# \#elastic-stack-alerting

**URL:** https://discuss.elastic.co/tag/elastic-stack-alerting/12.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Elasticsearch alerts don't show source.ip](https://discuss.elastic.co/t/elasticsearch-alerts-dont-show-source-ip/386763)

<div class="topic-metadata">

**Author:** [@komposektoras](https://discuss.elastic.co/u/komposektoras)\
**Replies:** 0\
**Last updated:** [June 8, 2026, 4:54pm UTC](https://discuss.elastic.co/t/elasticsearch-alerts-dont-show-source-ip/386763 "2026-06-08T16:54:16Z")

</div>

I have built a project lab with following tools: Component Tool Hypervisor VirtualBox Attacker VM Kali Linux Victim VM Ubuntu Server 22.04 SIEM VM Ubuntu Server 22.04 Log shipper (Linux) Filebeat …

---

## [Best practices for dashboards and rules](https://discuss.elastic.co/t/best-practices-for-dashboards-and-rules/386316)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 0\
**Last updated:** [May 13, 2026, 6:42am UTC](https://discuss.elastic.co/t/best-practices-for-dashboards-and-rules/386316 "2026-05-13T06:42:46Z")

</div>

Good afternoon, colleagues! If it's not too much trouble, could you please share your ready-made correlation rules and dashboards that are really useful to you in practice. According to Best Practice. I will be very gra…

---

## [Elastic - ESET AV integration](https://discuss.elastic.co/t/elastic-eset-av-integration/385971)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 12:25pm UTC](https://discuss.elastic.co/t/elastic-eset-av-integration/385971 "2026-04-22T12:25:04Z")

</div>

Good afternoon! Please tell me if anyone has configured the integration of ESET AntiVirus with ELASTIC. I deployed a Linux-based syslog server, specified the address and port 514 or 6514 in ESET, but there are no logs, …

---

## [Sythetics icmp down alert received but host and agent had been unenrolled!](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [April 13, 2026, 9:20am UTC](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866 "2026-04-13T09:20:44Z")

</div>

host had been decommissioned. agent had been unrolled weeks back BUT still getting sythetics icmp down alert today. Kindly assist!

---

## [Unable to view rule detail. (Unable to load rule)](https://discuss.elastic.co/t/unable-to-view-rule-detail-unable-to-load-rule/385837)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 2\
**Last updated:** [April 10, 2026, 6:19am UTC](https://discuss.elastic.co/t/unable-to-view-rule-detail-unable-to-load-rule/385837 "2026-04-10T06:19:53Z")

</div>

Alerts trigger. However unable to view rule detail. (Unable to load rule)

---

## [Looking for Alert rule dataview and index](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 7\
**Last updated:** [March 30, 2026, 1:30pm UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650 "2026-03-30T13:30:39Z")

</div>

Using the API we can get the index of the alert that it is being used curl --request GET 'https://localhost:5601/api/alerting/rules/\_find' \\ If I want to use a query which default dataview or default index for all al…

---

## [Query DSL alert configuration](https://discuss.elastic.co/t/query-dsl-alert-configuration/385538)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 4\
**Last updated:** [March 26, 2026, 4:04am UTC](https://discuss.elastic.co/t/query-dsl-alert-configuration/385538 "2026-03-26T04:04:44Z")

</div>

I am trying to use the Elasticsearch Query DSL to create an alert The query consist of LIMIT 100 but the actual output is actually less than 10. When I did run the test query . Query matched 852597 documents in the las…

---

## [After reindexing. what needs to be done for alerts and dashboard?](https://discuss.elastic.co/t/after-reindexing-what-needs-to-be-done-for-alerts-and-dashboard/385599)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 0\
**Last updated:** [March 25, 2026, 6:59am UTC](https://discuss.elastic.co/t/after-reindexing-what-needs-to-be-done-for-alerts-and-dashboard/385599 "2026-03-25T06:59:32Z")

</div>

We are re-indexing our indices and giving it a new name lets say "indicies\_name\_v2" I suppose this will have impact to our alerts and dashboard Correct me if i am wrong. For alerts i suppose this is what we need to do …

---

## [Reading Auth Logs on Mac devices](https://discuss.elastic.co/t/reading-auth-logs-on-mac-devices/385269)

<div class="topic-metadata">

**Author:** [@HaydenB0101](https://discuss.elastic.co/u/HaydenB0101)\
**Replies:** 0\
**Last updated:** [February 27, 2026, 5:19pm UTC](https://discuss.elastic.co/t/reading-auth-logs-on-mac-devices/385269 "2026-02-27T17:19:30Z")

</div>

I want to get auth. logs from my mac devices and am struggling to find a working integration to use. I have been using the Custom macOS Unified Logs integration to try and get this data from the devices since it’s the o…

