# How to configure "per query monitor" to trigger alerts according to each error logs on query result

**URL:** <https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055>\
**Category:** DevOps\
**Tags:** discuss, configure, alerting\
**Created:** [April 9, 2025, 8:03am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055 "2025-04-09T08:03:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew\_flying](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@andrew\_flying](https://forum.opensearch.org/u/andrew_flying)\
**Post date:** [April 9, 2025, 8:03am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/1 "2025-04-09T08:03:21Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
Opensearch 2.15

**Describe the issue** :  
I have a monitor for error logs level with multiple index in 1 Cluster, I’m using the “Per query monitor” type with interval of 1 minutes, the query search for “Error” and trigger alarm if there is errors during that 1 minute.  
 → The issue is that if during that 1 minute, we have multiple errors, just only 1 alert is generated and push to our team, we want to set up that each error log will trigger an alert for it.

**Configuration** :

- Per query monitor
- interval: 1 minute
- Select data: multiple indexes from local Cluster
- Query:  
"  
{  
“size”: 10,  
“query”: {  
“bool”: {  
“must”: [  
{  
“match\_phrase”: {  
“level”: {  
“query”: “Error”,  
“slop”: 0,  
“zero\_terms\_query”: “NONE”,  
“boost”: 1  
}  
}  
}  
],  
“filter”: [  
{  
“range”: {  
“@timestamp”: {  
“from”: “{{period\_end}}||-1m”,  
“to”: “{{period\_end}}”,  
“include\_lower”: true,  
“include\_upper”: true,  
“format”: “epoch\_millis”,  
“boost”: 1  
}  
}  
}  
],  
“adjust\_pure\_negative”: true,  
“boost”: 1  
}  
},  
“\_source”: {  
“includes”: [  
“@timestamp”,  
“message”,  
“level”  
],  
“excludes”:   
},  
“sort”: [  
{  
“@timestamp”: {  
“order”: “desc”  
}  
}  
]  
}  
"
- Trigger condition: ctx.results[0].hits.total.value \> 0
- Message:  
"  
{  
“message”: “ALARM: {{ctx.results.0.hits.hits.0.\_index}}”,  
“description”: “ERROR LOG: {{ctx.results.0.hits.hits.0.\_source.message}}”,  
“tags”: [“Staging”],  
“alias”: “{{ctx.results.0.hits.hits.0.\_index}}- {{ctx.results.0.hits.hits.0.\_source.message}}”,  
“priority”: “P3”,  
“details”: {  
“AWSAccountId”: “905417996969”  
}  
}  
"

**Relevant Logs or Screenshots** :

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [April 11, 2025, 12:47pm UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/2 "2025-04-11T12:47:01Z")

</div>

Hi @andrew_flying,

If my understanding is correct, **per query** type treats the query as a whole unit and evaluates aggregated conditions like `ctx.results[0].hits.total.value > 0`, even though your query pulls multiple logs, the trigger logic references only the first hit.

Have you considered using **per document** type?

Best,  
mj

---

<div class="post-metadata">

**Author:** ![andrew\_flying](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@andrew\_flying](https://forum.opensearch.org/u/andrew_flying)\
**Post date:** [April 11, 2025, 2:14pm UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/3 "2025-04-11T14:14:14Z")

</div>

Hi @Mantas ,

Thank you for your response.

If I have n indexes to query like: a\*, b\*, c\*,… n\* in my previous **per query monitor** and I want to change to use **per document monitor** , I need to create n document monitors, right?

I’m new to Opensearch, could you give me example config of query, trigger and message that use to alert when each time index a\* got error log.

