# How to create proper alert for multiple hits?

**URL:** <https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [April 5, 2023, 1:22pm UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432 "2023-04-05T13:22:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jackshan](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jackshan](https://discuss.elastic.co/u/jackshan)\
**Post date:** [April 5, 2023, 1:22pm UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432/1 "2023-04-05T13:22:00Z")

</div>

I have a scenario where i am matching two metadata along with "level" = "error". I am setting the time to last 15 minutes for running the query. The monitor does capture what i want, but when there are multiple hits in the last 15 minutes, the alert is messed up. The information is sent without any spaces between two different metadata.  
This is my query below:

```auto
{
    "size": 10000,
    "query": {
        "bool": {
            "must": [
                {
                    "query_string": {
                        "query": "\"metadata1\" AND \"metadata2\"",
                        "default_field": "*",
                        "fields": [],
                        "type": "best_fields",
                        "default_operator": "or",
                        "max_determinized_states": 10000,
                        "enable_position_increments": true,
                        "fuzziness": "AUTO",
                        "fuzzy_prefix_length": 0,
                        "fuzzy_max_expansions": 50,
                        "phrase_slop": 0,
                        "analyze_wildcard": true,
                        "escape": false,
                        "auto_generate_synonyms_phrase_query": true,
                        "fuzzy_transpositions": true,
                        "boost": 1
                    }
                },
                {
                    "match_phrase": {
                        "level": {
                            "query": "error",
                            "slop": 0,
                            "zero_terms_query": "NONE",
                            "boost": 1
                        }
                    }
                },
                {
                    "range": {
                        "@timestamp": {
                            "from": "{{period_end}}||-15m",
                            "to": "{{period_end}}",
                            "include_lower": true,
                            "include_upper": true,
                            "format": "epoch_millis",
                            "boost": 1
                        }
                    }
                }
            ],
            "adjust_pure_negative": true,
            "boost": 1
        }
    },
    "_source": {
        "includes": [],
        "excludes": []
    },
    "stored_fields": "*",
    "docvalue_fields": [
        {
            "field": "@timestamp",
            "format": "date_time"
        },
        {
            "field": "start_time",
            "format": "date_time"
        },
        {
            "field": "timestamp",
            "format": "date_time"
        },
        {
            "field": "ts",
            "format": "date_time"
        }
    ],
    "script_fields": {
        "logSize": {
            "script": {
                "source": "doc['_size']",
                "lang": "painless"
            },
            "ignore_failure": false
        }
    },
    "sort": [
        {
            "@timestamp": {
                "order": "asc",
                "unmapped_type": "boolean"
            }
        }
    ],
    "aggregations": {
        "2": {
            "date_histogram": {
                "field": "@timestamp",
                "time_zone": "Asia/Kolkata",
                "interval": "3h",
                "offset": 0,
                "order": {
                    "_key": "asc"
                },
                "keyed": false,
                "min_doc_count": 1
            }
        }
    },
    "highlight": {
        "pre_tags": [
            "@kibana-highlighted-field@"
        ],
        "post_tags": [
            "@/kibana-highlighted-field@"
        ],
        "fragment_size": 2147483647,
        "fields": {
            "*": {}
        }
    }
}

```

And this is the message that i am using in the trigger:

```auto
{"markdown":" \nExecutionReqId: ``{{#ctx.results.0.hits.hits}}{{_source.execRequestId}}{{/ctx.results.0.hits.hits}}`` \n \n ClientId: ``{{#ctx.results.0.hits.hits}}{{_source.clientId}}{{/ctx.results.0.hits.hits}}`` \n\n Logiflow Id: ``{{#ctx.results.0.hits.hits}}{{_source.logiflowId}}{{/ctx.results.0.hits.hits}}`` \n \nTraceID: ``{{#ctx.results.0.hits.hits}}{{_source.traceId}}{{/ctx.results.0.hits.hits}}`` 

```

Also, what's the correct documentation to follow for this?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 15, 2023, 5:10am UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432/2 "2023-04-15T05:10:41Z")

</div>

Hello.  
That looks like a Watcher query. Most of the documentation will be here: [Watcher | Kibana Guide [8.7] | Elastic](https://www.elastic.co/guide/en/kibana/current/watcher-ui.html)

I would recommend taking a look at Alerting as well since it has achieved parity in more user-friendly way in most places.

> **[Alerting | Kibana Guide \[8.7\] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2023, 5:11am UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432/3 "2023-05-13T05:11:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
