Kibana rules/alerts "If alert matches a query" not working for custom fields

Elasticsearch, Kibana, Logstash and Beats using version 8.9.1 or 8.10.1

When creating Kibana rules for Log threshold or Metric threshold, the "If alert matches a query" defined is a custom fields, it will not process the action - Webhook but will still trigger the alert.

Adding the filter in the "Condition" and removing it from the "If alert matches a query" will work.

How can i achieve this inside the Actions instead of creating multiple Rules? Thanks

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.