# How to set up alerts triggered by an unknown factor?

**URL:** <https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 23, 2019, 8:04am UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642 "2019-09-23T08:04:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tic89](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tic89](https://discuss.elastic.co/u/tic89)\
**Post date:** [September 23, 2019, 8:04am UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642/1 "2019-09-23T08:04:56Z")

</div>

Hello experts,

I would like to set up an alert that follows a logic like:

Trigger when:text:"ErrorCode: 1036", IP count \> 5, now-1h, where the IP is an unknown constant.

I end up where I always need to specify the IP in advance or manually review a dashboard to get the information that I want rather than have it as an automated watcher alert.

Is it possible to modify the following watcher alert set up for a known specified IP to trigger for count \>5 for an unknown IP ?

Ex.  
//  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "application\_name: "auth" AND level: "ERROR" AND text: "ErrorCode: 1036"",  
"analyze\_wildcard": true,  
"default\_field": "\*"  
}  
},  
{  
"match\_phrase": {  
"remote\_address": {  
"query": "185.188.92.1"  
}  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-1h",  
"lte": "now"  
}  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 5  
}  
}  
},

//  
Thanks in advance for any help on this!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 24, 2019, 8:26am UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642/2 "2019-09-24T08:26:26Z")

</div>

try using an aggregation, that aggregates on the IP, so that you can see if there is a bucket, with a document count \> 5... if there is one or more ip addresses with a count greater than five you will see it.

---

<div class="post-metadata">

**Author:** ![tic89](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@tic89](https://discuss.elastic.co/u/tic89)\
**Post date:** [September 24, 2019, 11:26am UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642/3 "2019-09-24T11:26:14Z")

</div>

Hi Alexander,

Than you for your input

If I understand you correctly and translate this into the Alert format, I get something like this:

//  
"input": {  
"search": {  
"request": {  
"search\_type": "query\_then\_fetch",  
"indices": [  
"_:egencialogs-_"  
],  
"types": ,  
"body": {  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "application\_name:"auth" AND level:"ERROR" AND text:"ErrorCode: 1036" AND text:"ErrorMessage"",  
"analyze\_wildcard": true,  
"default\_field": "\*"  
}  
},  
{  
"range": {  
"@timestamp": {  
"gte": "now-1h",  
"lte": "now"  
}  
}  
}  
]  
}  
},  
"aggs": {  
"ip\_count": {  
"terms": {  
"field": "remote\_address"  
}  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.aggregations.ip\_count.buckets.0.doc\_count": {  
"gte": 5  
}  
}  
},

//

My simulations works without errors, but did not trigger (yet, if done correctly as intended)

I am not entirely sure if my condition: ""ctx.payload.aggregations.ip\_count.buckets.0.doc\_count": {  
"gte": 5"

- Is this how it should be written?

Tobias

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 24, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642/4 "2019-09-24T13:18:56Z")

</div>

you can use the [Execute Watch API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/watcher-api-execute-watch.html) to configure an alternative input, that should make your condition trigger in order to check if everything is working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 1:19pm UTC](https://discuss.elastic.co/t/how-to-set-up-alerts-triggered-by-an-unknown-factor/200642/5 "2019-10-22T13:19:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
