# Problem with alerts recovered

**URL:** <https://discuss.elastic.co/t/problem-with-alerts-recovered/362036>\
**Category:** Elastic Observability\
**Created:** [June 25, 2024, 3:29pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036 "2024-06-25T15:29:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [June 25, 2024, 3:29pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/1 "2024-06-25T15:29:43Z")

</div>

Friends, I have a problem with the recovery of my alerts related to my monitors, before the alerts when they were activated and the ping went down were recovered without problem, but now it is different, the alert is active all the time so the ping is balanced

Has anyone else had this behavior?

Status active not recovered

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9581f34792e21da51a8450ded1bf0d563ca6e84.png)

Settings rule

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e16970c6b3d366d2be60c7da59ca121b887e20c8.png)

With this configuration my alerts are recovered, now it doesn't work the same

---

<div class="post-metadata">

**Author:** ![faisal-k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisal-k/32/103817_2.png) [@faisal-k](https://discuss.elastic.co/u/faisal-k)\
**Post date:** [June 25, 2024, 4:21pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/2 "2024-06-25T16:21:14Z")

</div>

Hello @iTiago, I'm happy to help you with your question but first I need your help to understand some of the points you mentioned!

> before the alerts when they were activated and the ping went down were recovered without problem

Did you perform any Kibana updates recently?

> the alert is active all the time so the ping is balanced

Do you mean by "balanced" that the ping went back to its normal/baseline ms but the alert is still in `active` state? How do you read/know the ping status?

---

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [June 25, 2024, 6:01pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/3 "2024-06-25T18:01:22Z")

</div>

> Did you perform any Kibana updates recently?

RE: No

> Do you mean by "balanced" that the ping went back to its normal/baseline ms but the alert is still in `active` state? How do you read/know the ping status?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9c5dac9b1d086dfd4982e9aed5aed7ccc3e138a.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4de66c4b09a123e771e04ad905dd8f680d617f8e.png)

When viewing more details of an active alert, this example shows an alert that has been UP for more than 10 minutes (according to my rule it should not be active), it should be marked as recovered

---

<div class="post-metadata">

**Author:** ![faisal-k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisal-k/32/103817_2.png) [@faisal-k](https://discuss.elastic.co/u/faisal-k)\
**Post date:** [June 26, 2024, 11:06am UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/4 "2024-06-26T11:06:18Z")

</div>

Thanks for the reply. Can you please check if the rule of this alert is still there? i.e. The rule is not deleted and the alert is not _orphan_

---

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [June 26, 2024, 1:41pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/5 "2024-06-26T13:41:41Z")

</div>

> Can you please check if the rule of this alert is still there? i.e. The rule is not deleted and the alert is not _orphan_

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f802ca46471fd93bf30de98bd708624e278592fc.png)  
The rule is enabled

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c82ccc0a34f3f0fe5c3bd9cf9706c36d9d1a2a3.png)  
active alerts

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b87911b2c1b3754fb1a784dfcb213ff888b51ab0.png)  
Details alert

---

<div class="post-metadata">

**Author:** ![faisal-k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisal-k/32/103817_2.png) [@faisal-k](https://discuss.elastic.co/u/faisal-k)\
**Post date:** [June 27, 2024, 10:37am UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/6 "2024-06-27T10:37:46Z")

</div>

There is something interesting in the screenshot of the alert flyout. The `Started at` and `Last updated` have the exact same value, and the alert `Duration` is 0.

The behavior of having an alert active all the time, is the main symptom of an _orphaned_ alert. So I would you double check that.

### Would you please follow these steps:

1. From Alert page, click on `Fields` and add the `_id` field.  

2. Copy the id from the alert table of the alert that you estimate should be `recovered`

3. Open the Rule details page, and in the Alert table use the search bar  

Does the alert appears in the alert table on the Rule details page?

---

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [June 27, 2024, 2:11pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/7 "2024-06-27T14:11:02Z")

</div>

Copyng...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d1fe6f83d38f76034732e471eaf6dd71700a2332.png)

Searching...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99e6e68a19f3f8611533bc7f409d4b8cb27d57c3.png)

If you notice, it remains active and this is happening with all of them even though the ping is restored. Also, if you notice, the number of alerts has increased since I made this post.

---

<div class="post-metadata">

**Author:** ![shahzad31](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahzad31/32/51637_2.png) [@shahzad31](https://discuss.elastic.co/u/shahzad31)\
**Post date:** [June 27, 2024, 4:51pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/8 "2024-06-27T16:51:29Z")

</div>

@iTiago are you using logstash in between heartbeat and elasticsearch?

can you please check what mappings you have for a field `monitor.timespan` in heartbeat index?

---

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [June 27, 2024, 5:40pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/9 "2024-06-27T17:40:26Z")

</div>

@shahzad31  
Sure, additionally I will show you the details of the latest records of a monitor that should mark recovered alerts

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/3779199e988f0e8a99bbbfdca90114c5625b49cc.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53fd839815ca0d78ada3fb7f68b77f7a1cbcb6b1.png)

---

<div class="post-metadata">

**Author:** ![dpeterson87](https://avatars.discourse-cdn.com/v4/letter/d/ad7895/32.png) [@dpeterson87](https://discuss.elastic.co/u/dpeterson87)\
**Post date:** [March 4, 2025, 9:21pm UTC](https://discuss.elastic.co/t/problem-with-alerts-recovered/362036/10 "2025-03-04T21:21:31Z")

</div>

I had this same issue. I just disabled and re-enabled the alert and it untracked all the stale alerts and now there are no "real" active ones showing.
