# Kibana alert on index threshold

**URL:** https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221
**Category:** Kibana
**Created:** [March 24, 2021, 1:54pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221 "2021-03-24T13:54:20Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![sireesha\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sireesha_m/32/85688_2.png) [@sireesha\_m](https://discuss.elastic.co/u/sireesha_m)
#### Post date: [March 24, 2021, 1:54pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/1 "2021-03-24T13:54:20Z")

</div>

I have created an index 'foo'. I created an alert of type index threshold to send emails when any info is written in this index.  
But I see that the alert has not changed to 'active' state. It stays in 'ok' and I see no emails.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 24, 2021, 5:29pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/2 "2021-03-24T17:29:24Z")

</div>

Hi @sireesha_m

We can't help unless you provide the configuration of the alert.

I suspect you want to do this from the API, my suggestion would be to set up and email connector via the Kibana GUI and Test it.

Then Set up a Threshold Alert through the Kibana GUI and test it.

Then do a GET on that alert and action via the new API and use it as a template.

I just set up a new email connector and tested it.

 ![Screen Shot 2021-03-24 at 8.08.59 AM](https://us1.discourse-cdn.com/elastic/original/3X/1/3/13b0cd30b6b29f3226399419347859a4c7aeb5cf.png)

Then I setup a threadshold alert... and I could see it was over the threshold

 ![Screen Shot 2021-03-24 at 7.57.33 AM](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bd5490d35905df0902d21667a44ae8382a171b9.png)

Saved it and it fired, these alerts have been around for a long time, they are pretty solid.

Then if I wanted to create another one the the Alerts API I would GET this one.

The API is brand new, so go slowly / be careful Let us know if there are any doc issues etc.

First I searched for it.

`curl -u elastic:asldkfjhasdfkljhasldkfjhasd 'https://192blsakdjfhalskdjfhlaskdjfh.us-west1.gcp.cloud.es.io/api/alerts/_find?search_fields=name&search=threshold' | jq`

And get that as an example to work from.

```
{
  "page": 1,
  "perPage": 10,
  "total": 1,
  "data": [
    {
      "id": "db417e40-8caf-11eb-9114-b532abbbc0df",
      "notifyWhen": "onActionGroupChange",
      "params": {
        "aggType": "count",
        "termSize": 5,
        "thresholdComparator": ">",
        "timeWindowSize": 1,
        "timeWindowUnit": "m",
        "groupBy": "all",
        "threshold": [
          400
        ],
        "index": [
          "metrics-*"
        ],
        "timeField": "@timestamp"
      },
      "consumer": "alerts",
      "alertTypeId": ".index-threshold",
      "schedule": {
        "interval": "1m"
      },
      "actions": [
        {
          "actionTypeId": ".email",
          "params": {
            "subject": "alert '{{alertName}}' is active for group '{{context.group}}':",
            "to": [
              "stephen.brown@elastic.co"
            ],
            "message": "alert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
          },
          "group": "threshold met",
          "id": "e0f3b4a0-8cb1-11eb-9114-b532abbbc0df"
        },
        {
          "actionTypeId": ".slack",
          "params": {
            "message": "alert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
          },
          "group": "threshold met",
          "id": "f6ebfc33-a974-41d2-ad0a-7b1b8cc714fb"
        },
        {
          "actionTypeId": ".slack",
          "params": {
            "message": "RECOVERED\n\nalert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
          },
          "group": "recovered",
          "id": "f6ebfc33-a974-41d2-ad0a-7b1b8cc714fb"
        }
      ],
      "tags": [],
      "name": "test-index-threshold",
      "enabled": true,
      "throttle": null,
      "apiKeyOwner": "4212746406",
      "createdBy": "4212746406",
      "updatedBy": "4212746406",
      "muteAll": false,
      "mutedInstanceIds": [],
      "updatedAt": "2021-03-24T15:27:27.492Z",
      "createdAt": "2021-03-24T14:47:29.779Z",
      "scheduledTaskId": "34251720-8cb4-11eb-9114-b532abbbc0df",
      "executionStatus": {
        "lastExecutionDate": "2021-03-24T17:27:33.283Z",
        "status": "ok"
      }
    }
  ]
}

