# Log Threshold - Alert Body

**URL:** <https://discuss.elastic.co/t/log-threshold-alert-body/350979>\
**Category:** Logs\
**Tags:** elastic-stack-alerting\
**Created:** [January 12, 2024, 4:15pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979 "2024-01-12T16:15:43Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [January 12, 2024, 4:15pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/1 "2024-01-12T16:15:43Z")

</div>

Hello,

As referenced here: [Action variables for a Logs threshold rule](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394)

I created a log threshold rule. I would like to do is use variables/fields from the documents/logs to appear in the email body.

Like how it was mentioned in above, you should be able to use `{{context.hits}}` but nothing is appearing. Any help is much appreciated,

Thanks,  
Erik

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 12, 2024, 4:36pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/2 "2024-01-12T16:36:29Z")

</div>

> [@erikg](#):
>
> Hello,
> 
> As referenced here: [Action variables for a Logs threshold rule](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394)
> 
> I created a log threshold rule. I would like to do is use variables/fields from the documents/logs to appear in the email body.
> 
> Like how it was mentioned in above, you should be able to use `{{context.hits}}` but nothing is appearing. Any help is much appreciated,
> 
> Thanks,  
> Erik

Hi,

The {{context.hits}} variable should give you access to the documents that matched your threshold condition, but you need to specify the exact field you want to display.

For example, if you want to display a field named "message" from your logs, you should use {{context.hits.message}} in your alert message. If the field is nested, you would use dot notation to access it, like {{context.hits.field.subfield}}.

Regards

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [January 12, 2024, 4:58pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/3 "2024-01-12T16:58:49Z")

</div>

Hey @yago82 ,

Look, I tried it and the fields don't appear (unless I am doing it wrong):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2cd9f7f9ded4f5349c7909581657b608b7ff9cb2.png)

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [January 24, 2024, 3:01pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/4 "2024-01-24T15:01:22Z")

</div>

Hello ,  
This is my sample data and I tried to use this as you mentioned .Still nothing comes in my body e-mail:

{{context.hits.\_source.v2.private.src\_labels.app}}.

Still no value comes. It has been so many hours wasted to address this issue. Would you please help.  
Best,  
Narges

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af8912946b231a7f755bdd6c93cc18956e8a6b03.png)

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [January 24, 2024, 3:12pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/5 "2024-01-24T15:12:27Z")

</div>

You can find the response of e-mail notification here: No value

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62d72eb24b85fae50eaa89eddf17ac3c01f7694b.png)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 24, 2024, 7:30pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/6 "2024-01-24T19:30:49Z")

</div>

Hi @erikg,

I think the log threshold rule type doesn't grant access to individual documents in its alert context since it only operates on aggregate results. If I read the code correctly, though, it puts a whole bunch of ECS fields from the first document in the aggregate result into the context: [kibana/packages/kbn-ecs/generated/ecs\_flat.ts at cd907739f3cb4c57bb2ace7a6da538226b5334d7 · elastic/kibana · GitHub](https://github.com/elastic/kibana/blob/cd907739f3cb4c57bb2ace7a6da538226b5334d7/packages/kbn-ecs/generated/ecs_flat.ts)

Maybe the values you are looking for are in there?

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [January 25, 2024, 5:42pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/7 "2024-01-25T17:42:39Z")

</div>

Any update on this @erikg

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [January 25, 2024, 7:48pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/8 "2024-01-25T19:48:49Z")

</div>

Hey @NShrek ,

I see you are using ES Query, which is what I ended up doing since Log Threshold wasn't working.  
I looked at your alert body and it should have worked, perhaps you can try doing this:

This makes it so it can go through all the hits or documents that match your query.

```auto
{{#context.hits}}
{{_source.host.name}}
{{/context.hits}}

```

This worked for me:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2f26ea3fb76cfeadb544c0a3ec602d852c5c4a4.png)

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [January 25, 2024, 7:53pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/9 "2024-01-25T19:53:13Z")

</div>

Hey @weltenwort , yeah not sure why it doesn't work because I used @timestamp in the sample^ , I was recommended to use Elastic Query rule instead.  
Thanks!

