# 🧐 Observability \> Alerts \> Manage Rules: "Unable to load rules"

**URL:** <https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170>\
**Category:** Elastic Observability\
**Created:** [September 26, 2022, 1:17pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170 "2022-09-26T13:17:22Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 26, 2022, 1:17pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/1 "2022-09-26T13:17:22Z")

</div>

Hi!

When I navigate to Observability \> Alerts \> Manage Rules, I get 2 "Unable to load rules" errors in a small popup:

 ![R2](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb4ca2f91a85ef197a60adb73d03a1b920f2a2da.jpeg)

And I see two 400 errors, that say

```auto
{"statusCode":400,"error":"Bad Request","message":"KQLSyntaxError: Expected \"(\", NOT, end of input, field name, value, whitespace but \"{\" found.\n{\"type\":\"function\",\"function\":\"or\",\"arguments\":[{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"xpack.uptime.alerts.monitorStatus\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"xpack.uptime.alerts.tlsCertificate\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"xpack.uptime.alerts.durationAnomaly\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"logs.alert.document.count\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"metrics.alert.inventory.threshold\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"metrics.alert.threshold\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"apm.transaction_duration\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"apm.anomaly\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"apm.error_rate\",\"isQuoted\":false}]},{\"type\":\"function\",\"function\":\"is\",\"arguments\":[{\"type\":\"literal\",\"value\":\"alert.attributes.alertTypeId\",\"isQuoted\":false},{\"type\":\"literal\",\"value\":\"apm.transaction_error_rate\",\"isQuoted\":false}]}]}\n^: Bad Request"}

```

At the same time I can see a list of rules in the Management section:

 ![R3](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6a0f88ebc8fd9730e74ef7f5576a7efc61ff6dc5.png)

Can you please advise how to fix this error?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 26, 2022, 1:54pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/2 "2022-09-26T13:54:00Z")

</div>

Hi @Its_Anton,

Can you provide the Kibana version you are using please?

Just to confirm the scenario, you created a rule from the Rules and Connectors page, then try to access the Observabiliry \> Alert page, correct?

Thanks

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 26, 2022, 2:04pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/3 "2022-09-26T14:04:43Z")

</div>

Hi, @Kevin_Delemme  
Thanks for the quick reply!

I use the latest Kibana and Elasticsearch 8.4.2.

My steps:

1. I have opened Observability \> Alerts \> Manage Rules for the first time and got the same "Unable to load rules" errors. At that time I had no any rules.
2. I have successfully created my first rule "Test" from the Observability \> Alerts \> Manage Rules page
3. Now I see that I have 1 rule on the Observability \> Alerts page on top (small counter)
4. When I click Manage Rules on the Observability \> Alerts page I get the error reported in my first message here.

Hope that helps.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 26, 2022, 2:12pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/4 "2022-09-26T14:12:05Z")

</div>

Thanks for providing the information, I'm going to try to reproduce your issue.  
I'll keep you posted.

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 26, 2022, 2:28pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/5 "2022-09-26T14:28:28Z")

</div>

@Its_Anton Did you upgraded from a previous version or is it a fresh new install?

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 26, 2022, 2:35pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/6 "2022-09-26T14:35:56Z")

</div>

It's a fresh install that runs in Docker, single node mode with security disabled.

Since it is my test instance, I can give you full access to Kibana if that will help.

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 26, 2022, 2:36pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/7 "2022-09-26T14:36:27Z")

</div>

CC @Kevin_Delemme

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/8 "2022-09-26T14:51:12Z")

</div>

If it's accessible, I can take a look directly yes. You can send me an email with the credentials: [kevin.delemme@elastic.co](mailto:kevin.delemme@elastic.co)

So far I've started a 8.4.2 instance, and I can access the rules page without any errors showing up, and can create rules and see them active in the Alerts page.

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 27, 2022, 2:24pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/9 "2022-09-27T14:24:37Z")

</div>

Hey @Its_Anton,

We think this error is related to Kibana security being disabled.

We are going to investigate further but in the meantime if you can try to enable [Kibana Security](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/configuring-stack-security.html?blade=kibanasecuritymessage) on your instance and check if the error still happens?

Thanks

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 27, 2022, 3:55pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/10 "2022-09-27T15:55:48Z")

</div>

Hi, @Kevin_Delemme!

Do I also need to enable security on Elasticseach? Or just Kibana (xpack.security.enabled=true)?

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 27, 2022, 4:24pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/11 "2022-09-27T16:24:42Z")

</div>

It needs to be enabled in the elasticsearch.yml config file. [More details here](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/security-minimal-setup.html)

---

<div class="post-metadata">

**Author:** ![Its\_Anton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its_anton/32/111286_2.png) [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Post date:** [September 27, 2022, 10:29pm UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/12 "2022-09-27T22:29:05Z")

</div>

Hi, @Kevin_Delemme!

With security enabled, I don't have this bug.

---

<div class="post-metadata">

**Author:** ![Kevin\_Delemme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_delemme/32/108920_2.png) [@Kevin\_Delemme](https://discuss.elastic.co/u/Kevin_Delemme)\
**Post date:** [September 28, 2022, 12:02am UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/13 "2022-09-28T00:02:40Z")

</div>

Thanks for confirming. A bug fix is on its way: [[RAM] Bug on find with KueryNode filter by XavierM · Pull Request #142001 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/142001)

Thanks for reporting the issue!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:37am UTC](https://discuss.elastic.co/t/observability-alerts-manage-rules-unable-to-load-rules/315170/14 "2022-11-04T08:37:09Z")

</div>


