# Log threshold alert with the actual message inside the alert

**URL:** <https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [October 21, 2021, 7:26am UTC](https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258 "2021-10-21T07:26:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ido\_Ilani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ido_ilani/32/96175_2.png) [@Ido\_Ilani](https://discuss.elastic.co/u/Ido_Ilani)\
**Post date:** [October 21, 2021, 7:26am UTC](https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258/1 "2021-10-21T07:26:56Z")

</div>

Hi,  
I set up a Log threshold alert to Slack when number of error log lines exceeds a certain limit.  
Is there a way to alert to Slack the actual log message body? I searched for a way and the only variables I see I can add to the message relates to the context, query, etc..

Looking forward for you answer 🙂  
Thanks,  
Ido

---

<div class="post-metadata">

**Author:** ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)\
**Post date:** [October 26, 2021, 11:38am UTC](https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258/2 "2021-10-26T11:38:20Z")

</div>

Hi,

I'm sorry but this functionality doesn't exist at the moment. However, we are aware this is an enhancement many are looking for, and it's something we'll hopefully be looking into by creating more specific rule types in the future (however I can't give any timeframes).

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 26, 2021, 3:01pm UTC](https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258/3 "2021-10-26T15:01:42Z")

</div>

There is a conversation about this in progress in [[Logs UI] Make matching documents available in log threshold alert action context · Issue #112447 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/112447). You're welcome to weigh in over there too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2021, 3:02pm UTC](https://discuss.elastic.co/t/log-threshold-alert-with-the-actual-message-inside-the-alert/287258/4 "2021-11-23T15:02:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
