# Send link to search in slack

**URL:** <https://discuss.elastic.co/t/send-link-to-search-in-slack/81359>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 5, 2017, 6:12pm UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359 "2017-04-05T18:12:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![isaac](https://avatars.discourse-cdn.com/v4/letter/i/8e8cbc/32.png) [@isaac](https://discuss.elastic.co/u/isaac)\
**Post date:** [April 5, 2017, 6:12pm UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/1 "2017-04-05T18:12:22Z")

</div>

Hi,

Is it possible to send a link with the search that will match the watcher that has been triggered with the slack message?

Or any similar way to easily find the errors in kibana when getting the slack notification.

Thanks,  
Isaac

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 6, 2017, 7:26am UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/2 "2017-04-06T07:26:13Z")

</div>

Hey,

that depends how you wrote your query. If you are using the `query_string`query, you could create a proper link to the dashboard or the discover tab (just check how the URL's are constructed) and embed that into the slack message, as this query is used in kibana as well. if you used another query, that is not possible.

Hope this helps.

--Alex

---

<div class="post-metadata">

**Author:** ![isaac](https://avatars.discourse-cdn.com/v4/letter/i/8e8cbc/32.png) [@isaac](https://discuss.elastic.co/u/isaac)\
**Post date:** [April 6, 2017, 7:30am UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/3 "2017-04-06T07:30:23Z")

</div>

Hi Alex,

thanks, we are not using query string, but it's not a problem to change the query into it.

Cheers,  
Isaac

---

<div class="post-metadata">

**Author:** ![isaac](https://avatars.discourse-cdn.com/v4/letter/i/8e8cbc/32.png) [@isaac](https://discuss.elastic.co/u/isaac)\
**Post date:** [April 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/4 "2017-04-06T13:48:12Z")

</div>

I'm trying to get a few values out of the watcher event, same way I did for hits and I'm not being able to get them.  
For hits I'm using:  
{{ctx.payload.hits.total}}  
Not sure if they are not available or if I'm using the wrong syntax.  
The two fields are:  
result.input.search.request.body.query.bool.must.query\_string.query  
result.execution\_time

Are those available?

Thanks,  
Isaac

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 10, 2017, 7:21am UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/5 "2017-04-10T07:21:50Z")

</div>

Hey,

you cannot extract the query, as the query is in the request, but not in the response. You would need to duplicate that. Execution time is available though.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![isaac](https://avatars.discourse-cdn.com/v4/letter/i/8e8cbc/32.png) [@isaac](https://discuss.elastic.co/u/isaac)\
**Post date:** [April 10, 2017, 8:03am UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/6 "2017-04-10T08:03:42Z")

</div>

Hi Alex,

it helps thanks!  
It's a bit annoying because we need to remember to update the search in two places but does the job.

Cheers,  
Isaac

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2017, 8:05am UTC](https://discuss.elastic.co/t/send-link-to-search-in-slack/81359/7 "2017-05-08T08:05:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
