# Issue with contextlink value for alerts

**URL:** <https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 27, 2025, 6:07pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496 "2025-03-27T18:07:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarioCDS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariocds/32/142293_2.png) [@MarioCDS](https://discuss.elastic.co/u/MarioCDS)\
**Post date:** [March 27, 2025, 6:07pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/1 "2025-03-27T18:07:28Z")

</div>

Hello,  
We've been having an issue where our context.link in staging displays the wrong value for our alerts. In dev it shows the correct url like **[elk-dev.company.com](http://elk-dev.company.com)** but in staging it shows **[company-elk-staging.kb.westeurope.azure.elastic-cloud.com:9243](http://company-elk-staging.kb.westeurope.azure.elastic-cloud.com:9243)**  
How can this context.link value be changed?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/e/1e4de265a18554f67270948831dc9da443430f1d.png)

Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 28, 2025, 8:16pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/2 "2025-03-28T20:16:39Z")

</div>

Hi @MarioCDS Welcome to the community...

Concerning you issues the dev endpoint looks like a self managed cluster and the staging looks like and Elastic Cloud Hosted deployment that context is pulled from the underlying meta data

What version are you on and are you running different types of deployments?

Note: Seems like you perhaps tried to post this a couple time but since you are a new user the bot sees those links as attempted spam.

---

<div class="post-metadata">

**Author:** ![MarioCDS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariocds/32/142293_2.png) [@MarioCDS](https://discuss.elastic.co/u/MarioCDS)\
**Post date:** [April 1, 2025, 10:53am UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/3 "2025-04-01T10:53:25Z")

</div>

Hey @stephenb , thanks for the answer, I am running both on version 8.6.1, from what I can see both staging and dev environment have build\_type: "docker".  
Is there any way I can change this "context.link" property?

---

<div class="post-metadata">

**Author:** ![MarioCDS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariocds/32/142293_2.png) [@MarioCDS](https://discuss.elastic.co/u/MarioCDS)\
**Post date:** [May 19, 2025, 9:54pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/4 "2025-05-19T21:54:46Z")

</div>

Any help on this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 19, 2025, 10:48pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/5 "2025-05-19T22:48:29Z")

</div>

I asked a question whether one was running in elastic cloud and the other was running self-managed on-prem  
The build type of docker is not what matters. It's the URL which you access them by?

And of course you can put any value you like in hard-coded. But no, I don't think those contact links can be changed

That looks like elastic Cloud to me  
`company-elk-staging.kb.westeurope.azure.elastic-cloud.com:9243`

---

<div class="post-metadata">

**Author:** ![MarioCDS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariocds/32/142293_2.png) [@MarioCDS](https://discuss.elastic.co/u/MarioCDS)\
**Post date:** [May 19, 2025, 11:12pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/6 "2025-05-19T23:12:26Z")

</div>

When I ping the URLs both return the same IP and DNS, which makes me think they're both hosted on cloud  
"k8s-infra-01-public-companyname.westeurope.cloudapp.azure"

Also the real issue is that when I press the link from alerts built in staging "company-elk-staging.kb.westeurope.azure.elastic-cloud:9243" it fails with the below error, which forces me to manually replace the URL with elk-staging.company

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99635a9438a2ad4442fff619f0eb171a23bc7334.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 19, 2025, 11:46pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496/7 "2025-05-19T23:46:08Z")

</div>

Sorry I'm confused. I have lost track of what the actual URL

> [@MarioCDS](#):
>
> k8s-infra-01-public-companyname.westeurope.cloudapp.azure

I don't know what that is....

The IP is most likely the proxy endpoint for elastic cloud which then gets translated.

Also, you'll always have to authenticate that's not going to happen automatically from an alert from like an email or something.

I'm not sure I can help because I don't have enough information.... I suspect you created an alias for your elastic cloud, although I think that should still work.

I will test when I get a chance with my elastic Cloud deployment and see what the context link is

Perhaps you should open a support ticket.
