# Getting Alerts and Actions to work

**URL:** <https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [March 3, 2021, 10:27am UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086 "2021-03-03T10:27:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilai\_Velocity](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilai_velocity/32/84875_2.png) [@Ilai\_Velocity](https://discuss.elastic.co/u/Ilai_Velocity)\
**Post date:** [March 3, 2021, 10:27am UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086/1 "2021-03-03T10:27:02Z")

</div>

Hey guys,  
I got a few questions that I encountered when trying to setup alerts and actions.

We're on the Elasticsearch as a Service (Managed) solution.

Question 1 -  
I'm following [Defining alerts | Kibana Guide [7.x] | Elastic](https://www.elastic.co/guide/en/kibana/7.x/defining-alerts.html) to define alerts, and I want to display a link back to the alert in the message. However, {{kibanaBaseUrl}} is empty.  
Based on [Configure Kibana | Kibana Guide [7.x] | Elastic](https://www.elastic.co/guide/en/kibana/7.x/settings.html#server-publicBaseUrl) it probably means that `server.publicBaseUrl` is not populated.

First, I would expect the managed elasticsearch to have this populated, and second, I tried editing it in the `kibana.yml` in the management console but I got an error: "Your changes cannot be applied. Kibana - 'server.publicBaseUrl': is not allowed".

Question 2 -  
I tried placing newlines ("\n" ) inside a JSON field in the body of a webhook action, but it got messed up. How can create new lines in JSON messages?

Question 3 -  
I'm trying to close an alert in Opsgenie after the alert was recovered, and this requires setting a variable URL (.../alerts/close/{{alertId}}) but I suspect mustache variables are not populated in webhook URLs. How can this be solved?

Question 4 -  
Is there a way to troubleshoot why alerts are firing off?  
I have an alert that is configured to alert for every unique value of a field, and it is firing for instance `*` (star), but that's not a value of the field. I suspect it's a bug on your side?

Thanks a lot in advance, expecting to hear from you soon so we can get this alerting solution to a "production-ready" level,  
Ilai

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 5, 2021, 4:23am UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086/2 "2021-03-05T04:23:46Z")

</div>

cc @pmuellr /@gmmorris can you shed some light here please ?

Thanks

---

<div class="post-metadata">

**Author:** ![gmmorris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmorris/32/72624_2.png) [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Post date:** [March 9, 2021, 1:34pm UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086/3 "2021-03-09T13:34:59Z")

</div>

hey @Ilai_Velocity ,  
Sorry you encountered this somewhat broken UX 😬

> [@Ilai\_Velocity](#):
>
> First, I would expect the managed elasticsearch to have this populated

Agreed, and this is in process.  
There are a variety of complications which might not be obvious looking in from the outside.  
As there are a wide range of deployment strategies (such as multiple Kibana across managed and unmanaged, different proxies in front of served Kibana etc.), configuring this out ofthe box has proved tricky.

> [@Ilai\_Velocity](#):
>
> I tried editing it in the `kibana.yml` in the management console but I got an error: "Your changes cannot be applied. Kibana - 'server.publicBaseUrl': is not allowed".

That said, this is an obvious oversight - you should be able to set this manually.  
I've spoken to the team that owns this configuration and they have assured me they'll look to add this to the allowlist asap.

> [@Ilai\_Velocity](#):
>
> Question 2 -  
> I tried placing newlines ("\n" ) inside a JSON field in the body of a webhook action, but it got messed up. How can create new lines in JSON messages?

I am aware of an [issue](https://github.com/elastic/kibana/issues/81849) with newlines which we're hoping to get to as part of 7.13 (though, I can't commit to that), but it looks like using explicit "\n" works.  
Could you share the exact config that's failing for you?

> [@Ilai\_Velocity](#):
>
> I'm trying to close an alert in Opsgenie after the alert was recovered, and this requires setting a variable URL (.../alerts/close/{{alertId}}) but I suspect mustache variables are not populated in webhook URLs. How can this be solved?

You're correct- this isn't supported at the moment.  
We began looking into this and realised there's actually a security/safety difficulty here.  
The complexity to this is that it would mean _user A_ could provide authorization for a specific URL, but _user B_ could then programatically change where that URL is pointing.  
We have to find a good safe way of modeling this feature in a manner that keeps it secure and safe to use.

In the meantime, we're hoping to find capacity for the development of a dedicated OpsGenie Connector type in 7.13 (but as stated above, I can't commit to that).  
You can track the issue [here](https://github.com/elastic/kibana/issues/56403)

> [@Ilai\_Velocity](#):
>
> Is there a way to troubleshoot why alerts are firing off?

That depends on the Alert Type. 🤔

> [@Ilai\_Velocity](#):
>
> I have an alert that is configured to alert for every unique value of a field, and it is firing for instance `*` (star), but that's not a value of the field. I suspect it's a bug on your side?

That does sound weird, but I can't confirm if it's a bug without more details.  
Could you provide more details for where you're encountering this?

What Alert Type is this?  
How is it configured?  
Can you provide an example of the data that it's alerting on?

---

<div class="post-metadata">

**Author:** ![Ilai\_Velocity](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilai_velocity/32/84875_2.png) [@Ilai\_Velocity](https://discuss.elastic.co/u/Ilai_Velocity)\
**Post date:** [March 11, 2021, 8:37am UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086/4 "2021-03-11T08:37:49Z")

</div>

Hi Gidi! Thanks for the elaborate answers.

> That said, this is an obvious oversight - you should be able to set this manually.  
> I've spoken to the team that owns this configuration and they have assured me they'll look to add this to the allowlist asap.

Thank you! Is there any estimation as to what ASAP means?

> I am aware of an [issue](https://github.com/elastic/kibana/issues/81849) with newlines which we're hoping to get to as part of 7.13 (though, I can't commit to that), but it looks like using explicit "\n" works.  
> Could you share the exact config that's failing for you?

I am using a simple "\n", but I send it via the API and when I look at the webhook body in the UI, I see a new line, which is an invalid JSON message (and it also doesn't trigger, which brings me back to the question of how to debug the actions)

> In the meantime, we're hoping to find capacity for the development of a dedicated OpsGenie Connector type in 7.13 (but as stated above, I can't commit to that).  
> You can track the issue [here](https://github.com/elastic/kibana/issues/56403)

Thank you.

> That depends on the Alert Type. 🤔

Got it. So... "Inventory. Alert when the inventory exceeds a defined threshold."

> That does sound weird, but I can't confirm if it's a bug without more details.  
> Could you provide more details for where you're encountering this?
> 
> What Alert Type is this?  
> How is it configured?  
> Can you provide an example of the data that it's alerting on?

So we figured out what it was: An instance of an alert of no data... I would say it's very unintuitive. Would consider changing how it's being presented.

Adding a question:

Question 5 -  
I'm getting the following error:  
`An error occurred when decrypting the alert. Saved object [alert/<uuid>] not found`

 ![Screen Shot 2021-03-11 at 10.36.02](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5c9130f6095924353b9ee78ba2863c9986946a8d.png)

Indeed when I queried `api/saved_objects/_find?type=alert` there were 0 results. This looks like a bug?

Thanks again, Ilai

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2021, 8:38am UTC](https://discuss.elastic.co/t/getting-alerts-and-actions-to-work/266086/5 "2021-04-08T08:38:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
