# Fire alert for each document with specific value in field

**URL:** <https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [May 21, 2021, 3:44pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685 "2021-05-21T15:44:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dzious](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@Dzious](https://discuss.elastic.co/u/Dzious)\
**Post date:** [May 21, 2021, 3:44pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/1 "2021-05-21T15:44:38Z")

</div>

Hi,

I'm currently struggling with Filebeat and Alerts.  
I'm trying to build a system that would allow me to fire an alert for each document with a specific value in log.level field.

From what i tried i was only able to fire when N documents have a specific level. And when this alert is fired, it doesn't make one alert for each document but one telling me N documents have a log level of "Warn" (this is just an example).

Any help on how to do so would be appreciate.  
Thanks by advance

---

<div class="post-metadata">

**Author:** ![Dzmitry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dzmitry/32/65026_2.png) [@Dzmitry](https://discuss.elastic.co/u/Dzmitry)\
**Post date:** [May 21, 2021, 5:42pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/2 "2021-05-21T17:42:13Z")

</div>

Hi @Dzious ,

There are 2 ways to detect condition and take actions in stack: Kibana Alerting & Watcher.  
You can check the difference [here](https://www.elastic.co/guide/en/kibana/7.x/alerting-getting-started.html#alerting-concepts-differences)  
I don't think Kibana alerting today allows to build condition based on field value the way. you described, but since [watcher](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/xpack-alerting.html) supports ES query you might be able to do it there.

Regards, Dzmitry

---

<div class="post-metadata">

**Author:** ![Dzious](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@Dzious](https://discuss.elastic.co/u/Dzious)\
**Post date:** [May 25, 2021, 6:40am UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/3 "2021-05-25T06:40:03Z")

</div>

hi @Dzmitry,  
Thanks for your help.  
Unfortunately i'm only able to get the basic licence this means i wont be able to access watchers.  
Moreover, Kibana Alerting allow me to use query based alerts. My problem is that i cannot fire an alert for each document individualy. Because Alerts require a minimum number of match

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [May 25, 2021, 11:44am UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/4 "2021-05-25T11:44:37Z")

</div>

Hi @Dzious!

It sounds like you are using the Elasticsearch query rule type to create your own Elasticsearch DSL query and fire alerts based on the conditions. Is that correct? If so, you are correct in that there is currently no way to trigger an action based on each matching document. The rule will trigger a single action if the specified condition is matched and then the contents of each matching document will be available inside the `context.hits` [action variable](https://www.elastic.co/guide/en/kibana/7.12/alert-type-es-query.html#_add_action_variables_2), where the maximum number of documents retrieved is controlled by the `size` parameter.

---

<div class="post-metadata">

**Author:** ![Dzious](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@Dzious](https://discuss.elastic.co/u/Dzious)\
**Post date:** [May 25, 2021, 12:21pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/5 "2021-05-25T12:21:54Z")

</div>

Hi @ying.mao !  
Yeah that's exactly what i tried... Sad to learn that it's not possible  
I wasn't aware of the `context.hits` action variable. Thanks for that.  
is there a way for me to retrive a single document such as `{{context.hits[i]}}` with `i < size` ?  
Thanks by advance

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [May 25, 2021, 12:51pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/6 "2021-05-25T12:51:05Z")

</div>

> is there a way for me to retrive a single document such as `{{context.hits[i]}}` with `i < size` ?

Hi @Dzious! We use Mustache as our templating engine, so you can iterate over `context.hits` like this:

```auto
{{#context.hits}}
This is my document id {{_id}}
{{/context.hits}}

```

Or access a specific array element like this:

```auto
First hit document id: {{context.hits.0._id}}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2021, 12:51pm UTC](https://discuss.elastic.co/t/fire-alert-for-each-document-with-specific-value-in-field/273685/7 "2021-06-22T12:51:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
