# How to link to entries triggering a rule

**URL:** <https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting, detection-rules\
**Created:** [March 9, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334 "2023-03-09T08:36:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![blindahl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blindahl/32/118231_2.png) [@blindahl](https://discuss.elastic.co/u/blindahl)\
**Post date:** [March 9, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/1 "2023-03-09T08:36:10Z")

</div>

We have setup some Rules and Alerts that should trigger if we get error in our logs. In the mail that is sent when a rule is triggered it feels natural to include a link to Discover view with some filters setup and with the time interval that shows the error(s) that triggered the Rule+Alert.

We wonder if we're doing something fundamentally wrong because when adding some filters, the url to Discover view get so long that it sometimes exceed some limit that Outlook can handle.

Is it possible somehow to create a link to a Discover with some predefined filters that get a static, much shorter url that can be reused. The only thing we really want to vary is the time interval where we want to show only the interval where the errors appeared in our logs.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 22, 2023, 7:45pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/2 "2023-03-22T19:45:05Z")

</div>

You can create a permalink using the Share link in Discover. From there you can select to use a short url. Here is the relevant [documentation](https://www.elastic.co/guide/en/kibana/current/reporting-getting-started.html).

---

<div class="post-metadata">

**Author:** ![blindahl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blindahl/32/118231_2.png) [@blindahl](https://discuss.elastic.co/u/blindahl)\
**Post date:** [March 22, 2023, 8:03pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/3 "2023-03-22T20:03:18Z")

</div>

But can you generate a permalink through API or something since I need to create the link including the time interval containing the entries that triggered the rule. Not sure how that would be done. Haven't found anything about that in the documentation.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 22, 2023, 8:18pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/4 "2023-03-22T20:18:40Z")

</div>

Yeah, that might not be currently possible. I'd imagine you could replace the time value and have the saved search just look back a set amount, but not sure. That might get you where you need to go.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 23, 2023, 5:28pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/5 "2023-03-23T17:28:57Z")

</div>

Ok, using 7.x here, but it should probably work find in 8.x as well. From Discover you should be able to Share the snap shot, from there you'll see a "time" section in the URL. You'll want to set the "to" section to an absolute time and have "from" be relative. For example this would search from today at 17:00 to back 4 days.

```auto
time:(from:now-4d%2Fd,to:'2023-03-23T17:00:00.000Z')

```

I was able to successfully change those settings in the URL and see them take effect in the browser. Good luck.

---

<div class="post-metadata">

**Author:** ![blindahl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blindahl/32/118231_2.png) [@blindahl](https://discuss.elastic.co/u/blindahl)\
**Post date:** [March 31, 2023, 5:21am UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/6 "2023-03-31T05:21:43Z")

</div>

Thanks for the response. The issue is that we have some filters we want to include and they take up quite a lot of space in the url and is quite cumbersome to maintain as well. But maybe we can utilize saved search somehow making things more manageable.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 31, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/7 "2023-03-31T21:19:26Z")

</div>

Yeah that makes sense. I wonder if you could save the search with the filters on it and then reference that saved search in a visualization and then share the visualization and change the time there. Never tried that before but it might be possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334/8 "2023-04-28T21:19:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
