# How to show custom data in alerts messages in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [August 30, 2021, 6:19am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777 "2021-08-30T06:19:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhinav3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhinav3/32/62151_2.png) [@abhinav3](https://discuss.elastic.co/u/abhinav3)\
**Post date:** [August 30, 2021, 6:19am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/1 "2021-08-30T06:19:07Z")

</div>

Hi

I have a below data coming to elasticsearch:

```auto
{
	"Data": {
		"WiFiIP": "N/A",
		"signal_strength": "N/A",
		"signal_percent": 0,
		"signal_level": "N/A",
		"CPU": 10,
		"cpu_temp": 47.0,
		"Internet": true,
		"Publish msg count": 8631,
		"Created": "2021-08-30T06:15:07.789527",
		"DeviceId": "TX-D2-319",
		"UpTime": "2021-08-24T07:53:11"
	}
}

```

It has value of cpu temp. In Kibana I have set alert on cpu temp so that if t increases more than 65, I get an alert on Microsoft Teams with below message:

server temperature has increased more than 65\*C.

I have many devices which are uploading data to elastisearch. I wanted to know how I can get the DeviceId in the alert message so that I know which device cpu temperature has increased?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2021, 10:10am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/2 "2021-08-30T10:10:56Z")

</div>

Hey,

so the idea would be to run a query for documents \> 65 degrees celsius in the last `n` minutes, but also have a **terms** aggregation, that aggregates on the `DeviceId`, so you can include the ids in your message.

See [Terms aggregation | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/search-aggregations-bucket-terms-aggregation.html)

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![abhinav3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhinav3/32/62151_2.png) [@abhinav3](https://discuss.elastic.co/u/abhinav3)\
**Post date:** [August 30, 2021, 10:40am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/3 "2021-08-30T10:40:25Z")

</div>

Hey spinscale

When creating a monitor, we do not have option to select DeviceId. Below is the image of how I am creating monitor

 ![ty](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28a0570341efa8e4fda74656d6dcb300fbcf8478.png)

In above image I have selected the index pattern, then getting the count of documents for last 1hr where cpu is greater than 60. And in the trigger, I define this count to be lets say more than 10. So count of all document where cpu temp is more than 60, is greater than 10, I get an alert. I do not see any option for DeviceId here. Can you please explain, if I am moving in wrong direction. Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2021, 11:34am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/4 "2021-08-30T11:34:02Z")

</div>

On top of my head this will not work with the threshold watch, but you need to write the watch yourself (or use the advanced watch tab, which is just a JSON editor) when you create the watch.

---

<div class="post-metadata">

**Author:** ![abhinav3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhinav3/32/62151_2.png) [@abhinav3](https://discuss.elastic.co/u/abhinav3)\
**Post date:** [August 30, 2021, 12:24pm UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/5 "2021-08-30T12:24:53Z")

</div>

Can you share any link to document sharing how to write your own watch. Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 30, 2021, 1:11pm UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/6 "2021-08-30T13:11:09Z")

</div>

See [Create or update watch API | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/watcher-api-put-watch.html) and even more the whole watcher documentation, starting with the getting started docs at [Getting started with Watcher | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/watcher-getting-started.html)

---

<div class="post-metadata">

**Author:** ![abhinav3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhinav3/32/62151_2.png) [@abhinav3](https://discuss.elastic.co/u/abhinav3)\
**Post date:** [August 31, 2021, 4:57am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/7 "2021-08-31T04:57:09Z")

</div>

Hi spinscale

Thanks for sharing the links. I didn't knew we can create watch & alerts this way also. I will work on this and will close this topic. Will create any topic if any issues. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2021, 4:57am UTC](https://discuss.elastic.co/t/how-to-show-custom-data-in-alerts-messages-in-kibana/282777/8 "2021-09-28T04:57:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