---

## [Elastic Agent on Mac in failed state](https://discuss.elastic.co/t/elastic-agent-on-mac-in-failed-state/385255)

<div class="topic-metadata">

**Author:** [@HaydenB0101](https://discuss.elastic.co/u/HaydenB0101)\
**Replies:** 1\
**Last updated:** [February 26, 2026, 6:17pm UTC](https://discuss.elastic.co/t/elastic-agent-on-mac-in-failed-state/385255 "2026-02-26T18:17:22Z")

</div>

Hello, I am using the Custom macOS Unified Logs integration with elastic 8.18.8 in order to get logs from my mac device, and I getting errors from the agent elastic-agent status fleet status: (HEALTHY) Connected elas…

---

## [Kibana Instance Crashing During PDF/CSV Export on Elastic Cloud](https://discuss.elastic.co/t/kibana-instance-crashing-during-pdf-csv-export-on-elastic-cloud/384990)

<div class="topic-metadata">

**Author:** [@Hichem\_Blagui](https://discuss.elastic.co/u/Hichem_Blagui)\
**Replies:** 4\
**Last updated:** [February 12, 2026, 2:07pm UTC](https://discuss.elastic.co/t/kibana-instance-crashing-during-pdf-csv-export-on-elastic-cloud/384990 "2026-02-12T14:07:28Z")

</div>

Hi, I am experiencing frequent instance crashes when attempting to export default dashboards (PDF/PNG/CSV) from Kibana. I am currently using Elastic Cloud and do not have access to the underlying terminal or the physica…

---

## [Failed to check if maintenance windows are active](https://discuss.elastic.co/t/failed-to-check-if-maintenance-windows-are-active/384984)

<div class="topic-metadata">

**Author:** [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Replies:** 6\
**Last updated:** [February 11, 2026, 12:15pm UTC](https://discuss.elastic.co/t/failed-to-check-if-maintenance-windows-are-active/384984 "2026-02-11T12:15:26Z")

</div>

After the update of the on-premises deployment, this error appears. What could be the root cause?

---

## [Kibana Log Threshold Alert Rule Trigger Problem when using multiple conditions](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795)

<div class="topic-metadata">

**Author:** [@manzer](https://discuss.elastic.co/u/manzer)\
**Replies:** 8\
**Last updated:** [February 1, 2026, 5:54pm UTC](https://discuss.elastic.co/t/kibana-log-threshold-alert-rule-trigger-problem-when-using-multiple-conditions/384795 "2026-02-01T17:54:57Z")

</div>

Hi, I have created many alert rules in Kibana, however currently I am facing a strange issue, when I create Log Threshold Rule with single condition it is working file and Triggering the alert, but if I add multiple con…

---

## [Create a custom dashboard on elastic alerting data](https://discuss.elastic.co/t/create-a-custom-dashboard-on-elastic-alerting-data/384108)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [December 16, 2025, 11:15am UTC](https://discuss.elastic.co/t/create-a-custom-dashboard-on-elastic-alerting-data/384108 "2025-12-16T11:15:59Z")

</div>

Hi, I would like to create a dashboard with the data from elastic alerting. According to this documentation page the data is visible under .internal-alerts-\* indices I can see those in index management ex. .internal…

---

## [Context group not visible in rule](https://discuss.elastic.co/t/context-group-not-visible-in-rule/384052)

<div class="topic-metadata">

**Author:** [@Dhruv\_Naik](https://discuss.elastic.co/u/Dhruv_Naik)\
**Replies:** 1\
**Last updated:** [December 15, 2025, 10:13am UTC](https://discuss.elastic.co/t/context-group-not-visible-in-rule/384052 "2025-12-15T10:13:52Z")

</div>

I’ve set a GROUP BY query which looks as follows under Rules: When I test the index connector via Dev Tools the context.group stays empty. My document is formatted as follows: { "alert\_type": "ERROR\_THRESHOLD\_BREA…

---

## [Synthetic Rules - Active & recovered states - Incident Create & update](https://discuss.elastic.co/t/synthetic-rules-active-recovered-states-incident-create-update/383944)

<div class="topic-metadata">

**Author:** [@c.m](https://discuss.elastic.co/u/c.m)\
**Replies:** 1\
**Last updated:** [December 11, 2025, 9:24am UTC](https://discuss.elastic.co/t/synthetic-rules-active-recovered-states-incident-create-update/383944 "2025-12-11T09:24:43Z")

</div>

Hi, I am trying to capture ‘Active & Recovered ‘ events for a synthetic monitor so that i can update Incident in SNOW now. Setup: Have synthetic monioring setup for a website. Have a syntheric & uptime rule setup. Have…

