# Stack Monitoring Alerts Disk Usage, how to get the node name only?

**URL:** <https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [June 1, 2023, 4:07pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012 "2023-06-01T16:07:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 1, 2023, 4:07pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012/1 "2023-06-01T16:07:51Z")

</div>

Hello,

I'm using the built-in _Disk Usage_ rule in Kibana Alert on my monitoring cluster to alert me when a node reaches more than 94% of disk usage (I've changed my watermarks), this works fine, but now I need to send those alerts to slack and I'm trying to get only the node name to use on the slack webhook payload, but the variable `context.node` gives me the node name **and** the disk usage percent, which I do not want.

I'm using these two context variables.

![Screenshot from 2023-06-01 13-04-00](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f0d6193297a495456cbe5c5fdcf3ed4b3f7ec39.png)

I would expect the `context.node` would give me the node name, and `context.state` the current state of the alert, but using `context.node` gives me the node name followed by the disk usage percent in the following format:

`node-name:95`

Is there any way to get only the node name? Should I open an issue to fix this?

My monitoring cluster is on `8.8.0`.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012/2 "2023-06-01T16:33:25Z")

</div>

Well, aparently there is no way to get just the node name.

Looking at the content of the context field, these are the fields available:

```auto
{
  "internalShortMessage": "Disk usage alert is firing for node nodeName-06 in cluster: clusterName. Verify disk usage level of node.",
  "internalFullMessage": "Disk usage alert is firing for node nodeName-06 in cluster: clusterName. [View node](/app/monitoring#/elasticsearch/nodes/redactedNodeId?_g=(cluster_uuid:redactedClusterId))",
  "state": "firing",
  "nodes": "nodeName-06:96",
  "count": 1,
  "node": "nodeName-06:96",
  "clusterName": "clusterName",
  "action": "[View node](/app/monitoring#/elasticsearch/nodes/redactedNodeId?_g=(cluster_uuid:redactedClusterId))",
  "actionPlain": "Verify disk usage level of node."
}

```

The `context.node` should be split in two fields, `context.node` with the node name and `context.diskUsage` with the disk percent used.

I will open an issue in github.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 2, 2023, 3:19pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012/3 "2023-06-02T15:19:03Z")

</div>

Opened this [issue](https://github.com/elastic/kibana/issues/158850) on Github.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2023, 3:19pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012/4 "2023-06-30T15:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
