# Include entire query result in Watcher email

**URL:** <https://discuss.elastic.co/t/include-entire-query-result-in-watcher-email/223988>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 17, 2020, 7:15pm UTC](https://discuss.elastic.co/t/include-entire-query-result-in-watcher-email/223988 "2020-03-17T19:15:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkaiser101](https://avatars.discourse-cdn.com/v4/letter/m/ecc23a/32.png) [@mkaiser101](https://discuss.elastic.co/u/mkaiser101)\
**Post date:** [March 17, 2020, 7:15pm UTC](https://discuss.elastic.co/t/include-entire-query-result-in-watcher-email/223988/1 "2020-03-17T19:15:08Z")

</div>

I am attempting to include all fields from my search query results in an watcher email, currently I can only see what I am matching directly in my query.

```auto
{

  "trigger": {

    "schedule": {

      "interval": "90s"

    }

  },

  "input": {

    "search": {

      "request": {

        "search_type": "query_then_fetch",

        "indices": [

          "wazuh-alerts-3.x-*"

        ],

        "rest_total_hits_as_int": true,

        "body": {

          "size": 1000,

          "query": {

            "bool": {

              "must": [

                {

                  "match": {

                    "syscheck.tags": "1234"

                  }

                },

                {

                  "range": {

                    "timestamp": {

                      "gte": "now-90s",

                      "lte": "now"

                    }

                  }

                }

              ]

            }

          }

        }

      }

    }

  },

  "condition": {

    "compare": {

      "ctx.payload.hits.total": {

        "gte": 1

      }

    }

  },

  "actions": {

    "send_email": {

      "email": {

        "profile": "standard",

        "attachments": {

          "attached_data": {

            "data": {

              "format": "json"

            }

          }

        },

        "priority": "high",

        "to": [

          "yellow@gmail.com"

        ],

        "subject": "Arbitrary Email Subject ",

        "body": {

          "text": "See attached JSON file for details"

        }

      }

    }

  }

}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 18, 2020, 3:16pm UTC](https://discuss.elastic.co/t/include-entire-query-result-in-watcher-email/223988/2 "2020-03-18T15:16:43Z")

</div>

The `attached_data` will always only contain the data that was returned by your query. In this example 1000 documents. There is no way, that it will return more data.

In addition, email is probably not the best way to send potentially millions of documents somewhere. Maybe just execute a scroll search by yourself?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2020, 3:16pm UTC](https://discuss.elastic.co/t/include-entire-query-result-in-watcher-email/223988/3 "2020-04-15T15:16:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
