# Kibana Open Distro Alerts - 2+ monitor conditions & relative triggers

**URL:** <https://forum.opensearch.org/t/kibana-open-distro-alerts-2-monitor-conditions-relative-triggers/2366>\
**Category:** Alerting\
**Created:** [March 7, 2020, 11:33am UTC](https://forum.opensearch.org/t/kibana-open-distro-alerts-2-monitor-conditions-relative-triggers/2366 "2020-03-07T11:33:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pete](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@pete](https://forum.opensearch.org/u/pete)\
**Post date:** [March 7, 2020, 11:33am UTC](https://forum.opensearch.org/t/kibana-open-distro-alerts-2-monitor-conditions-relative-triggers/2366/1 "2020-03-07T11:33:23Z")

</div>

hi,

currently familiarising with Open Distro Alerting Features in Kibana and wanted to ask 2 quick questions.

1. Can triggers be relative values of total hits?  
e.x.: trigger: **\> 10% of total hits**

2. Can Monitors be set up for 2+ conditions?  
e.x.: field 1 contains “abc” AND field 2 contains “200”

thanks

---

<div class="post-metadata">

**Author:** ![rakesh](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/rakesh/32/1341_2.png) [@rakesh](https://forum.opensearch.org/u/rakesh)\
**Post date:** [April 9, 2021, 5:12pm UTC](https://forum.opensearch.org/t/kibana-open-distro-alerts-2-monitor-conditions-relative-triggers/2366/2 "2021-04-09T17:12:49Z")

</div>

Hi,

We are also looking for this feature, is there a fix for this?

- Thank you

---

<div class="post-metadata">

**Author:** ![qreshi](https://avatars.discourse-cdn.com/v4/letter/q/aca169/32.png) [@qreshi](https://forum.opensearch.org/u/qreshi)\
**Post date:** [April 9, 2021, 6:20pm UTC](https://forum.opensearch.org/t/kibana-open-distro-alerts-2-monitor-conditions-relative-triggers/2366/3 "2021-04-09T18:20:22Z")

</div>

Hi @rakesh,

If you select `"Define using extraction query"` when creating the Monitor, you’ll be able to define your Triggers yourself with Painless scripts. This will allow you to create more complex Trigger conditions.

For example:

```auto
int count = 0;
// Get 10% of the total hits of the response
double percentOfTotal = ctx.results[0].total.value * 0.1;
// Iterate over the search hits
for (int i = 0; i < ctx.results[0].hits.hits.length; i++) {
    // Storing the source as a variable just to reference it easier
    Map src = ctx.results[0].hits.hits[i]._source;
    // Check if both field_1 and field_2 match certain values
    if (src.field_1 == "abc" && src.field_2 == 200) {
        count++;
    }
}
return count > percentOfTotal;

```

In the example above, instances of both of @pete’s conditions can be seen. We iterate over the search hits (which are the response of the Monitor’s input query) and increment a count if both `field_1` and `field_2` are what we expect. We then check if the count is greater than 10% of the total hits.
