Thanks for your answer.
My question maybe wasn't really specific.
Now I'm going to expose my real case.
I have a hits from differents (virtual machines) comming with three differents values, Down, Up, Warning.
I want to visualice only Down and Warning on a Dashboard. And when I recieve an 'Up' these alert should disapear from the dashboard table.
00:00 PM - VM-001 send a log Down --> I visualice on Dashboard.
00:05 PM - VM-001 send a log Up --> Alert on Dashboard disapear.
I'm trying doing a query DSL with the code comming from the dashboard to do a intermediate filter. But I don't reach a sollution.
Other idea was use threshold Alert but still unworking.