# Kibana alerts to notify only if the error persisted in the last 1 hour

**URL:** <https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [October 3, 2022, 12:08pm UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683 "2022-10-03T12:08:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [October 3, 2022, 12:08pm UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683/1 "2022-10-03T12:08:25Z")

</div>

I am scanning a time series index of logs and sending an alert every hour if an error occurred, the check is happening every min. But I would like to like to send the alerts only if the error was repeated in the last hour, meaning if it occurred one time or within a small time range then stopped then no alert should be sent . Is there a way to achieve that?

Index mapping:

```auto
{
  "test-index": {
    "mappings": {
      "dynamic": "false",
      "properties": {
        "@internal": {
          "properties": {
            "event_lag": {
              "type": "long"
            }
          }
        },
        "@timestamp": {
          "type": "date"
        },
        "app": {
          "log": {
            "level": {
              "type": "keyword"
            },
            "message": {
              "type": "text"
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 27, 2022, 11:33am UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683/2 "2022-10-27T11:33:39Z")

</div>

I'm not an expert but this seems to be a use case for Elasticsearch [Event Query Language](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/eql.html) (EQL) and the [Security solution alert](https://www.elastic.co/guide/en/security/current/detection-engine-overview.html) of "event correlation" type.

The main point here (if I understood correctly) is that you want to find two or more events that happened within a defined amount of time so this does not fit the regular stack rule types.

I'd suggest to review the documentation and overall structure of the Security solution and if it fits your requirements start playing with it and feel free to open new posts at the [Security subforum](https://discuss.elastic.co/c/security/83).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 9:43am UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683/3 "2022-11-24T09:43:49Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2022, 6:38am UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683/4 "2022-12-22T06:38:22Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2023, 6:38am UTC](https://discuss.elastic.co/t/kibana-alerts-to-notify-only-if-the-error-persisted-in-the-last-1-hour/315683/5 "2023-01-19T06:38:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
