# 7.12 Kibana log alerting - pass log details to PagerDuty

**URL:** <https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 9, 2021, 3:11pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506 "2021-05-09T15:11:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tslattery](https://avatars.discourse-cdn.com/v4/letter/t/51bf81/32.png) [@tslattery](https://discuss.elastic.co/u/tslattery)\
**Post date:** [May 9, 2021, 3:11pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506/1 "2021-05-09T15:11:35Z")

</div>

7.12 Kibana alerting  
I am trying to get some details of a log message to propagate to PagerDuty. The Connector is working and events are created in PD. The alert configuration:

 ![Screen Shot 2021-05-09 at 10.58.45 AM](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15fe9d8168ace8d035bc4f8d6e848623b727b587.png)  
 ![Screen Shot 2021-05-09 at 10.58.58 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a45bfab86e55a7bae1e13c4b0bef91e984932e0b.png)  
 ![Screen Shot 2021-05-09 at 11.00.35 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b18d7f44a44d84b0a07559e6e3ea0991a83ee253.png)

I read these two threads and understand that there may be multiple values of a field if the alert is the aggregation of multiple documents.

> [@Custom variables in Kibana Alerts](https://discuss.elastic.co/t/custom-variables-in-kibana-alerts/249986):
>
> I am exploring alerts and connectors in Kibana. I can configure and test them perfectly but I am unable to use the custom variable present in metricbeat, filebeat or any other beat module index. Let me explain this by an example. Let say, two different snapshot of my application is running on different servers with metricbeat docker module enabled. The hostname of my first server is host1 and second is host2. The container name of the application is myapp. I've one variable serviceName which is…

> [@The context.thresholdOf, context.metricOf and context.valueOf not working in inventory alert](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094):
>
> Hi, I am using the ELK 7.8.0 and making an inventory alert. I have created an action message as shown below. [image] But I am not getting values for context.thresholdOf, context.metricOf and context.valueOf. I have also tried context.reason as well but not worked. When I checked the alert index I found the following. [image] I want to get the current values for CPU and RAM utilization. Please help, if I am making any mistake or anything else.

There is no aggregation in this case. I'd like to pass the values of several fields to PD, such as the device MAC, serialNumber, domainName, zoneName.

Thanks!

---

<div class="post-metadata">

**Author:** ![Igor\_Zaytsev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_zaytsev/32/50662_2.png) [@Igor\_Zaytsev](https://discuss.elastic.co/u/Igor_Zaytsev)\
**Post date:** [May 13, 2021, 4:16pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506/2 "2021-05-13T16:16:11Z")

</div>

I think this is only possible with a [preconfigured](https://www.elastic.co/guide/en/kibana/current/pagerduty-action-type.html#Preconfigured-pagerduty-configuration) pager duty connecter. And, also with enabled `attach_payload` in your [elasticsearch.yml](https://www.elastic.co/guide/en/x-pack/current/actions-pagerduty.html#adding-context-and-payloads-to-pagerduty-actions)

---

<div class="post-metadata">

**Author:** ![tslattery](https://avatars.discourse-cdn.com/v4/letter/t/51bf81/32.png) [@tslattery](https://discuss.elastic.co/u/tslattery)\
**Post date:** [June 9, 2021, 9:39pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506/3 "2021-06-09T21:39:47Z")

</div>

Is there more detailed documentation on creating a preconfigured PD connector and attaching a payload? I'm not following the docs in the links you provided.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [June 29, 2021, 7:15pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506/4 "2021-06-29T19:15:51Z")

</div>

We have an issue open to make more of the data from the searched documents available in actions - [[Discuss] Ability to interact with the alert query result - User requests · Issue #89161 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/89161)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 7:16pm UTC](https://discuss.elastic.co/t/7-12-kibana-log-alerting-pass-log-details-to-pagerduty/272506/5 "2021-07-27T19:16:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
