)._