---

## [Using multiple data views in a single alert definition?](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683)

<div class="topic-metadata">

**Author:** [@gueguet57](https://discuss.elastic.co/u/gueguet57)\
**Replies:** 5\
**Last updated:** [December 1, 2025, 2:48pm UTC](https://discuss.elastic.co/t/using-multiple-data-views-in-a-single-alert-definition/383683 "2025-12-01T14:48:40Z")

</div>

Hi everyone, I’m wondering if it’s possible for an alert to reference multiple data views in its definition. My use case: I have one data view per environment, and I’d like to avoid duplicating the same alert definitio…

---

## [Rule Consumer explanation](https://discuss.elastic.co/t/rule-consumer-explanation/383264)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [November 21, 2025, 11:40am UTC](https://discuss.elastic.co/t/rule-consumer-explanation/383264 "2025-11-21T11:40:57Z")

</div>

Hi everyone, Can someone give me a rundown of what each consumer means and is tied to? Regarding the Rule APIs (Create/Update). There's an open Github issue for improving the documentation but it seems to be in one he…

---

## [Alerting on field value change](https://discuss.elastic.co/t/alerting-on-field-value-change/383451)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 12\
**Last updated:** [November 16, 2025, 1:10pm UTC](https://discuss.elastic.co/t/alerting-on-field-value-change/383451 "2025-11-16T13:10:12Z")

</div>

I’m currently logging on-change data in ES, and I’m running a latest transform to store the most updated data into a separate index. I was advised that an ingest pipeline will help me compare any value coming in with th…

---

## [Observability UI shows incorrect count of active alerts](https://discuss.elastic.co/t/observability-ui-shows-incorrect-count-of-active-alerts/383386)

<div class="topic-metadata">

**Author:** [@Hari\_mandla](https://discuss.elastic.co/u/Hari_mandla)\
**Replies:** 0\
**Last updated:** [November 12, 2025, 10:55am UTC](https://discuss.elastic.co/t/observability-ui-shows-incorrect-count-of-active-alerts/383386 "2025-11-12T10:55:32Z")

</div>

Our expectation about Alert lifecycle is, "When a rule creates an alert for particular group, kibana creates a document in .internal-observability-\* index with a status active. When this is recovered, kibana updates the …

---

## [How to update fields that are not opened in the source document without affecting them](https://discuss.elastic.co/t/how-to-update-fields-that-are-not-opened-in-the-source-document-without-affecting-them/383175)

<div class="topic-metadata">

**Author:** [@S-Dragon0302](https://discuss.elastic.co/u/S-Dragon0302)\
**Replies:** 14\
**Last updated:** [November 11, 2025, 1:48am UTC](https://discuss.elastic.co/t/how-to-update-fields-that-are-not-opened-in-the-source-document-without-affecting-them/383175 "2025-11-11T01:48:32Z")

</div>

My template { "mappings":{"dynamic": "false","\_source":{"includes":\["a","b"\]},"properties":{"a":{"type": "keyword"},"b":{"type": "keyword"},"c":{"type": "keyword"}}}} PUT /your\_index\_name/\_doc/1 {"a": "value\_a","b": "…

---

## [Comparison of data between two indices](https://discuss.elastic.co/t/comparison-of-data-between-two-indices/382719)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 3\
**Last updated:** [October 15, 2025, 11:22am UTC](https://discuss.elastic.co/t/comparison-of-data-between-two-indices/382719 "2025-10-15T11:22:14Z")

</div>

Hello, I'm looking for suggestions. I have two indices, for example: index-a-2025 index-b-2025 Both indices contain Beat host names on which they are deployed. I want to compare both indices to identify any missing …

---

## [Watcher error using 'terms' query with metadata array input](https://discuss.elastic.co/t/watcher-error-using-terms-query-with-metadata-array-input/382513)

<div class="topic-metadata">

**Author:** [@Simriti\_Bundhoo](https://discuss.elastic.co/u/Simriti_Bundhoo)\
**Replies:** 1\
**Last updated:** [October 8, 2025, 4:05am UTC](https://discuss.elastic.co/t/watcher-error-using-terms-query-with-metadata-array-input/382513 "2025-10-08T04:05:14Z")

</div>

Hi everyone, I'm trying to use an array from the watch metadata in a terms query for one of my watchers. I want to use a Mustache search template-style query as described here: :link: https://www.elastic.co/docs/soluti…

---

## [Watcher: Support for Keystore Variables in Watch Definitions](https://discuss.elastic.co/t/watcher-support-for-keystore-variables-in-watch-definitions/382362)

<div class="topic-metadata">

**Author:** [@console\_fulcrum](https://discuss.elastic.co/u/console_fulcrum)\
**Replies:** 5\
**Last updated:** [October 6, 2025, 2:33pm UTC](https://discuss.elastic.co/t/watcher-support-for-keystore-variables-in-watch-definitions/382362 "2025-10-06T14:33:53Z")

