# Using multiple data views in a single alert definition?

**URL:** <https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [November 26, 2025, 12:41pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683 "2025-11-26T12:41:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gueguet57](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueguet57/32/143903_2.png) [@gueguet57](https://discuss.elastic.co/u/gueguet57)\
**Post date:** [November 26, 2025, 12:41pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/1 "2025-11-26T12:41:10Z")

</div>

Hi everyone,

I’m wondering if it’s possible for an alert to reference _multiple data views_ in its definition.

My use case: I have one data view per environment, and I’d like to avoid duplicating the same alert definition for each environment. Ideally, the alert’s query would run across several data views at once.

Is this currently supported, or is there a recommended workaround?

Thanks!

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [November 26, 2025, 3:20pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/2 "2025-11-26T15:20:28Z")

</div>

Hello @gueguet57

When you say every environment you mean space Or multiple data views per environment in same space?

Also the alert you are trying to create is a threshold or custom rule?

Can we create a single dataview with index\* if you have index name as index-dev , index-test , index-prod?

Thanks!!

---

<div class="post-metadata">

**Author:** ![gueguet57](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueguet57/32/143903_2.png) [@gueguet57](https://discuss.elastic.co/u/gueguet57)\
**Post date:** [December 1, 2025, 1:16pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/3 "2025-12-01T13:16:39Z")

</div>

Hello @Tortoise, thanks for your answer !

1. When I say _every environment_, I mean one environment for each of my Kubernetes environments (non-prod, prod, etc.). I’m not talking about Spaces here.

2. Not sure I fully understand the question — I have a custom query, and if it returns at least one document, my alert is triggered.

3. Yes, now I remember that someone also advised me to do this! I can definitely use a wildcard to declare a more generic dataview and get all environments at once.

Thanks!

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [December 1, 2025, 1:36pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/4 "2025-12-01T13:36:44Z")

</div>

Hello @gueguet57 ,

I think you can define a data view that accesses all environments, and then you can break down each environment at the level of your rule. And that way you just have one rule.

---

<div class="post-metadata">

**Author:** ![gueguet57](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gueguet57/32/143903_2.png) [@gueguet57](https://discuss.elastic.co/u/gueguet57)\
**Post date:** [December 1, 2025, 2:13pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/5 "2025-12-01T14:13:37Z")

</div>

> [@ahmed\_charafouddine](#):
>
> ata view that accesses all environments, and then you can break down each environment at the level of your rule. And that way you ju

Yes I will try this method thanks !

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [December 1, 2025, 2:48pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683/6 "2025-12-01T14:48:40Z")

</div>

Hello @gueguet57

The question was specifically for below scenario, you create a single dataview index\* which will have data for index-dev, index-prod, index-test

Now you have a rule if error \> 0 raise alert but how will you know it is for which environment? This was the reason for asking which rule you are going to create after the dataview. If you create a custom threshold, there is option to create different alerts per environment but in each index do you have an environment field? So your rule will execute against each environment error \> 0 & it should raise 2 alerts say for env test & prod if for this the count is \> 0 for test/prod & not for dev.

Thanks!!
