# The context.thresholdOf, context.metricOf and context.valueOf not working in inventory alert

**URL:** <https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [September 27, 2020, 4:17pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094 "2020-09-27T16:17:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohanr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanr/32/73317_2.png) [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Post date:** [September 27, 2020, 4:17pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/1 "2020-09-27T16:17:44Z")

</div>

Hi,

I am using the ELK 7.8.0 and making an inventory alert. I have created an action message as shown below.

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f3630b91d46aa4f97d546a0e5d19502aa80a41c.png)

But I am not getting values for **context.thresholdOf** , **context.metricOf** and **context.valueOf**. I have also tried **context.reason** as well but not worked. When I checked the alert index I found the following.

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/402e04de321b0246226799170adf15d145b7def6.png)

I want to get the current values for CPU and RAM utilization. Please help, if I am making any mistake or anything else.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 27, 2020, 8:11pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/2 "2020-09-27T20:11:23Z")

</div>

Hi @mohanr

FIrst what kind of alert did you create? Did you create it from the Metrics App it should be of type Metric Threshold.

Here is my config on 7.8.1

 ![Screen Shot 2020-09-27 at 12.20.50 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/2/02026fb4a1e4a577c76c6094890627d80ac3f017.png)

 ![Screen Shot 2020-09-27 at 12.20.59 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/4/64026123b822e4face45533d9902b29647bf03a9.png)

Here is my action message complete with a little cool URL to open detailed metrics on host that created the alert (BTW, in future please paste the txt version of your config / results much easier for others to help with)

```
{
  "message": "On host : {{context.group}} {{context.metricOf.condition0}} has crossed a threshold of {{context.thresholdOf.condition0}}, Current value is {{context.valueOf.condition0}}",
  "alertId": "{{alertId}}",
  "alertName": "{{alertName}}",
  "notifygroup": "{{tags}}",
  "target": "{{context.group}}",
  "metric": "{{context.metricOf.condition0}}",
  "current_value": "{{context.valueOf.condition0}}",
  "threshold": "{{context.thresholdOf.condition0}}",
  "severity": "Warning",
  "eventsource": "elasticsearch",
  "url" : http://localhost:5601/app/metrics/detail/host/{{context.group}}?metricTime=(autoReload:!f,refreshInterval:5000,time:(from:now-1h,to:now))" 
}

```

You will notice the `condition0` on the end that is because the alert creates and object since these alerts are created per host. They documentation does not really explain that, apologies... but if / when you do a new action you will see the `condition0` but it does not show in the context menu

```
{{alertName}} - {{context.group}}

{{context.metricOf.condition0}} has crossed a threshold of {{context.thresholdOf.condition0}}
Current value is {{context.valueOf.condition0}}

```

And my results

```
{
 "message": "On host : ceres-2.local cpu has crossed a threshold of 5, Current value is 10.5%",
 "alertId": "dec67da3-6d9b-4c56-997b-13bc925aef79",
 "alertName": "test-cpu-alert",
 "notifygroup": "",
 "target": "ceres-2.local",
 "metric": "cpu",
 "current_value": "10.5%",
 "threshold": "5",
 "severity": "Warning",
 "eventsource": "elasticsearch",
 "url" : http://localhost:5601/app/metrics/detail/host/ceres-2.local?metricTime=(autoReload:!f,refreshInterval:5000,time:(from:now-1h,to:now))"
}

```

Hope that helps, plus you got and extra URL goodie 🙂

Finally if you could I would get to 7.9.2 there was a lot of additional Alerting capability released especially in the metrics area, where you can test your alert, see the current values vs threshold, automatically get alerted if the metrics stop, but be carefull some of the meta data / context names have changed a little

 ![Screen Shot 2020-09-27 at 1.07.14 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/3/232be857af3c9df957b2a4e9b639c9810bd242a9.png)

Here is my alerts for 7.9.2 some slight differences

```
   {
      "message": "On host {{context.group}}, {{context.reason}}",
      "alertId": "{{alertId}}",
      "alertName": "{{alertName}}",
      "notifygroup": "{{tags}}",
      "target": "{{context.group}}",
      "metric": "{{context.metric.condition0}}",
      "current_value": "{{context.value.condition0}}",
      "threshold": "{{context.threshold.condition0}}",
      "severity": "Warning",
      "eventsource": "elasticsearch",
      "url" : http://localhost:5601/app/metrics/detail/host/{{context.group}}?metricTime=(autoReload:!f,refreshInterval:5000,time:(from:now-1h,to:now))" 
    }
```

---

<div class="post-metadata">

**Author:** ![mohanr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohanr/32/73317_2.png) [@mohanr](https://discuss.elastic.co/u/mohanr)\
**Post date:** [September 28, 2020, 6:11am UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/3 "2020-09-28T06:11:43Z")

</div>

@stephenb Thanks for your reply. It really helps me and works perfectly. I am using the EKL 7.8.0 and facing another issue. I have a centralized log system having multiple application instances. Multiple Docker containers are running on a particular instance.  
I am creating an alert for container resource utilization like CPU, RAM, etc.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c06cd7f332fbd9c8874379033e46b7a24e085dc5.png)  
It gives me information about the container like name, threshold value, and current value but not able to get the information about the instance (server).  
I want to get alert information like which container has how much resource utilization for a particular instance. I have a custom field **instance** in the Metricbeat index.  
Is there a way to use this custom field or anything else?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 28, 2020, 3:17pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/4 "2020-09-28T15:17:14Z")

</div>

Looks like some of the features I was looking at in 7.9.2 are also in 7.8.1

Perhaps, You could try this.

Go To Alert and Actions and create a Metric Threshold alert this is the more General version of the Inventory Alert.

 ![Screen Shot 2020-09-28 at 8.13.33 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/2/7276910d792bb6a797a1e4c7edf4b973714ad5d1.png)

Then you could try Create Alert Per and put your `Instance` field in that. It will need to be a Keyword Type

 ![Screen Shot 2020-09-28 at 8.10.17 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e6faec0fcda6a290ce75cc8398b18f527791cbc.png)

That should generate alerts by Instance and then that instance should be part of the alert context.

---

<div class="post-metadata">

**Author:** ![igorid70](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igorid70/32/45136_2.png) [@igorid70](https://discuss.elastic.co/u/igorid70)\
**Post date:** [October 3, 2020, 3:57pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/5 "2020-10-03T15:57:01Z")

</div>

I have 2 'per' fields in alert for file systems usage in multi-host environment (I use v7.9.1) , so I must create alerts per host (host.name) and per file system (system.filesystem.mount\_point)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/9/89beac7345ed270da7d09906ddeb472e4b7e6823.png)

How I can get a separated value for each one of them?  
In Kibana log I have them concatenated (in the example below, 'AlertGroup' field contains both host name and file system name with a comma in between). Of course I can split, but it still would be nice to have each field separately without any extra manipulations).

e.g. /usr file system is alerted like this:  
AlertName:Disk Space Alert;AlertGroup:my-host1-name, /usr;AlertTimestamp:2020-10-03T15:29:00.000Z;

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 3, 2020, 5:44pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/6 "2020-10-03T17:44:25Z")

</div>

Interesting I tested this myself as well, the context group is presented as you see it... it does not look like separate fields are supported, seems like a good idea perhaps you can submit an Feature Request [here](https://github.com/elastic/kibana/issues/new/choose)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2020, 5:44pm UTC](https://discuss.elastic.co/t/the-context-thresholdof-context-metricof-and-context-valueof-not-working-in-inventory-alert/250094/7 "2020-10-31T17:44:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
