# Kibana Log Threshold Alert Rule Trigger Problem when using multiple conditions

**URL:** <https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [January 29, 2026, 1:59pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795 "2026-01-29T13:59:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![manzer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manzer/32/113604_2.png) [@manzer](https://discuss.elastic.co/u/manzer)\
**Post date:** [January 29, 2026, 1:59pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/1 "2026-01-29T13:59:17Z")

</div>

Hi,

I have created many alert rules in Kibana, however currently I am facing a strange issue, when I create Log Threshold Rule with single condition it is working file and Triggering the alert, but if I add multiple conditions to it, alert is not getting triggered, to validate I have checked log count in Discover section with the same condition and time range/window and it is showing the documents

KQL : service.name : "aem-shared-a-publisher-service" AND http.response.status\_code : 429

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c97731dd7fcc9d3b0d81de870ec4c0ce4e0edb0e.png)

service.name field type is keyword

http.response.status\_code field type is long

Alert Rule :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79ff0034147636a0a1bdcc6d73fb4acbbe285778.png)

Kibana Version : 8.5.3

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 30, 2026, 4:10am UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/2 "2026-01-30T04:10:36Z")

</div>

Hi @manzer Welcome to the community

First always tell us the version.

Open These... and look

 ![Screenshot 2026-01-29 at 8.02.58 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36f999369f066a29709893591d62e867fa758524.jpeg)

So I set mine up with some logs...

 ![Screenshot 2026-01-29 at 8.08.42 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a4d0e11ff7586779d0bbf6134117840de5da449.png)

And it worked and

> stephenb-es-integrationAPP [8:05 PM](https://elastic.slack.com/archives/GC7N35CRY/p1769745952547639)
> 
> 532 log entries in the last 5 mins. Alert when \> 75.stephen discuss test Log threshold rule is active.532 log entries have matched the following conditions: k8s.container.name equals cart and service.name equals cart[View alert details](https://k8s-demo-stephenb.kb.us-west1.gcp.cloud.es.io/app/observability/alerts/1a7ad39c-062e-4f84-a11b-822f127ec689)

---

<div class="post-metadata">

**Author:** ![manzer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manzer/32/113604_2.png) [@manzer](https://discuss.elastic.co/u/manzer)\
**Post date:** [February 1, 2026, 7:26am UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/3 "2026-02-01T07:26:13Z")

</div>

Hi @stephenb ,

Thank you for the response !

I had mentioned the version : 8.5.3 🙂

Please find the expanded screenshot below. conditions are meeting, however Alert are not getting trigged

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f462be78bf837858cd4ba5aa8cbeb1e45bb5798.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15dc904ede36dc0c58c05910ab8b9715c8a4a653.png)

Also, as mentioned in my 1st post, it is working for me for other Alert rules, but not this one, I also tried only one condition at a time just to test, individually both of them are working fine and triggering the alerts, but not working together

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 1, 2026, 12:46pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/4 "2026-02-01T12:46:59Z")

</div>

Can you run the same query in Discover for the same time interval and share the result?

Use the query bellow looking for the last 24 hours

`service.name: "aem-shared-a-publisher-service" and http.response.status_code: 429`

---

<div class="post-metadata">

**Author:** ![manzer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manzer/32/113604_2.png) [@manzer](https://discuss.elastic.co/u/manzer)\
**Post date:** [February 1, 2026, 1:36pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/5 "2026-02-01T13:36:46Z")

</div>

Hi @leandrojmp ,

SS Below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d36ad53893889284bc7a8a84dddff700202fc8b4.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 1, 2026, 3:26pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/6 "2026-02-01T15:26:44Z")

</div>

@manzer

Sorry I missed the version 8.5 is very old and lots of updates and fixes especially with respect to alerts you should think about getting to 8.19.x in prep to 9.x

When you say the alert is not triggered where are you checking/ to validating that?

Have you deleted the rule and recreated it.

If it is working for 1 alert not the other it is usually the alert condition itself

You could test with elasticsearch query rule with your KQL

---

<div class="post-metadata">

**Author:** ![manzer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manzer/32/113604_2.png) [@manzer](https://discuss.elastic.co/u/manzer)\
**Post date:** [February 1, 2026, 4:31pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/7 "2026-02-01T16:31:13Z")

</div>

@stephenb

Agree with you point on considering to upgrade the cluster, however I am not sure that I can achieve it now due to other dependencies.

I already have many alert rules configured and those are working fine, based on our new requirement I was trying to create this new alert rule, and observed this unexpected behavior

I have already tested KQL and it is Discover (pasted the output in previous post)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 1, 2026, 5:20pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/8 "2026-02-01T17:20:26Z")

</div>

> [@manzer](#):
>
> I have already tested KQL and it is Discover (pasted the output in previous post)

yes understood

> [@stephenb](#):
>
> You could test with elasticsearch query rule with your KQL

> **[Create an Elasticsearch query rule | Kibana Guide \[8.19\] | Elastic](https://www.elastic.co/guide/en/kibana/8.19/rule-type-es-query.html)**

Version 8.19

> In **Stack Management** \> **Rules** , click **Create rule**. Select the **Elasticsearch query** rule type then fill in the name and optional tags. An Elasticsearch query rule can be defined using Elasticsearch Query Domain Specific Language (DSL), Elasticsearch Query Language (ES|QL), Kibana Query Language (KQL), or Lucene.

But KQL alert is not available in 8.5 ☹ .... You could try the DSL Rule with the same conditions

My Guess there is some bug / behavior or something,  
I noticed that the status code is numeric.  
But the query is perhaps treated as a keyword etc... which should be fine but maybe it is not

> The comparators available for conditions depend on the chosen field. The combinations available are:

> - Numeric fields: **more than** , **more than or equals** , **less than** , or **less than or equals**.
> - Aggregatable fields: **is** and **is not**.
> - Non-aggregatable fields: **matches** , **does not match** , **matches phrase** , **does not match phrase**.

Maybe you should treat as a Numbers More than or Equal 429 or something

Really, before spending too much time, I would work on upgrading. 8.5 is 3.5 years old.... a lifetime in Elasticsearch world.

In 8.19 you will have many more choices ESQL rules are quite powerful...

---

<div class="post-metadata">

**Author:** ![manzer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manzer/32/113604_2.png) [@manzer](https://discuss.elastic.co/u/manzer)\
**Post date:** [February 1, 2026, 5:54pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795/9 "2026-02-01T17:54:57Z")

</div>

@stephenb  
Thanks a lot for the details and your quick responses, much appreciated 🫡 ,

I will give a try to your suggestions !
