# Kibana rule false positivie

**URL:** <https://discuss.elastic.co/t/kibana-rule-false-positivie/334025>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [May 22, 2023, 2:06pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025 "2023-05-22T14:06:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![amityahav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amityahav/32/119362_2.png) [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Post date:** [May 22, 2023, 2:06pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025/1 "2023-05-22T14:06:30Z")

</div>

Hey there,  
We have alerting rules in our company which are triggered even though it seems that they shouldnt

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2f23795c48d9d9640c462c5e8bbec78a166da78.jpeg)

in this example i've configured the alert to trigger when then number of docs is below 75k for the last 30mins. and when running the "Test query" i can see that in the last 30m there are over 290k docs. hence the alert should not fire and as you can see it is active.

then i copied the DSL query using "Copy query" and ran in console under \<OUR\_INDEX\>/\_search and saw that the number of hits are limited by 10k

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e9e04a91e913cca27ed202e578c06d8e49813ee.png)

then i've modified the threshold of the rule to below 9999 to see if the alert is still triggered.,  
and surprisingly it is recovered, which means maybe that it checks the doc count against the limit (10k)?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/297e1176305f27efd30ee56d4d00e8d5f9c4719e.jpeg)

Please help me figure this out, thanks!

---

<div class="post-metadata">

**Author:** ![amityahav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amityahav/32/119362_2.png) [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Post date:** [May 24, 2023, 1:10pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025/2 "2023-05-24T13:10:35Z")

</div>

bumping

---

<div class="post-metadata">

**Author:** ![maryam-saeidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maryam-saeidi/32/126947_2.png) [@maryam-saeidi](https://discuss.elastic.co/u/maryam-saeidi)\
**Post date:** [May 31, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025/3 "2023-05-31T13:25:28Z")

</div>

Hi @amityahav ,

Indeed that's the limitation related to `track_total_hits` mentioned [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-search.html)

> `track_total_hits`
> 
> (Optional, integer or Boolean) Number of hits matching the query to count accurately. Defaults to `10000`.
> 
> If `true`, the exact number of hits is returned at the cost of some performance. If `false`, the response does not include the total number of hits matching the query.

Have you tried using query DSL instead of KQL or Lucene and passing `track_total_hits` there?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37cea033dad9417ce0f177bf6b434644b4374852.png)
