# Alerting Rule with link to Discover

**URL:** <https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 18, 2024, 8:25am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628 "2024-06-18T08:25:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [June 18, 2024, 8:25am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/1 "2024-06-18T08:25:20Z")

</div>

Hi Guys,  
I'm trying to get my head around the following:

Is it possible to have a Discover Link included in the E-Mail Alert?

The Use-Case is as following:  
Whenever I receive an Alert over the Mail Connector, I'd like to have a Link in that E-Mail that leads me directly to Discover and displays all of the entries regarding this Alert.  
I do believe something similar has existed? If this still does work, whats the Field name I have to place in the Alert-Mail?

Thanks for the help in Advance!

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 18, 2024, 8:40am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/2 "2024-06-18T08:40:45Z")

</div>

Hi @_Thomas,

Welcome to the community! I'm not aware of a way to add the link to the discover menu with parameters. Have you looked at the email attachment feature to see if [sending a generated dashboard report as an attachment](https://www.elastic.co/guide/en/elasticsearch/reference/current/actions-email.html#configuring-email-attachments) would work for you?

Let us know!

---

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [June 18, 2024, 8:44am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/3 "2024-06-18T08:44:08Z")

</div>

Hi @carly.richmond  
Thanks for the swift reply.

I've had a quick glance at your Article - this however is sadly not what I'm looking for. I do believe in an older Version of Elasticsearch there was a possibility to add the Discover Link with the Timeframe from when the Alert triggered.

I might be wrong, though.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 18, 2024, 8:46am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/4 "2024-06-18T08:46:16Z")

</div>

Thanks for confirming. I did find [this old thread from 2016](https://discuss.elastic.co/t/alert-to-contain-link-to-kibana-search-results/57750) that suggests having the link as metadata and then invoking the property in the email body.

Is that closer to what you need?

---

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [June 18, 2024, 8:52am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/5 "2024-06-18T08:52:36Z")

</div>

This looks more promising - appreciate that! 🙂

Looking through the attached github Link - it seems that this is either a Feature Request or something you guys aren't supporting for long.

Do you happen to know, whether or not something like that will make it into a future (major/minor) release? I guess I'm probably not the only one, interested in that feature/function 😅

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 18, 2024, 10:56am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/6 "2024-06-18T10:56:59Z")

</div>

Hi @_Thomas,

Do you mean the issue for adding documentation of the RISON format?

> <https://github.com/elastic/kibana/issues/4338>
>
> The format of the URL parameters is \[RISON\](https://github.com/Nanonid/rison), b…ut there is no documentation around the structure of this object. It doesn't appear to be a raw ES query object converted from JSON to RISON. Aside from reverse-engineering by reading the source code - there should be some documentation about the structure of the objects passed so that URLs can be easily generated by external systems.
> \## Example use-case
> 1. ELK is aggregating log information to a central place.
> 2. An error occurs on an application server.  
> 3. An email is sent with the corresponding Kibana Discover URL which narrows down the time-frame and applies some filters. 
> 4. An engineer clicks on the URL and is able to quickly get the log information they need to debug issue.

I see that issue has been closed due to inactivity, but there is a bit about interacting with that format [here in the documentation](https://www.elastic.co/guide/en/kibana/current/kibana-navigation.html#state-sync) and also in [this forum post](https://discuss.elastic.co/t/kibana-g-and-a-parameters-in-the-dashboards-url-string/264642).

Hope that helps!

---

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [June 18, 2024, 11:11am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628/7 "2024-06-18T11:11:15Z")

</div>

Hi,  
yes that was the Link I was referring to.

I'll have a closer look into the Documentation as well as the other Link you've posted.

I appreciate the help on that one 🙂