Thank so much,  
Andrew,

---

<div class="post-metadata">

**Author:** ![KateWinslet](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/katewinslet/32/6694_2.png) [@KateWinslet](https://forum.opensearch.org/u/KateWinslet)\
**Post date:** [April 18, 2025, 8:49am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/4 "2025-04-18T08:49:42Z")

</div>

> [@andrew\_flying](#):
>
> **Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
> Opensearch 2.15
> 
> **Describe the issue** :  
> I have a monitor for error logs level with multiple index in 1 Cluster, I’m using the “Per query monitor” type with interval of 1 minutes, the query search for “Error” and trigger alarm if there is errors during that 1 minute.  
> → The issue is that if during that 1 minute, we have multiple errors, just only 1 alert is generated and push to our team, we want to set up that each error log will trigger an alert for it.
> 
> **Configuration** :
> 
> - Per query monitor
> - interval: 1 minute
> - Select data: multiple indexes from local Cluster
> - Query:  
> "  
> {  
> “size”: 10,  
> “query”: {  
> “bool”: {  
> “must”: [  
> {  
> “match\_phrase”: {  
> “level”: {  
> “query”: “Error”,  
> “slop”: 0,  
> “zero\_terms\_query”: “NONE”,  
> “boost”: 1  
> }  
> }  
> }  
> ],  
> “filter”: [  
> {  
> “range”: {  
> “@timestamp”: {  
> “from”: “{{period\_end}}||-1m”,  
> “to”: “{{period\_end}}”,  
> “include\_lower”: true,  
> “include\_upper”: true,  
> “format”: “epoch\_millis”,  
> “boost”: 1  
> }  
> }  
> }  
> ],  
> “adjust\_pure\_negative”: true,  
> “boost”: 1  
> }  
> },  
> “\_source”: {  
> “includes”: [  
> “@timestamp”,  
> “message”,  
> “level”  
> ],  
> “excludes”: [car movers](https://smartautomove.com/car-movers/)  
> },  
> “sort”: [  
> {  
> “@timestamp”: {  
> “order”: “desc”  
> }  
> }  
> ]  
> }  
> "
> - Trigger condition: ctx.results[0].hits.total.value \> 0
> - Message:  
> "  
> {  
> “message”: “ALARM: {{ctx.results.0.hits.hits.0.\_index}}”,  
> “description”: “ERROR LOG: {{ctx.results.0.hits.hits.0.\_source.message}}”,  
> “tags”: [“Staging”],  
> “alias”: “{{ctx.results.0.hits.hits.0.\_index}}- {{ctx.results.0.hits.hits.0.\_source.message}}”,  
> “priority”: “P3”,  
> “details”: {  
> “AWSAccountId”: “905417996969”  
> }  
> }  
> "
> 
> **Relevant Logs or Screenshots** :

Per-query monitors only evaluate the query once per interval, so only one alert is triggered per run. To get alerts for each error, use **bucket-level monitors** with a grouping field (like `message` or a unique ID) to trigger individual alerts for each log entry.

---

<div class="post-metadata">

**Author:** ![andrew\_flying](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@andrew\_flying](https://forum.opensearch.org/u/andrew_flying)\
**Post date:** [April 21, 2025, 4:43am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/5 "2025-04-21T04:43:10Z")

</div>

If I would need to send the error logs to each alert, How can I configure it in “Bucket monitor” type?

---

<div class="post-metadata">

**Author:** ![andrew\_flying](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@andrew\_flying](https://forum.opensearch.org/u/andrew_flying)\
**Post date:** [April 28, 2025, 5:03am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/6 "2025-04-28T05:03:54Z")

</div>

Hi @Mantas, @KateWinslet ,

Could you guys help me on some documents for configuring “Per-document-monitor” monitor for my case?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/33547ea01a5b12dcca2958411d3edd97ae2ea8c1.png) [@system](https://forum.opensearch.org/u/system)\
**Post date:** [June 27, 2025, 5:04am UTC](https://forum.opensearch.org/t/how-to-configure-per-query-monitor-to-trigger-alerts-according-to-each-error-logs-on-query-result/24055/7 "2025-06-27T05:04:06Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
