Rules in the experimental alerting system

A rule is where the experimental alerting system starts. It points Kibana at the data you care about, describes what counts as a problem in ES|QL, and says how often to check. On each scheduled run, Kibana writes each matching row as a rule event to .rule-events. Those events are never overwritten. Alert episodes, action policies, and notifications all flow from those events.

Rules only define what to detect. They don't control notifications, who gets notified, or when. That's the job of action policies, which are global objects scoped to your space that match alert episodes from any rule.

This separation means you can update notification routing without touching a rule, and have multiple action policies respond to the same rule independently.

Use these pages to create a rule, change its settings, or review what it has detected.

  • Create a rule: Compare creation paths and choose the one that fits your workflow.
  • Configure a rule: Set the schedule, grouping, alert delay, recovery condition, and no-data behavior.
  • Rule mode: Set whether matches are grouped into an alert episode or remain available for later analysis.
  • View and manage rules: Enable, disable, clone, delete, and bulk-manage rules from the Rules page.
  • Review rule execution history: Monitor rule execution outcomes across all rules in a space.
  • ES|QL query patterns: Browse query patterns ordered by complexity, from a basic event filter to SLO burn rate and persistent breach detection.
  • Rule events: Understand the documents Kibana writes to .rule-events, and how type relates to episodes.
  • Query signals: Query events with type: signal in Discover and use them as input to a rule that opens an episode.
Important - How to use the experimental alerting system documentation

Because the experimental alerting system is still evolving, its UI can change before general availability. Rather than pointing to an exact button or menu, the documentation focuses on the underlying concepts and behavior. If something doesn't match what you see in the Kibana UI, look for the closest equivalent instead. The concepts and behaviors described in the documentation still apply.