# Alerts and passing additional detail in message body

**URL:** <https://discuss.elastic.co/t/alerts-and-passing-additional-detail-in-message-body/214857>\
**Category:** Kibana\
**Created:** [January 13, 2020, 3:00pm UTC](https://discuss.elastic.co/t/alerts-and-passing-additional-detail-in-message-body/214857 "2020-01-13T15:00:10Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Schellhouse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_schellhouse/32/56631_2.png) [@Michael\_Schellhouse](https://discuss.elastic.co/u/Michael_Schellhouse)\
**Post date:** [January 13, 2020, 3:00pm UTC](https://discuss.elastic.co/t/alerts-and-passing-additional-detail-in-message-body/214857/1 "2020-01-13T15:00:10Z")

</div>

Currently have alerts setup based on extraction query. I have used aggregation to get summary counts by two fields. I would like to output the agg results in the body of the alert message. problem is, message will only send IF all ctx variables referenced actually resolve to a value. Not sure how to handle dynamic buckets in output. Any suggestions?

Extraction Query Response:

> {  
> "\_shards": {  
> "total": 2955,  
> "failed": 0,  
> "successful": 2955,  
> "skipped": 2170  
> },  
> "hits": {  
> "hits": ,  
> "total": 177,  
> "max\_score": 0  
> },  
> "took": 1436,  
> "num\_reduce\_phases": 2,  
> "timed\_out": false,  
> "aggregations": {  
> "1": {  
> "doc\_count\_error\_upper\_bound": 0,  
> "sum\_other\_doc\_count": 0,  
> "buckets": [  
> {  
> "2": {  
> "doc\_count\_error\_upper\_bound": 0,  
> "sum\_other\_doc\_count": 0,  
> "buckets": [  
> {  
> "doc\_count": 74,  
> "key": "10.9.2.156-consle.log"  
> },  
> {  
> "doc\_count": 74,  
> "key": "10.9.2.156-server.log"  
> },  
> {  
> "doc\_count": 7,  
> "key": "10.9.2.156-messages"  
> }  
> ]  
> },  
> "doc\_count": 155,  
> "key": "ams-jboss"  
> },  
> {  
> "2": {  
> "doc\_count\_error\_upper\_bound": 0,  
> "sum\_other\_doc\_count": 0,  
> "buckets": [  
> {  
> "doc\_count": 10,  
> "key": "10.9.2.188-messages"  
> },  
> {  
> "doc\_count": 7,  
> "key": "10.9.1.151-messages"  
> },  
> {  
> "doc\_count": 5,  
> "key": "10.9.1.197-messages"  
> }  
> ]  
> },  
> "doc\_count": 22,  
> "key": "annuity-services-b"  
> }  
> ]  
> }  
> }  
> }

Looking to do something like this in message body:

> Details of Kibana search result:  
> @log\_group = {{ctx.results.0.aggregations.1.buckets.0.key}} - {{ctx.results.0.aggregations.1.buckets.0.doc\_count}} total events across the following @log\_streams:  
> {{ctx.results.0.aggregations.1.buckets.0.2.buckets.0.key}}  
> {{ctx.results.0.aggregations.1.buckets.0.2.buckets.1.key}}  
> {{ctx.results.0.aggregations.1.buckets.0.2.buckets.2.key}}  
> {{ctx.results.0.aggregations.1.buckets.0.2.buckets.3.key}}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2020, 3:00pm UTC](https://discuss.elastic.co/t/alerts-and-passing-additional-detail-in-message-body/214857/2 "2020-02-10T15:00:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
