# Observability Alerting

**URL:** <https://discuss.elastic.co/t/observability-alerting/383344>\
**Category:** Elastic Observability\
**Created:** [November 10, 2025, 8:48pm UTC](https://discuss.elastic.co/t/observability-alerting/383344 "2025-11-10T20:48:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![MuchoRiceGobler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muchoricegobler/32/145697_2.png) [@MuchoRiceGobler](https://discuss.elastic.co/u/MuchoRiceGobler)\
**Post date:** [November 10, 2025, 8:48pm UTC](https://discuss.elastic.co/t/observability-alerting/383344/1 "2025-11-10T20:48:04Z")

</div>

I've made a couple hundred Observability rules to detect when 0 logs are received from specific hosts (monitors logs are being forwarded to Elastic). However, my rules run every 60 seconds (to minimise time to detection of a host not forwarding logs). The issue im having, is if you see an alert, you make a case and attach the alert to track/investigate/resolve the issue. But When your rule runs again 60 seconds later it generates another new identical alert. This means its impossible to have a clean view of your alerts page that shows only issues that are yet to be documented in a case. At a glance, you dont know what is being dealt with already and what isnt….it seems really silly.

Any advice is greatly appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 11, 2025, 4:14pm UTC](https://discuss.elastic.co/t/observability-alerting/383344/2 "2025-11-11T16:14:35Z")

</div>

Hi @MuchoRiceGobler Welcome to the community.

Couple questions

What version are you on?

Exactly what type of rule are you creating?

Can you share and example rule?

Are you aware of Action On status change which only notifies once when the alert is triggered?

You also mentioned 100s of alerts I am going to assume that is per host or data type ...are you aware you may be able use group by to reduce the number alerts but cover you cases.

> **[Create and manage alerting rules with Kibana | Elastic Docs](https://www.elastic.co/docs/explore-analyze/alerts-cases/alerts/create-manage-rules)**
>
> The Stack Management \> Rules UI provides a cross-app view of alerting. Different Kibana apps like Observability, Security, Maps and Machine Learning can...

There also is another fundamental way to monitor last data checkin by using a latest transform... But let's understand your alerts first...

So share some more details and we might be able to help.
