# Watcher email body message to send some parameters in anomaly explorer

**URL:** <https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-machine-learning\
**Created:** [December 27, 2019, 12:42am UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114 "2019-12-27T00:42:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [December 27, 2019, 12:42am UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/1 "2019-12-27T00:42:23Z")

</div>

Hi Team,  
i need to send email to the customer any anomaly reaches 75% above critical.  
in email body included parameters like ("job id, actual,typical values and probability ,anomaly score , influencers ")shown in image marked as highligher with respective values. how to fetch those values in email body message in watcher alert creation .

please help me .

 ![sample](https://us1.discourse-cdn.com/elastic/original/3X/7/4/745b72efeeeba94cdedda2daf430a142156728e0.jpeg)

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [December 28, 2019, 3:24am UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/2 "2019-12-28T03:24:20Z")

</div>

In meassge body include the anomaly values and parameters like “job id ,job name,time,url,actual& typical values , influencer values” and sent to the customer.  
How the anomaly explorer shows the details in screen shot highligted in yellow same structure we need in the alert email message body .

Could you please help us.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 30, 2019, 4:14pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/3 "2019-12-30T16:14:32Z")

</div>

Here is an example you could use as a model for what you want to do:

> <https://gist.github.com/richcollier/1c2b8161286bdca6c553859f28d3d66d>

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [January 2, 2020, 3:07pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/4 "2020-01-02T15:07:51Z")

</div>

how to get specific actual & typical values shown in screenshot get into message body .. how to declare or specify in html or any {ctx.payload. aggregations .actual.values .count } type update me .

thanks in advance

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 2, 2020, 3:43pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/5 "2020-01-02T15:43:58Z")

</div>

The example I posted shows you one way of doing it - using a `transform` block to extract the `actual` and `typical` out of the `ctx.payload.hits.hits` array and storing them as a new data structure called `ctx.payload._value` - which is then accessed via mustache syntax in the `logging` section.

Was that not clear?

---

<div class="post-metadata">

**Author:** ![vishnuvardhan](https://avatars.discourse-cdn.com/v4/letter/v/50afbb/32.png) [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Post date:** [January 2, 2020, 4:12pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/6 "2020-01-02T16:12:15Z")

</div>

i need to do the specific single job anomalies have above 75% to send the Email (include message body the parameters job id, time, actual,typical value,probability score values ).but automatic email alert i get the anomaly score ,buckets score ,link ,job id ,time .

so , i need to get actual,typical value,probability score values using any method . i mention in my email message body.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 2, 2020, 5:50pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/7 "2020-01-02T17:50:13Z")

</div>

Again - look at the example I provided here: [https://gist.github.com/richcollier/1c2b8161286bdca6c553859f28d3d66d](https://gist.github.com/richcollier/1c2b8161286bdca6c553859f28d3d66d)

You can see exactly where I grab the `actual` and `typical`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a77419f4e4c47984058a02c637a24c458d37ea99.png)

and then reference it later in the logging section (or in your case the email section) so that the output looks like:

```auto
Anomalies:
==========
time=2017-02-09T16:00:00.000Z 
airline=AAL 
score=99 (out of 100) 
responsetime=242ms (typical=100ms)
link= http://localhost:5601/...
...

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2020, 5:50pm UTC](https://discuss.elastic.co/t/watcher-email-body-message-to-send-some-parameters-in-anomaly-explorer/213114/8 "2020-01-30T17:50:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
