# How can I trigger an email alert that includes all alerts, instead of sending each alert live? Urgent! Please help

**URL:** <https://discuss.elastic.co/t/how-can-i-trigger-an-email-alert-that-includes-all-alerts-instead-of-sending-each-alert-live-urgent-please-help/373943>\
**Category:** Elastic Agent\
**Tags:** elastic-stack-alerting\
**Created:** [January 31, 2025, 1:31pm UTC](https://discuss.elastic.co/t/how-can-i-trigger-an-email-alert-that-includes-all-alerts-instead-of-sending-each-alert-live-urgent-please-help/373943 "2025-01-31T13:31:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![evangelin](https://avatars.discourse-cdn.com/v4/letter/e/838e76/32.png) [@evangelin](https://discuss.elastic.co/u/evangelin)\
**Post date:** [January 31, 2025, 1:31pm UTC](https://discuss.elastic.co/t/how-can-i-trigger-an-email-alert-that-includes-all-alerts-instead-of-sending-each-alert-live-urgent-please-help/373943/1 "2025-01-31T13:31:47Z")

</div>

Hello team,  
I have installed Elastalert2 and configured it with elk  
i want to trigger an email alert that includes all alerts, instead of sending each alert live? Like custom rule anything?  
How can i do that please help!  
i have used this custom rule to trigger live email alerts

```auto
index: .ds-logs-auditd.log-default-*
type: any

filter:
- term:
    event.action: "started-session"
- bool:
    must_not:
      term:
        user.terminal: "cron"
        
alert:
- "email"

email:
- "***"
smtp_host: d.in
smtp_port: port
smtp_auth_file: smtp_auth.yaml

alert_subject: "Alert: Sudo Command Execution or Session Start Detected on {0}"
alert_subject_args:
  - "agent.name"

alert_text: |
  Alert! A sudo command execution or session start was detected:

  - Timestamp: {0}
  - Host: {1}
  - User ID: {2}
  - Username: {3}
  - Event Action: {4}
  - Outcome: {5}

alert_text_type: alert_text_only
alert_text_args:
  - "@timestamp"
  - "agent.name"
  - "user.id"
  - "user.name"
  - "event.action"
  - "event.outcome"

```

i was getting alert!!  
So i tried modifying this rule to print the output in the file the rule looks like

```auto
cat elastalert2/custom/rules/sudo_rule_file.yaml 
name: "Sudo Command Execution Alert"
type: any

index: .ds-logs-auditd.log-default-*

filter:
  - term:
      event.action: "started-session"

alert: 
  - command

command: 
  - "/bin/bash"
  - "-c"
  - "echo 'Alert! sudo command executed at {{@timestamp}} on {{agent.name}} by user {{user.id}} ({{user.name}}) with outcome: {{event.outcome}}' >> /home/sandra/sudo_alert.txt"

command_args:
  - "@timestamp"
  - "agent.name"
  - "user.id"
  - "user.name"
  - "event.outcome"

alert_subject: "Alert: Sudo Command Execution Detected on {{agent.name}}"
alert_subject_args:
  - "agent.name"

alert_text: |
  **Alert! A sudo command was executed:**

  - **Timestamp:** {{@timestamp}}
  - **Host:** {{agent.name}}
  - **User ID:** {{user.id}}
  - **Username:** {{user.name}}
  - **Outcome:** {{event.outcome}}

alert_text_type: alert_text_only
alert_text_args:
  - "@timestamp"
  - "agent.name"
  - "user.id"
  - "user.name"
  - "event.outcome"

```

but the output was

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/256e91972c728220b5f0e81050d281fd3a47b5ee.png)

Please help me to solve this

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 31, 2025, 4:02pm UTC](https://discuss.elastic.co/t/how-can-i-trigger-an-email-alert-that-includes-all-alerts-instead-of-sending-each-alert-live-urgent-please-help/373943/2 "2025-01-31T16:02:01Z")

</div>

ElastAlert2 is not a Elastic tool, it is a third-party tool that is not supported here.

You need to ask on their Github.

Also, check their documentation, you need to aggregate your alerts as explained [here](https://elastalert2.readthedocs.io/en/latest/ruletypes.html#aggregation).
