# Send Email from watcher when the system get specify log

**URL:** <https://discuss.elastic.co/t/send-email-from-watcher-when-the-system-get-specify-log/209566>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 26, 2019, 6:55pm UTC](https://discuss.elastic.co/t/send-email-from-watcher-when-the-system-get-specify-log/209566 "2019-11-26T18:55:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mord](https://avatars.discourse-cdn.com/v4/letter/m/ed8c4c/32.png) [@mord](https://discuss.elastic.co/u/mord)\
**Post date:** [November 26, 2019, 6:55pm UTC](https://discuss.elastic.co/t/send-email-from-watcher-when-the-system-get-specify-log/209566/1 "2019-11-26T18:55:05Z")

</div>

Hello Everyone.  
My Elasticsearch getting logs of "Security risk found" in Event Name(field).  
I want to get details of this log to my email.  
In my watcher I create a new alert with this text:

```
 {
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "*sepm*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "match": {
                    "EventName.keyword": "Security risk found"
                  }
                },
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-1m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          },
          "sort": [
            {
              "@timestamp": {
                "order": "desc"
              }
            }
          ]
        }
      }
    }
  },
  "condition": {
    "always": {}
  },
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "mymail@mycompany.com"
        ],
        "subject": "ALERT: {{ctx.payload.hits.hits.0._source.EventName}}",
        "body": {
          "text": "Time: {{ctx.payload.hits.hits.0._source.TimeStamp}}\n\nEvent Name: {{ctx.payload.hits.hits.0._source.EventName}}\nDomainSEP: {{ctx.payload.hits.hits.0._source.DomainSEP}}\nGroup: {{ctx.payload.hits.hits.0._source.Group}}\nHostName: {{ctx.payload.hits.hits.0._source.HostName}}\nUserName: {{ctx.payload.hits.hits.0._source.UserName}}\nIPAddress: {{ctx.payload.hits.hits.0._source.IPAddress}}\n\nRisk Name: {{ctx.payload.hits.hits.0._source.RiskName}}\nSHA256: {{ctx.payload.hits.hits.0._source.SHA256}}\nAction: {{ctx.payload.hits.hits.0._source.Action}}\nPath: {{ctx.payload.hits.hits.0._source.Path}}\n\nPayload:\n{{ctx.payload.hits.hits.0._source.Message}}\nTimes:Scheduled{{ctx.trigger.scheduled_time}}||-1m\nTriggered{{ctx.trigger.triggered_time}}-------------\n\n"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 28, 2019, 9:13am UTC](https://discuss.elastic.co/t/send-email-from-watcher-when-the-system-get-specify-log/209566/2 "2019-11-28T09:13:19Z")

</div>

do you care to explain what the current problem is in order to be better able to help? In your example an email would get send, even if no document matched the query, as the condition triggers always. This might already be a problem.

Otherwise please take the time to be clear what you expect and what is not working as expected.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 9:13am UTC](https://discuss.elastic.co/t/send-email-from-watcher-when-the-system-get-specify-log/209566/3 "2019-12-26T09:13:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