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [January 29, 2024, 2:56pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/10 "2024-01-29T14:56:44Z")

</div>

Hello @erikg .Thanks very much. I could see all the data now. How can I go deeper in the data.

```auto
-APP NAME PLS: 
{{#context.hits}} 
{{_source.v2.private}}
{{/context.hits}}

```

Also do you know how can i modify time from zolo to UTC .  
This did not work:

{{#FormatDate}} {{{date}}} ; America/New\_York {{/FormatDate}}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a1aad9654da7c3626908f34310f2428fe97bf50.png)

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [January 30, 2024, 2:55pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/11 "2024-01-30T14:55:46Z")

</div>

Hey @NShrek

You can access any fields now like:

```auto
-APP NAME PLS: 
{{#context.hits}} 
{{_source.v2.private}}
{{_source.v2.private.dst_label}}
{{_source.v2.private.src_ip}}
{{/context.hits}}

```

As for the date, interesting I am not sure why yours doesn't work but here's the one I use:  
`{{#FormatDate}} {{{signal.original_time}}} ; America/Los_Angeles; DD MMMM YYYY {{/FormatDate}}`

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [January 30, 2024, 3:59pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/12 "2024-01-30T15:59:14Z")

</div>

Hello Erik,  
Thanks very much for your quick response! 🤩

I was following this docs on Elastic and I wanted to create some kind of headings for each variable but it did not work.

[Rule action variables | Kibana Guide [8.12] | Elastic](https://www.elastic.co/guide/en/kibana/8.12/rule-action-variables.html#alert-summary-action-variables)

at the bottom of the page is render sample, how can i do that?  
Also time format did not work.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec7c871f8a85d5838445f527a8fd8069facb81e8.png)

Best,  
Narges

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [February 2, 2024, 3:28pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/13 "2024-02-02T15:28:38Z")

</div>

@erikg is there any way we format the way that it shows the data in the email. Would u pls help?

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [February 2, 2024, 5:19pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/14 "2024-02-02T17:19:12Z")

</div>

Hey @NShrek , perhaps you can share your alert body, to help you but also I can share my alert body.

For the markdown this my example:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c51f90fc8e1c8a8ac804201743b5a377c6d6fe6c.png)

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [February 2, 2024, 5:38pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/15 "2024-02-02T17:38:48Z")

</div>

Hey , thanks! If you go to the **image from 4days ago** , I need to show all destination info

for example

```auto
| **Destination Application** | {{_source.v2.private.dst_label.app}}
| **Destination IP Address** | {{_source.v2.private.dst_ip}}

```

Is this correct?

Best,  
Narges

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [February 2, 2024, 5:48pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/16 "2024-02-02T17:48:24Z")

</div>

Hey, yes that is correct!  
but don't forget to include `{{#context.hits}}` at the beginning and  
`{{/context.hits}}` at the end.

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [February 2, 2024, 10:24pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/17 "2024-02-02T22:24:44Z")

</div>

You are awesome! It worked and data is very clean now . I dont see the columns but it is showing in a very better format. thanks @erikg

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [February 5, 2024, 2:03pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/18 "2024-02-05T14:03:39Z")

</div>

@erikg Hey,

I got this far by your help. Could you please tell me how can I make headings and show the data under the header .

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73cf53259712ca568ce1412a2dda84d62bb7ea95.png)

Best,  
Narges

---

<div class="post-metadata">

**Author:** ![NShrek](https://avatars.discourse-cdn.com/v4/letter/n/b487fb/32.png) [@NShrek](https://discuss.elastic.co/u/NShrek)\
**Post date:** [February 6, 2024, 2:39pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/19 "2024-02-06T14:39:01Z")

</div>

@erikg would you pls help me on this?

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [February 6, 2024, 3:13pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979/20 "2024-02-06T15:13:45Z")

</div>

Hey @NShrek ,

So based on image,

You would need to move the heading before the `{{#context.hits}}` .  
As you can see in my example, I placed Event Details before `{{#context.hits}}`  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50f7a38dfb8771325b6ccf7289070dc3f6150a8b.png)  
Hope that helps!

[Next page](https://discuss.elastic.co/t/log-threshold-alert-body/350979.md?page=2)
