# More than 90 days records unable to set the time

**URL:** https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [August 15, 2022, 8:45am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078 "2022-08-15T08:45:01Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![muthusundar.p](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@muthusundar.p](https://discuss.elastic.co/u/muthusundar.p)
#### Post date: [August 15, 2022, 8:45am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/1 "2022-08-15T08:45:01Z")

</div>

# I trying to create an alert for more than 90 days of records for my audit purpose.

I only see the "last" xx days in the option, but I need more than \> 90 days old data. Could you please help me with how to set it up? I tried in-dev tools and got the expected result.

# GET kafka-xxxx-xxxx.\*/\_search

{  
"\_source": ["data.xxxxxx.xxxx.xxxx","@timestamp"],  
"query": {  
"range": {  
"@timestamp": {  
"gte": "now-90d"  
}  
}  
}  
}

But unable to achieve in alerting part.

---

<div class="post-metadata">

### Author: ![EricDavisX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericdavisx/32/73456_2.png) [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)
#### Post date: [August 15, 2022, 11:57am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/2 "2022-08-15T11:57:14Z")

</div>

Hi! Thanks for writing in. Let me see if I can help. May I ask what version you're on?

I was wondering if your concerns were regarding the actual data still being available in the index, which would relate to ILM or Index LIfecycle Management, with relating docs here:

> **[ILM: Manage the index lifecycle | Elasticsearch Guide \[8.3\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html)**

But, if the problem exists more within the Alert creation, can I confirm if you're using Kibana Alerting to achieve this? If so, which Rule type are you using? Knowing that we can guide you through the creation. Some relating Kibana Alerting docs are linked below, and I hope are helpful:

> **[Alerting | Kibana Guide \[8.3\] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

> **[Create and manage rules | Kibana Guide \[8.3\] | Elastic](https://www.elastic.co/guide/en/kibana/current/create-and-manage-rules.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

If you're using a separate system for the alert I'm not sure I'll know how to help within that context. If dev-tools worked, I'm unsure where to go from here, if you can expand on it we can try to help.

Regards

---

<div class="post-metadata">

### Author: ![muthusundar.p](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@muthusundar.p](https://discuss.elastic.co/u/muthusundar.p)
#### Post date: [August 22, 2022, 3:34am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/3 "2022-08-22T03:34:23Z")

</div>

Dear Eric,

thank you for the link. I'm trying to achieve the alerting on Log threshold.

---

<div class="post-metadata">

### Author: ![EricDavisX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericdavisx/32/73456_2.png) [@EricDavisX](https://discuss.elastic.co/u/EricDavisX)
#### Post date: [August 23, 2022, 8:26pm UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/4 "2022-08-23T20:26:13Z")

</div>

Dear Muthusundar, hi - that helps to know. So, I'm looking at the Log Threshold Rule in Kibana Alerting and I see the dialog that allows me to pick the days I wish to query over.

This is the dialog I see (below), are you seeing the same?

 ![Screen Shot 2022-08-23 at 3.59.53 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e2009a9ef04d10f3c8969928fc64100980591466.png)

---

<div class="post-metadata">

### Author: ![muthusundar.p](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@muthusundar.p](https://discuss.elastic.co/u/muthusundar.p)
#### Post date: [September 2, 2022, 3:39am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/5 "2022-09-02T03:39:06Z")

</div>

Dear Eric,

Thank you so much. The above condition as 75 for the last 365 days is not working because the count 75 is taken as the record count last 365 days

Thank you

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 30, 2022, 3:39am UTC](https://discuss.elastic.co/t/more-than-90-days-records-unable-to-set-the-time/312078/6 "2022-09-30T03:39:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
