# How to loop over the ctx results, so as to send the extracted details in email alert?

**URL:** <https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [July 27, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419 "2023-07-27T10:17:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Divya\_Thaore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/divya_thaore/32/122479_2.png) [@Divya\_Thaore](https://discuss.elastic.co/u/Divya_Thaore)\
**Post date:** [July 27, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419/1 "2023-07-27T10:17:58Z")

</div>

The result set for example is :  
{  
"\_shards": {  
"total": 14,  
"failed": 0,  
"successful": 14,  
"skipped": 0  
},  
"hits": {  
"hits": [  
{  
"\_index": "logs-cfsyslog-2023.07.26",  
"\_type": "\_doc",  
"\_source": {  
"msg": "-",  
"referer": "-",  
"request\_size\_b": 7586,  
"x\_forwarded\_host": "-",  
"type": "request",  
"response\_status": 502,  
"correlation\_id": "caef30ae-e285-430b-5d07-0a9a36c34019"  
},  
"\_id": "RWbSkYkBtg3oak8jtmYg",  
"\_score": 2.2181222  
},  
{  
"\_index": "logs-cfsyslog-2023.07.24",  
"\_type": "\_doc",  
"\_source": {  
"msg": "-",  
"referer": "-",  
"request\_size\_b": 610,  
"x\_forwarded\_host": "-",  
"response\_status": 502,  
"correlation\_id": "63323fc8-efba-424f-69a9-adc7e313dcb1"  
},  
"\_id": "vY7KhokBjssTDO\_uKkRP",  
"\_score": 2.148272  
},  
{  
"\_index": "logs-cfsyslog-2023.07.22",  
"\_type": "\_doc",  
"\_source": {  
"msg": "-",  
"referer": "-",  
"response\_status": 500,  
"correlation\_id": "7f0b2e77-387f-468d-6bfc-5a4b710668f2"  
},  
"\_id": "84ipf4kBjssTDO\_uZFYk",  
"\_score": 2.0124397  
}  
],  
"total": {  
"value": 3,  
"relation": "eq"  
},  
"max\_score": 2.2181222  
},  
"took": 3,  
"timed\_out": false  
}

I want to extract the correlation\_id and response\_status for each of the documents returned in the resultset and add the same in the email alert.

the sample which I am using right now is returning only single first value. I want to know the way of looping over the resultset.  
Sample used by me for email alert is -  
{  
"eventType": "KibanaAlert",  
"resource": {  
"resourceName": "{{ctx.trigger.name}}",  
"resourceType": "cloud-resource"  
},  
"severity": "WARNING",  
"category": "ALERT",  
"subject": "Kibana Alert by {{ctx.trigger.name}} triggered",  
"body": "Monitor {{ctx.monitor.name}} just entered alert status. Please investigate the issue. CorrelationId is :{{ctx.results.0.hits.hits.0.\_source.correlation\_id}},Response status is :{{ctx.results.0.hits.hits.0.\_source.response\_status}}",  
"tags": {  
"ctx.monitor.name": "{{ctx.monitor.name}}",  
"ctx.trigger.name": "{{ctx.trigger.name}}",  
"ctx.periodStart": "{{ctx.periodStart}}",  
"ctx.periodEnd": "{{ctx.periodEnd}}",  
"ctx.trigger.severity": "{{ctx.trigger.severity}}",  
"ctx.results":"{{ctx.results.0.hits.hits.0.\_source.correlation\_id}}"

```
}

```

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2023, 10:18am UTC](https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419/2 "2023-08-24T10:18:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