```

then I used the `id` to get that individual alert

`curl -u elastic:kasjfdhsalkdjfhasldfkj 'https://11k234jh123kljh12k3jh792fa.us-west1.gcp.cloud.es.io/api/alerts/alert/db417e40-8caf-11eb-9114-b532abbbc0df' | jq`

```
{
  "id": "db417e40-8caf-11eb-9114-b532abbbc0df",
  "notifyWhen": "onActionGroupChange",
  "params": {
    "aggType": "count",
    "termSize": 5,
    "thresholdComparator": ">",
    "timeWindowSize": 1,
    "timeWindowUnit": "m",
    "groupBy": "all",
    "threshold": [
      400
    ],
    "index": [
      "metrics-*"
    ],
    "timeField": "@timestamp"
  },
  "consumer": "alerts",
  "alertTypeId": ".index-threshold",
  "schedule": {
    "interval": "1m"
  },
  "actions": [
    {
      "actionTypeId": ".email",
      "params": {
        "subject": "alert '{{alertName}}' is active for group '{{context.group}}':",
        "to": [
          "stephen.brown@elastic.co"
        ],
        "message": "alert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
      },
      "group": "threshold met",
      "id": "e0f3b4a0-8cb1-11eb-9114-b532abbbc0df"
    },
    {
      "actionTypeId": ".slack",
      "params": {
        "message": "alert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
      },
      "group": "threshold met",
      "id": "f6ebfc33-a974-41d2-ad0a-7b1b8cc714fb"
    },
    {
      "actionTypeId": ".slack",
      "params": {
        "message": "RECOVERED\n\nalert '{{alertName}}' is active for group '{{context.group}}':\n\n- Value: {{context.value}}\n- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}\n- Timestamp: {{context.date}}"
      },
      "group": "recovered",
      "id": "f6ebfc33-a974-41d2-ad0a-7b1b8cc714fb"
    }
  ],
  "tags": [],
  "name": "test-index-threshold",
  "enabled": true,
  "throttle": null,
  "apiKeyOwner": "4212746406",
  "createdBy": "4212746406",
  "updatedBy": "4212746406",
  "muteAll": false,
  "mutedInstanceIds": [],
  "updatedAt": "2021-03-24T15:27:27.492Z",
  "createdAt": "2021-03-24T14:47:29.779Z",
  "scheduledTaskId": "34251720-8cb4-11eb-9114-b532abbbc0df",
  "executionStatus": {
    "lastExecutionDate": "2021-03-24T17:30:42.269Z",
    "status": "ok"
  }
}
```

---

<div class="post-metadata">

### Author: ![sireesha\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sireesha_m/32/85688_2.png) [@sireesha\_m](https://discuss.elastic.co/u/sireesha_m)
#### Post date: [March 24, 2021, 6:04pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/3 "2021-03-24T18:04:34Z")

</div>

Thanks for the elaborate email.  
Essentially, you are saying that we will be able to raise alerts on any index. I saw that it was possible. I was able to create a threshold alert alone.

Regardless of the API, do you know kibana alerting supports getting the "to" list from a mustache template. Specifically, I want to access the contents of the doc which contributed towards raising the alert.

For example, I have an index foo with doc1 contaning, "message" and "created\_at". I want to display this message in email.  
I tried to access it from {{context}}. But I don't think it's supported

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 24, 2021, 6:17pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/4 "2021-03-24T18:17:37Z")

</div>

That's not supported today.

Content from the source documents is not supported.

And if we dig a little deeper alerts are aggregates (I think you may be setting your threshold /aggregate to 1 but it still an aggregate) but for this example let's say your threshold was 5 documents , nothing really guarantees that `message` would be the same for every document counted so which `message` would go in the alert? The first one , the last one?

That is why the content from the source documents are not supported as I understand it.

In short the source documents are not available to the alert actions.

---

<div class="post-metadata">

### Author: ![sireesha\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sireesha_m/32/85688_2.png) [@sireesha\_m](https://discuss.elastic.co/u/sireesha_m)
#### Post date: [March 25, 2021, 12:50am UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/5 "2021-03-25T00:50:04Z")

</div>

Yes got it, thanks for the confirmation.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 25, 2021, 4:49pm UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/6 "2021-03-25T16:49:50Z")

</div>

Hi @sireesha_m

I was thinking... this was also just released as part of 7.12 the new [DSL Query Alert](https://www.elastic.co/guide/en/kibana/current/alert-type-es-query.html)

And look at this....

`context.hits`

The most recent ES documents that matched the query. Using the [Mustache](https://mustache.github.io/) template array syntax, you can iterate over these hits to get values from the ES documents into your actions.

So you might be able to get the last / latest messages / values...

I just learned this and thought you might be interested...

---

<div class="post-metadata">

### Author: ![sireesha\_m](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sireesha_m/32/85688_2.png) [@sireesha\_m](https://discuss.elastic.co/u/sireesha_m)
#### Post date: [March 26, 2021, 12:11am UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/7 "2021-03-26T00:11:44Z")

</div>

That's nice. I have cluster running on 7.11 version. Is this feature generally available? I guess kibana emails and actions are available only through the gold plan.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [March 26, 2021, 12:53am UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/8 "2021-03-26T00:53:18Z")

</div>

The DSL Query is GA in 7.12

Yes Email Actions (Slack etc) start at Gold, Gold adds a lot of value for a relatively small uplift in cost

You can look [here](https://www.elastic.co/subscriptions/cloud) for feature vs subscription level and [here](https://cloud.elastic.co/deployment-pricing-table) for pricing

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 23, 2021, 12:53am UTC](https://discuss.elastic.co/t/kibana-alert-on-index-threshold/268221/9 "2021-04-23T00:53:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
