# Is it possible to acknowledge an alert / watcher?

**URL:** https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540
**Category:** Elasticsearch
**Tags:** elastic-stack-alerting
**Created:** [October 26, 2022, 2:54pm UTC](https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540 "2022-10-26T14:54:00Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)
#### Post date: [October 26, 2022, 2:54pm UTC](https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540/1 "2022-10-26T14:54:00Z")

</div>

Hello, is it possible to acknowledge an alert?

Let's imagine that every 10 minutes, an application sends to Elasticsearch an information telling me if there is an error or not :

The application send me two kind of data :  
`Host : host1 and Status : OK`  
or  
`Host : host1 and Status : Error`

So, i want to create an alet when the application send me an error. This is EASY no problemo.  
But after, if the problem is fixed, the application will send me `Status : OK` (because the error is fixed). And then, I want to resend an alert who said :

> "Your error on Host1 is fixed"

How can i do this ? Knowing that I receive data from several hosts

Thanks.

---

<div class="post-metadata">

### Author: ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)
#### Post date: [October 26, 2022, 3:13pm UTC](https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540/2 "2022-10-26T15:13:04Z")

</div>

> [@GinkoLucas](#):
>
> But after, if the problem is fixed, the application will send me `Status : OK` (because the error is fixed). And then, I want to resend an alert ...

Kibana alerting has a concept of "recovered" alert status. Once an alert is active, the next time the rule runs and that alert is NOT active, it will fire the "recovered" action. You need to configure that action separately, and it can be different from the "active" alert action.

For more info: [Create and manage rules | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/create-and-manage-rules.html#defining-rules-actions-details)

Note: the other constraint is you want a rule that operates over multiple possible alerts during the same run. I'd look at index threshold and metric threshold rule types for that. The elasticsearch query rule type only generates a single alert each run (whether the count of the returned search docs met a threshold).

---

<div class="post-metadata">

### Author: ![GinkoLucas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ginkolucas/32/107055_2.png) [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)
#### Post date: [November 2, 2022, 2:57pm UTC](https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540/3 "2022-11-02T14:57:30Z")

</div>

Hello Patrick,

I will try this thanks.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 30, 2022, 2:58pm UTC](https://discuss.elastic.co/t/is-it-possible-to-acknowledge-an-alert-watcher/317540/4 "2022-11-30T14:58:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
