# Email alert per sourceip

**URL:** <https://discuss.elastic.co/t/email-alert-per-sourceip/251864>\
**Category:** Elasticsearch\
**Created:** [October 13, 2020, 8:02am UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864 "2020-10-13T08:02:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ianvera](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@ianvera](https://discuss.elastic.co/u/ianvera)\
**Post date:** [October 13, 2020, 8:02am UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/1 "2020-10-13T08:02:53Z")

</div>

we created one watcher having multiple sourceip so that whenever the watcher matches the messages it will send email alert.

Will it be possible that the watcher having multiple sourceip will send multiple email alerts base on the sourceip that matches the message filter instead of having one email alerts only for all sourceip.

---

<div class="post-metadata">

**Author:** ![alisongoryachev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alisongoryachev/32/111352_2.png) [@alisongoryachev](https://discuss.elastic.co/u/alisongoryachev)\
**Post date:** [October 20, 2020, 12:44am UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/2 "2020-10-20T00:44:39Z")

</div>

Welcome, @ianvera! Would you mind sharing your watch definition? That will help me better answer your question. Thanks!

---

<div class="post-metadata">

**Author:** ![ianvera](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@ianvera](https://discuss.elastic.co/u/ianvera)\
**Post date:** [October 20, 2020, 1:28am UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/3 "2020-10-20T01:28:36Z")

</div>

Hi Alison,

Thank you for responding, appreciate it.

I have attach here the watch definition that we created.

Actually this is for our monitoring and alerting, that everytime the watcher runs it will search for messages per sourceip and send the log details in email per sourceip or per HOST that is actually the logic that we wanted. actually we prefer hostname to be mentioned in the email alert not the IP.

Hope you could assist us, since we were just new to ELK and watcher.

Eventually this alerts will be push to BigPanda.

Thanks in advance, looking forward to hearing from you.

Best regards,

Edward Ian Vera

(Attachment AIX\_POC\_Watcher\_Multiple\_Search\_IP\_err\_syslog\_ng.txt is missing)

---

<div class="post-metadata">

**Author:** ![ianvera](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@ianvera](https://discuss.elastic.co/u/ianvera)\
**Post date:** [October 20, 2020, 1:35am UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/4 "2020-10-20T01:35:33Z")

</div>

Hi Alison,

Thank you for responding, appreciate it.

I have attach here the watch definition that we created.

Actually this is for our monitoring and alerting, that everytime the watcher runs it will search for messages per sourceip and send the log details in email per sourceip or per HOST that is actually the logic that we wanted. actually we prefer hostname to be mentioned in the email alert not the IP.

Hope you could assist us, since we were just new to ELK and watcher.

Eventually this alerts will be push to BigPanda.

Thanks in advance, looking forward to hearing from you.

please see below.

{  
"trigger": {  
"schedule": {  
"interval": "15m"  
}  
},  
"input": {  
"search": {  
"request": {  
"body": {  
"size": 200,  
"query": {  
"bool": {  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "now-5m"  
}  
}  
},  
{  
"terms": {  
"SOURCEIP": ["10.411.123.11","10.411.123.12","10.412.123.13","10.412.123.14","10.511.123.17","10.611.123.18","10.812.123.19","10.811.123.20"]}  
}],  
"should": [

{  
"match\_phrase": {  
"message": "| notice | syslog-ng"  
}  
},  
{  
"match\_phrase": {  
"message": "| err | syslog-ng"  
}  
}  
]  
}  
}  
}  
}  
}  
},  
"condition": {  
"compare": {  
"ctx.payload.hits.total": {  
"gte": 1  
}  
}  
},  
"actions": {  
"send\_email": {  
"email": {  
"profile": "standard",  
"attachments": {  
"attached\_data": {  
"data": {  
"format": "json"  
}  
}  
},  
"to": [  
"[edward\_ian\_vera@manulife.com](mailto:edward_ian_vera@manulife.com)"  
],  
"subject": "ELK AIX JP POC server test alert",  
"body": {  
"html": "

### AIX err syslog-ng test alert, I/O error occurred while writing; fd='17', error='No space left on device. If the problem persists, please contact your system administrator (Test Only)\</h3\>

| Saved Search\</td\>\<cf\_org\_name: asitd\>{{ctx.watch\_id}}\</td\>\</tr\> |
| Query\</td\> | +( Syslog connection failed; fd='12', error='Connection timed out)\</td\>\</tr\> |
| Triggered time\</td\> | {{ctx.trigger.triggered\_time}}\</td\>\</tr\> |
| Hostname\</td\> | {{ctx.payload.hits.HOST}}\</td\>\</tr\>\</table\>  
History for this Watch\</a\>  
  

### Latest hit msg\</h3\>{{ctx.payload.hits.hits.0.\_source.msg}}
 
### All hits\</h3\>{{ctx.payload.hits.hits}}" } } }, "throttle\_period\_in\_millis": 90000 }
 

Best Regards.

 |

---

<div class="post-metadata">

**Author:** ![alisongoryachev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alisongoryachev/32/111352_2.png) [@alisongoryachev](https://discuss.elastic.co/u/alisongoryachev)\
**Post date:** [October 20, 2020, 1:17pm UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/5 "2020-10-20T13:17:04Z")

</div>

Thanks for sharing more information @ianvera! Watch actions support a [foreach](https://www.elastic.co/guide/en/elasticsearch/reference/current/action-foreach.html) field. I have not tested it, but it sounds like that might help you achieve sending multiple emails per source IP.

---

<div class="post-metadata">

**Author:** ![ianvera](https://avatars.discourse-cdn.com/v4/letter/i/57b2e6/32.png) [@ianvera](https://discuss.elastic.co/u/ianvera)\
**Post date:** [October 20, 2020, 1:42pm UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/6 "2020-10-20T13:42:40Z")

</div>

Thanks Alison for the feedback, BTW do you have a sample format of the foreach in the watch action.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2020, 1:42pm UTC](https://discuss.elastic.co/t/email-alert-per-sourceip/251864/7 "2020-11-17T13:42:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
