# Proper Monitoring of specific Field - Fields missing in Alerts & Insights Rules

**URL:** <https://discuss.elastic.co/t/proper-monitoring-of-specific-field-fields-missing-in-alerts-insights-rules/320510>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [December 6, 2022, 1:02am UTC](https://discuss.elastic.co/t/proper-monitoring-of-specific-field-fields-missing-in-alerts-insights-rules/320510 "2022-12-06T01:02:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![afammartino](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/afammartino/32/114254_2.png) [@afammartino](https://discuss.elastic.co/u/afammartino)\
**Post date:** [December 6, 2022, 1:02am UTC](https://discuss.elastic.co/t/proper-monitoring-of-specific-field-fields-missing-in-alerts-insights-rules/320510/1 "2022-12-06T01:02:03Z")

</div>

Hello, my goal is to monitor a specific value from an index in ELK. Concretely I would like to alert if the 95th percentile of my nginx request\_time is greater than some threshold. What is the best way to accomplish this?

# What I Have Tried

## Create a Rule using a [Metrics Threshold](https://www.elastic.co/guide/en/observability/7.17/metrics-threshold-alert.html#metrics-threshold-alert)

In this case I do not see the required field (request\_time) from my specific index. I have validated that the index pattern configured in `Observability > Logs > Settings` contains `request_time` and it is a float and can be aggregated. Do I need to add this index in `Observability > Metrics > Settings` for this to work, if so is this the recommended way of doing things?

## Create a Watcher

Two issues with a watcher right now:

1. It does not have an option for 95th percentile when setting up a new watcher
2. The Slack Action requires I set up a user, is there a way to use the Slack Action defined in the Alerting section?

Please let me know what the best way to accomplish this is!

Thanks  
Anthony

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2023, 1:02am UTC](https://discuss.elastic.co/t/proper-monitoring-of-specific-field-fields-missing-in-alerts-insights-rules/320510/2 "2023-01-03T01:02:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
