# Kibana alerting message with query results

**URL:** <https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075>\
**Category:** Kibana\
**Created:** [February 12, 2021, 2:06am UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075 "2021-02-12T02:06:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![earlsanchez](https://avatars.discourse-cdn.com/v4/letter/e/b9e5f3/32.png) [@earlsanchez](https://discuss.elastic.co/u/earlsanchez)\
**Post date:** [February 12, 2021, 2:06am UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/1 "2021-02-12T02:06:57Z")

</div>

I have a Kibana monitor setup with a trigger and actions. In the actions email message I can email the alert query results for 1 document with these ctx parameters:

```auto
- Hostname: {{ctx.results.0.hits.hits.0._source.host.name}}
- Log file: {{ctx.results.0.hits.hits.0._source.log.file.path}}
- Log message: 
{{ctx.results.0.hits.hits.0._source.message}}

```

If there are multiple documents returned from the trigger query results is there a way to include all documents results in the email message?

TIA!

---

<div class="post-metadata">

**Author:** ![earlsanchez](https://avatars.discourse-cdn.com/v4/letter/e/b9e5f3/32.png) [@earlsanchez](https://discuss.elastic.co/u/earlsanchez)\
**Post date:** [February 16, 2021, 10:15pm UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/2 "2021-02-16T22:15:23Z")

</div>

Anyone have any information regarding this post?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [February 17, 2021, 8:50pm UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/3 "2021-02-17T20:50:38Z")

</div>

Hi,

you can use the a chained input and just issue two different queries? Would that help already?

> **[Watcher chain input | Elasticsearch Reference \[7.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/input-chain.html)**

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![earlsanchez](https://avatars.discourse-cdn.com/v4/letter/e/b9e5f3/32.png) [@earlsanchez](https://discuss.elastic.co/u/earlsanchez)\
**Post date:** [February 17, 2021, 10:02pm UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/4 "2021-02-17T22:02:29Z")

</div>

@rashmi Thanks for the recommendation. Unfortunately we are using the open source Kibana which only has the Alerting module not Watcher.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [February 18, 2021, 1:35am UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/5 "2021-02-18T01:35:38Z")

</div>

@pmuellr can u plz share ur thoughts on this ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 18, 2021, 5:43am UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/6 "2021-02-18T05:43:50Z")

</div>

Hi @earlsanchez

There is perhaps an entirely different way to look at this. I'm not clear if you actually want to email all the logs (imagine there are hundreds) or you just want the alert to be able to show the user all the logs that made up the alert?

What you can do is create a URL in the action that would point to the Discover app in Kibana (or other customer dashboard) with the same query / filters parameters and time that made the alert fire and then you would be able to see the docs that caused the alert to fire.

What if there we're hundreds of documents would you really want to email all those?

Just a thought something I've done for several customers.

---

<div class="post-metadata">

**Author:** ![earlsanchez](https://avatars.discourse-cdn.com/v4/letter/e/b9e5f3/32.png) [@earlsanchez](https://discuss.elastic.co/u/earlsanchez)\
**Post date:** [February 18, 2021, 5:19pm UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/7 "2021-02-18T17:19:08Z")

</div>

Thank you @stephenb, I am doing that now with the search criteria URL. I think this along with one event message as I described above is the best solution. You are correct, I probably don't really want hundreds of events being emailed. Thx.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2021, 5:19pm UTC](https://discuss.elastic.co/t/kibana-alerting-message-with-query-results/264075/8 "2021-03-18T17:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
