# Question about creating a link to document in Kibana

**URL:** <https://discuss.elastic.co/t/question-about-creating-a-link-to-document-in-kibana/132335>\
**Category:** Kibana\
**Created:** [May 17, 2018, 12:57pm UTC](https://discuss.elastic.co/t/question-about-creating-a-link-to-document-in-kibana/132335 "2018-05-17T12:57:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![reswob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reswob/32/38015_2.png) [@reswob](https://discuss.elastic.co/u/reswob)\
**Post date:** [May 17, 2018, 12:57pm UTC](https://discuss.elastic.co/t/question-about-creating-a-link-to-document-in-kibana/132335/1 "2018-05-17T12:57:09Z")

</div>

Regarding the discussion below and the creation of a link directly to a document.

> [@Alert to contain link to Kibana search results](https://discuss.elastic.co/t/alert-to-contain-link-to-kibana-search-results/57750):
>
> Hello, Is there an easy way to have a Watcher action (let's say webhook) that can generate a link to Kibana with the query matching the data that triggered the alert? The idea being, I want to send a notification of new errors in logs, and the notification should contain a link - clicking this link should execute the search that triggered the alert. Thanks, Andrey

So I have created a link that works going to a specific document based on the 'share' capability in Kibana (note that the index is specified rather than using a wild card):

[http://ip:5601/app/kibana#/discover?\_g=(time:(from:now-1w,mode:quick,to:now)](http://ip:5601/app/kibana#/discover?_g=(time:(from:now-1w,mode:quick,to:now)))&=(columns:!(\_source),index:logstash-2018-05-15,interval:auto,query:(query\_string:(analyze\_wildcard:!t,query:'\_id:12k24j2l35k2l')))

While this works, I get an orange error that says

Discover: "logstash-2018-05-15" is not a configured pattern ID. Using the default index pattern: "23daslkj234jrlew"

This default index pattern isn't shown in the document details, how do I get a list of all my default index patterns?

The reason I'm doing this is because when I create an alert to send to someone based on a singe document, I want to link back to that document without having to build a dashboard.

Also, note that using a wildcard in the above search doesn't work.

index:logstash-\*

This gives an "unable to parse url" error

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 17, 2018, 7:50pm UTC](https://discuss.elastic.co/t/question-about-creating-a-link-to-document-in-kibana/132335/2 "2018-05-17T19:50:08Z")

</div>

`23daslkj234jrlew` is the ID of your default index pattern (different from its human readable name). The `index` parameter in the url requires this ID. The default index pattern is whichever one you selected in the management section of Kibana.

This might probably be problematic for you if you have a large number of index patterns, because I don't think Watcher will expose this information. If you only have a small number of index patterns and can hard code this index ID into your alerts, you can find the ID of each one of your index patterns in the Management section of Kibana. In Management select the "Index Patterns" link, then select the pattern you're interested in the sidebar, then look at the URL. The long string of numbers and letters in the URL is the ID.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2018, 7:50pm UTC](https://discuss.elastic.co/t/question-about-creating-a-link-to-document-in-kibana/132335/3 "2018-06-14T19:50:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
