I have a Kibana monitor setup with a trigger and actions. In the actions email message I can email the alert query results for 1 document with these ctx parameters:
There is perhaps an entirely different way to look at this. I'm not clear if you actually want to email all the logs (imagine there are hundreds) or you just want the alert to be able to show the user all the logs that made up the alert?
What you can do is create a URL in the action that would point to the Discover app in Kibana (or other customer dashboard) with the same query / filters parameters and time that made the alert fire and then you would be able to see the docs that caused the alert to fire.
What if there we're hundreds of documents would you really want to email all those?
Just a thought something I've done for several customers.
Thank you @stephenb, I am doing that now with the search criteria URL. I think this along with one event message as I described above is the best solution. You are correct, I probably don't really want hundreds of events being emailed. Thx.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.