</div>

Currently working on Elasticsearch 8.17.1 with Watcher + DataDog integration. While xpack.watcher.encrypt\_sensitive\_data=true encrypts stored watches, the initial watch definition still requires plaintext credentials. C…

---

## [How to prevent default header parameter from being passed with webhook action in Watcher](https://discuss.elastic.co/t/how-to-prevent-default-header-parameter-from-being-passed-with-webhook-action-in-watcher/381544)

<div class="topic-metadata">

**Author:** [@adityabk](https://discuss.elastic.co/u/adityabk)\
**Replies:** 3\
**Last updated:** [September 15, 2025, 1:51pm UTC](https://discuss.elastic.co/t/how-to-prevent-default-header-parameter-from-being-passed-with-webhook-action-in-watcher/381544 "2025-09-15T13:51:00Z")

</div>

I have a Watcher watch that uses webhook action to send HTTPS request to a Mule API. It looks like this: \</\> ”webhook”: { ”scheme”: “XXXX“ ”host”: “XXXXX“ ”port”: 443 ”method”: “post“ ”path”: “xxx/yyy/zzz” ”param…

---

## [Server Down or Restarted Alert Rule](https://discuss.elastic.co/t/server-down-or-restarted-alert-rule/381938)

<div class="topic-metadata">

**Author:** [@lomar](https://discuss.elastic.co/u/lomar)\
**Replies:** 1\
**Last updated:** [September 15, 2025, 7:41am UTC](https://discuss.elastic.co/t/server-down-or-restarted-alert-rule/381938 "2025-09-15T07:41:05Z")

</div>

I want to monitor whether my servers are shut down or restarted. To do this, I created a Metricbeat Threshold rule via Observability, but it is not working properly. Even if the condition that triggered the alarm is no l…

---

## [Elastic Watcher migration to Rules Issue's](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617)

<div class="topic-metadata">

**Author:** [@Sarada](https://discuss.elastic.co/u/Sarada)\
**Replies:** 1\
**Last updated:** [September 5, 2025, 5:41am UTC](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617 "2025-09-05T05:41:53Z")

</div>

Hi All, I migrating watchers to Rules, I do have a watcher that compares previous value from last entry and alerts if not same. This works perfectly in watcher as we wrote aggs and painless script but as we are migratin…

---

## [How to have the last timestamp field in Kibana Alerts](https://discuss.elastic.co/t/how-to-have-the-last-timestamp-field-in-kibana-alerts/381334)

<div class="topic-metadata">

**Author:** [@mosaadshaikh1998](https://discuss.elastic.co/u/mosaadshaikh1998)\
**Replies:** 3\
**Last updated:** [August 26, 2025, 9:57am UTC](https://discuss.elastic.co/t/how-to-have-the-last-timestamp-field-in-kibana-alerts/381334 "2025-08-26T09:57:39Z")

</div>

Hi, I have a use case in which Kibana alerting sends the alert when no documents are present in last 10 minutes. How can i add the timestamp of when the last document was found in message body?

---

## [Kibana Alert Webhook behind proxy with authentication using environment variables](https://discuss.elastic.co/t/kibana-alert-webhook-behind-proxy-with-authentication-using-environment-variables/381181)

<div class="topic-metadata">

**Author:** [@brunobastosg](https://discuss.elastic.co/u/brunobastosg)\
**Replies:** 6\
**Last updated:** [August 21, 2025, 9:51pm UTC](https://discuss.elastic.co/t/kibana-alert-webhook-behind-proxy-with-authentication-using-environment-variables/381181 "2025-08-21T21:51:48Z")

</div>

Hello, I'm trying to configure a Kibana alert to send webhooks to Microsoft Teams, but I'm facing an issue with proxy authentication configuration using environment variables. All internet access goes through a corpora…

---

## [Is it possible to skip some watcher inputs if an earlier input returns hits in Elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-skip-some-watcher-inputs-if-an-earlier-input-returns-hits-in-elasticsearch/381155)

<div class="topic-metadata">

**Author:** [@Simriti\_Bundhoo](https://discuss.elastic.co/u/Simriti_Bundhoo)\
**Replies:** 2\
**Last updated:** [August 21, 2025, 2:41am UTC](https://discuss.elastic.co/t/is-it-possible-to-skip-some-watcher-inputs-if-an-earlier-input-returns-hits-in-elasticsearch/381155 "2025-08-21T02:41:54Z")

</div>

Hi all, I’m working on an Elasticsearch Watcher that has multiple search inputs. What I want to do is: Run the first input query. If this query returns more than 0 hits, I want to skip running the other inputs ent…

[Next page](https://discuss.elastic.co/tag/elastic-stack-alerting/12.md?match_all_tags=true&page=1&tags%5B%5D=elastic-stack-alerting)
