# Seperate email alerts per detection?

**URL:** <https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112>\
**Category:** SIEM\
**Tags:** elastic-stack-security\
**Created:** [April 11, 2022, 2:21pm UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112 "2022-04-11T14:21:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_G](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Post date:** [April 11, 2022, 2:21pm UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112/1 "2022-04-11T14:21:26Z")

</div>

Hi Everyone,

I've been doing some testing with the Email Alerts, to alert us when a specific event code is generated.

I've done this under Security \> Rules, and it runs every 5 minutes. It works absolutely fine but the issue is if multiple detections are found these are all included in the single email alert, although the documentation I've read seems to suggest a seperate email woud be generated per detection:

> **[Alerting | Kibana Guide \[8.1\] | Elastic](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

Although there is talk of Watchers & Alerting being seperate which may be the issue? But this has lost me a little to be honest as further research seems to circle back to the initial alerting page.

This is my current Action using the Email connector:

```auto
Subject: 
A scan has been initiated on{{#context.alerts}} {{agent.name}} {{/context.alerts}}

Message:
Rule {{context.rule.name}} generated {{state.signals_count}} alerts

{{#context.alerts}}
**Agent Name:** {{agent.name}}  

**Scan Type:** {{winlog.event_data.Scan Type}}

**User:** {{winlog.event_data.User}}

**Elastic Timestamp:** {{@timestamp}}
{{/context.alerts}}

```

So when there has been one instance everything looks great, but if multiple have triggered since the rule last ran then all the Hosts are listed in the Subject and then one after another in the message body, followed by the next field etc. destroying any readability.

Am I going about this the wrong way?

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 5, 2022, 11:39pm UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112/2 "2022-05-05T23:39:41Z")

</div>

Hey there @Josh_G, thanks for all the details here and using Elastic Security! 🙂

So unfortunately, the documentation you're referencing is for the Stack Alerting feature, not the Security Alerting feature, which differs in implementation in a few areas.

Currently, all Security Rule types are only capable of running the alert action for the group of alerts either created during the execution, or created since the action last fired (if the action is configured to run at an interval).

I went ahead and created [this enhancement](https://github.com/elastic/kibana/issues/131684) to add a feature that allows the user to specify the granularity for which they would like to fire their actions (per alert, per grouping, etc). If I missed any part of your use case please feel free to add a comment to the issue so we can capture it in planning.

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![Josh\_G](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Post date:** [May 17, 2022, 8:58am UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112/3 "2022-05-17T08:58:23Z")

</div>

Hi Garrett, thanks for clarifying.

I have managed to clean my output up since my post with some solid lines to seperate the alerts etc, but seperate emails per alert would certainly be preferable for how we are using them.

The enhancement request captures what I'm after.

Thanks again for your help.

Josh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 8:59am UTC](https://discuss.elastic.co/t/seperate-email-alerts-per-detection/302112/4 "2022-06-14T08:59:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
