# Email alert with readable body

**URL:** <https://discuss.elastic.co/t/email-alert-with-readable-body/142972>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 3, 2018, 8:49pm UTC](https://discuss.elastic.co/t/email-alert-with-readable-body/142972 "2018-08-03T20:49:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sasi\_Sasivarenan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sasi_sasivarenan/32/51036_2.png) [@Sasi\_Sasivarenan](https://discuss.elastic.co/u/Sasi_Sasivarenan)\
**Post date:** [August 3, 2018, 8:49pm UTC](https://discuss.elastic.co/t/email-alert-with-readable-body/142972/1 "2018-08-03T20:49:03Z")

</div>

Hi Team,

I am newbie to ELK.

Trying to create sample of Threat detection using the below URL as reference.

[https://github.com/elastic/examples/tree/master/Security%20Analytics/ssh\_analysis](https://github.com/elastic/examples/tree/master/Security%20Analytics/ssh_analysis)

I am trying create an email alert with following email body.

```
Application: SSH
User : root
Source IP : x.x.x.x
Destination: x.x.x.x
Actions: More than x denied logins, followed by access granted, for the <User>.

```

Watcher script

```
  POST _xpack/watcher/watch/_execute

```

> {  
> "watch": {  
> "metadata": {  
> "window\_period": "5m",  
> "required\_failures": 3  
> },  
> "trigger": {  
> "schedule": {  
> "interval": "5s"  
> }  
> },  
> "input": {  
> "chain": {  
> "inputs": [  
> {  
> "previous": {  
> "search": {  
> "request": {  
> "indices": ["cef-ssh-watch-results"],  
> "types": "brute\_force",  
> "body": {  
> "size": 0,  
> "aggs": {  
> "users": {  
> "terms": {  
> "field": "destinationUserName",  
> "size": 100  
> },  
> "aggs": {  
> "times": {  
> "terms": {  
> "field": "@timestamp",  
> "size": 100  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> {  
> "events": {  
> "search": {  
> "request": {  
> "indices": [  
> "cef-ssh-\*"  
> ],  
> "types": "syslog",  
> "body": {  
> "query": {  
> "bool": {  
> "filter": [  
> {  
> "terms": {  
> "categoryBehaviour": [  
> "cowrie.login.success",  
> "cowrie.login.failed"  
> ]  
> }  
> },  
> {  
> "exists": {  
> "field": "destinationUserName"  
> }  
> }  
> ]  
> }  
> },  
> "aggregations": {  
> "users": {  
> "terms": {  
> "field": "destinationUserName",  
> "size": 1500,  
> "min\_doc\_count": 4  
> },  
> "aggs": {  
> "times": {  
> "terms": {  
> "field": "@timestamp",  
> "size": 15000,  
> "order": {  
> "\_term": "asc"  
> }  
> },  
> "aggs": {  
> "access": {  
> "terms": {  
> "field": "categoryBehaviour",  
> "size": 1  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "size": 0  
> }  
> }  
> }  
> }  
> }  
> ]  
> }  
> },  
> "condition": {  
> "script": {  
> "inline": "if (ctx.payload.events.hits.total == 0 || ctx.payload.events.aggregations.users.buckets.size() == 0) { return false; } def historical\_events = ; if (ctx.payload.previous.hits.total \> 0) { historical\_events = ctx.payload.previous.aggregations.users.buckets.stream().flatMap(user -\> user.times.buckets.stream().map(time -\> user.key + '-' + time.key)).collect(Collectors.toList()); } for (user in ctx.payload.events.aggregations.users.buckets) { def failed = 0; for (time in user.times.buckets) { if (time.access.buckets[0].key == 'cowrie.login.failed') { failed += 1; } else { if (failed \>= ctx.metadata.required\_failures && !historical\_events.contains(user.key + '-' + time.key)) { return true; } else { failed=0; } } } } return false;"  
> }  
> },  
> "transform": {  
> "script": "def historical\_events = ; if (ctx.payload.previous.hits.total \> 0) { historical\_events = ctx.payload.previous.aggregations.users.buckets.stream().flatMap(user -\> user.times.buckets.stream().map(time -\> user.key + '-' + time.key)).collect(Collectors.toList()); } def users=[:]; for (user in ctx.payload.events.aggregations.users.buckets) { def times = ; def failed = 0; for (time in user.times.buckets) { if (time.access.buckets[0].key == 'cowrie.login.failed') { failed += 1; } else { if (failed \>= ctx.metadata.required\_failures && !historical\_events.contains(user.key + '-' + time.key)) { times.add(time.key\_as\_string); } failed = 0; } } if (times.length \> 0) { users[user.key] = times; } } return users;"  
> },  
> "actions": {  
> "log": {  
> "logging": {  
> "text": "More than {{ctx.metadata.required\_failures}} denied logins, followed by access granted, by the same user: {{ctx.payload}}"  
> }  
> },  
> "index\_payload": {  
> "transform": {  
> "script": "return ['\_doc':ctx.payload.entrySet().stream().flatMap(value -\> value.getValue().stream().map(timestamp -\> ['alert':true,'@timestamp':timestamp,'destinationUserName':value.getKey()])).collect(Collectors.toList())];"  
> },  
> "index": {  
> "index": "cef-ssh-watch-results",  
> "doc\_type": "brute\_force"  
> }  
> },  
> "email\_alert": {  
> "email": {  
> "to": "'John [John@example.com](mailto:John@example.com)'",  
> "subject": "Suspected SSH Brute force Alert",  
> "body": "More than {{ctx.metadata.required\_failures}} denied logins, followed by access granted, by the same user: {{ctx.payload}}"  
> }  
> }  
> }  
> }  
> }

Please assist.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 6, 2018, 8:25am UTC](https://discuss.elastic.co/t/email-alert-with-readable-body/142972/2 "2018-08-06T08:25:11Z")

</div>

please invest some more time and explain what your problem is properly, what exactly fails. Also provide the output of the execute watch API and what exactly your expectations are. Also explain what you tried so far and what did not work as expected to understand the usecase better and how we can improve on the watcher side.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2018, 8:31am UTC](https://discuss.elastic.co/t/email-alert-with-readable-body/142972/3 "2018-09-03T08:31:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
