# Log threshold rules does not allow filtering with boolean fields

**URL:** <https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175>\
**Category:** Elastic Observability\
**Created:** [October 21, 2022, 8:37am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175 "2022-10-21T08:37:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![qatium-developers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qatium-developers/32/112363_2.png) [@qatium-developers](https://discuss.elastic.co/u/qatium-developers)\
**Post date:** [October 21, 2022, 8:37am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175/1 "2022-10-21T08:37:39Z")

</div>

Hello,

we are trying to generate a Log Threshold rule that requires checking a boolean field to detect if the alert must be raised or not, but UI interface does not allow to use this kind of fields.

We have checked the documentation and it does not mention anything related to this.

Here is a screen capture of the rule form:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f70de6613c8d7dc98f3b5167570342b939763962.png)

And here is the field in the index:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/2/02da774e7b64a0ac67566cdd172380df20b0588e.png)

As a workaround we are planning to remap that field to a text/keyword field type, but we want to know if there is another workaround or if it is a bug or a planned feature.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 22, 2022, 5:35am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175/2 "2022-10-22T05:35:29Z")

</div>

Perhaps try an Elasticsearch Query Rule

 ![Screen Shot 2022-10-21 at 10.34.23 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f060d53014d12827ffa42e52222dffcf66ae102.png)

---

<div class="post-metadata">

**Author:** ![qatium-developers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qatium-developers/32/112363_2.png) [@qatium-developers](https://discuss.elastic.co/u/qatium-developers)\
**Post date:** [October 25, 2022, 10:58am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175/3 "2022-10-25T10:58:24Z")

</div>

Thanks, we will try and post here an update.

---

<div class="post-metadata">

**Author:** ![qatium-developers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qatium-developers/32/112363_2.png) [@qatium-developers](https://discuss.elastic.co/u/qatium-developers)\
**Post date:** [October 26, 2022, 10:10am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175/4 "2022-10-26T10:10:18Z")

</div>

@stephenb Thanks, we are able to use boolean field types using Elasticseach query based rules, although generating it is far more complex than using Log Threshold rules.

Do you know if there is a plan to include those field types in Log Threshold rules?
