# Kibana alert rule behavior

**URL:** https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [November 28, 2022, 12:37am UTC](https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896 "2022-11-28T00:37:44Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![vangap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vangap/32/44927_2.png) [@vangap](https://discuss.elastic.co/u/vangap)
#### Post date: [November 28, 2022, 12:37am UTC](https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896/1 "2022-11-28T00:37:44Z")

</div>

Hi,

I am exploring the Kibana alerts feature by creating rules and trying to index the actions in an index..  
I have it working, though the behavior of it seems unexpected (atleast from where I am standing)..

The rules interface has this note

> If the time window is greater than the check interval and a document matches the query in multiple runs, it is used in only the first threshold calculation.

If I understand this correctly based on the behavior that I am seeing, if some documents matched in the earlier rule run, they will not be considered to evaluate against the threshold in the next run..

for ex, I set `check every` to 1 minute so that I get alerted as early as possible when things go wrong..  
and, if I set `time window` to 120 minutes; even though there may be errors in last 120 minutes, alarm may not be considered active if errors didn’t happen between the last run and now (which is basically, last 1 minute)..

so, I might as well set the time window to 1. When would one want to set a very high value for `time window` compared to `Check every`?

(Ideally, what I am looking for is "Alert when the number of errors/timeperiod is greaterr than a certain threshold for last N time periods", similar to AWS Cloudwatch alerting behavior)

Thanks.

---

<div class="post-metadata">

### Author: ![vangap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vangap/32/44927_2.png) [@vangap](https://discuss.elastic.co/u/vangap)
#### Post date: [December 1, 2022, 12:46am UTC](https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896/2 "2022-12-01T00:46:24Z")

</div>

This has been addressed in 8.5 version according to @Patrick_Mueller on Elastic slack

> <https://github.com/elastic/kibana/issues/116970>
>
> When creating an Elasticsearch query alerting rule, the user is prompted to choo…se when actions should be created when the query matches more than the specified number of documents for a specific time frame:
> 
> \<img width="584" alt="Screen Shot 2021-11-01 at 6 55 45 AM" src="https://user-images.githubusercontent.com/627123/139683353-60d22db1-b41f-4c3b-97f6-43e2298efc0e.png"\>
> 
> The following are example time frames that are queried for an Elasticsearch query alerting rule that runs every 1 minute and queries documents for the last 5 minutes and hasn't identified any actions that should be executed:
> 
> | execution | from | to | duration |
> | ---- | ---- | ---- | ---- |
> | 1 | 2021-11-01T15:23:03.594Z | 2021-11-01T15:28:03.594Z | 5 minutes |
> | 2 | 2021-11-01T15:24:06.624Z | 2021-11-01T15:29:06.624Z | 5 minutes |
> | 3 | 2021-11-01T15:25:09.630Z| 2021-11-01T15:30:09.630Z | 5 minutes |
> 
> However, when the alerting rule identifies the specified condition, the following time frames are queried because an \[additional filter clause is added\](https://github.com/elastic/kibana/blob/3c8fa527a7765723d3851afe067315359a4763e7/x-pack/plugins/stack\_alerts/server/alert\_types/es\_query/alert\_type.ts#L184-L208):
> 
> | execution | from | to | duration |
> | ---- | ---- | ---- | ---- |
> | 1 | 2021-11-01T15:29:53.755Z | 2021-11-01T15:31:12.665Z | ≈ 1 minute 19 seconds |
> | 2 | 2021-11-01T15:29:53.755Z | 2021-11-01T15:32:15.647Z | ≈ 2 minutes 22 seconds |
> | 3 | 2021-11-01T15:29:53.755Z | 2021-11-01T15:33:18.674Z | ≈ 3 mintues 24 seconds |
> 
> This will invalidate the user's intention to execute an action when the threshold crosses a certain amount for the specified time frame because the time frame has been automatically adjusted.

> <https://github.com/elastic/kibana/pull/138781>
>
> fixes: #116970
> 
> For ESQuery rule type, we modify the time span given by the us…er (FOR THE LAST "X") to avoid duplicated results between consecutive rule executions. We use the last document's timestamp in an execution as start time of the next execution, which means modifying the params given by the user.
> 
> This PR intends to make this behaviour optional by adding a checkbox in to the rule create/update form.
> 
> Default value would be "true", so we don't need to migrate the existing rules.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 28, 2022, 10:29pm UTC](https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896/3 "2022-12-28T22:29:34Z")

</div>



---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 25, 2023, 10:29pm UTC](https://discuss.elastic.co/t/kibana-alert-rule-behavior/319896/4 "2023-01-25T22:29:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
