# How to extract specific data from extraction query response

**URL:** <https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [June 8, 2021, 8:42pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349 "2021-06-08T20:42:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![marifwanna](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@marifwanna](https://discuss.elastic.co/u/marifwanna)\
**Post date:** [June 8, 2021, 8:42pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349/1 "2021-06-08T20:42:33Z")

</div>

I am using an extraction query in monitor to alert me in case the email I send to a user bounces. I am able to get the trigger to work and receive an alert on slack  
I would like to include the user's email in the alert too. Is there any way to extract the user's email from the query responses  
{  
"version": true,  
"size": 500,  
"sort": [  
{  
"orig\_timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "orig\_timestamp",  
"fixed\_interval": "12h",  
"time\_zone": "xxx",  
"min\_doc\_count": 1  
}  
}  
},  
"stored\_fields": [  
"_"  
],  
"script\_fields": {},  
"docvalue\_fields": [  
{  
"field": "orig\_timestamp",  
"format": "date\_time"  
}  
],  
"\_source": {  
"excludes": []  
},  
"query": {  
"bool": {  
"must": [  
{  
"query\_string": {  
"query": "Bounce",  
"analyze\_wildcard": true,  
"time\_zone": "xxx"  
}  
}  
],  
"filter": [  
{  
"match\_phrase": {  
"\_index": "xxx"  
}  
},  
{  
"range": {  
"orig\_timestamp": {  
"gte": "2021-04-24T20:33:14.329Z",  
"lte": "2021-06-08T20:33:14.329Z",  
"format": "strict\_date\_optional\_time"  
}  
}  
}  
],  
"should": [],  
"must\_not": []  
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"_": {}  
},  
"fragment\_size": 2147483647  
}  
}

---

<div class="post-metadata">

**Author:** ![Aaron\_Caldwell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_caldwell/32/45755_2.png) [@Aaron\_Caldwell](https://discuss.elastic.co/u/Aaron_Caldwell)\
**Post date:** [June 9, 2021, 3:10pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349/2 "2021-06-09T15:10:58Z")

</div>

Hello,

I don't think is possible currently. There's an [open issue](https://github.com/elastic/kibana/issues/69611) that describes a similar request. You might want to take a look and comment if you'd like!

Regards,  
Aaron

---

<div class="post-metadata">

**Author:** ![marifwanna](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@marifwanna](https://discuss.elastic.co/u/marifwanna)\
**Post date:** [June 10, 2021, 7:51pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349/3 "2021-06-10T19:51:00Z")

</div>

Hi ,  
would it at least be possible to get the entire log into and display it with the alert message in slack  
Thanks for help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2021, 7:51pm UTC](https://discuss.elastic.co/t/how-to-extract-specific-data-from-extraction-query-response/275349/4 "2021-07-08T19:51:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
