# Watcher: Generating URLs to link back to Watch History

**URL:** <https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228>\
**Category:** Elasticsearch\
**Created:** [July 7, 2017, 8:16am UTC](https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228 "2017-07-07T08:16:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndyBCDL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andybcdl/32/19897_2.png) [@AndyBCDL](https://discuss.elastic.co/u/AndyBCDL)\
**Post date:** [July 7, 2017, 8:16am UTC](https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228/1 "2017-07-07T08:16:54Z")

</div>

Hi folks, we've just upgraded to Elastic 5 over Dev, UAT and Live. I'm just looking at Watcher for the first time.

I've configured a simple query to look for HTTP 503 errors in our HAproxy access logs and report to our slack channel if there are more than 25 errors over a 5 minute period. Here is the JSON

> {  
> "trigger": {  
> "schedule": {  
> "interval": "5m"  
> }  
> },  
> "input": {  
> "search": {  
> "request": {  
> "search\_type": "query\_then\_fetch",  
> "indices": [  
> "logstash-haproxy\_access-\*"  
> ],  
> "types": ,  
> "body": {  
> "query": {  
> "bool": {  
> "must": {  
> "match": {  
> "http\_status\_code": 503  
> }  
> },  
> "filter": {  
> "range": {  
> "@timestamp": {  
> "from": "{{ctx.trigger.scheduled\_time}}||-5m",  
> "to": "{{ctx.trigger.triggered\_time}}"  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> },  
> "condition": {  
> "compare": {  
> "ctx.payload.hits.total": {  
> "gte": 25  
> }  
> }  
> },  
> "actions": {  
> "notify-slack": {  
> "throttle\_period\_in\_millis": 300000,  
> "slack": {  
> "account": "REMOVEDCHANNELNAME",  
> "message": {  
> "from": "kibana-dev",  
> "to": [  
> "#kibana-dev"  
> ],  
> "attachments": [  
> {  
> "color": "danger",  
> "title": "HAPROXY 503 ERRORS",  
> "text": "Encountered {{ctx.payload.hits.total}} HTTP 503 errors in the last 5 minutes"  
> }  
> ]  
> }  
> }  
> }  
> }  
> }

And what you see in slack

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/0/804dcd6c4c9d493fbce96b9ddca807c02603d4cd.png)

So far, so good.

However, what i'd like to do is to add a URL to the slack message which links back to the Watch History or a Watcher index so someone can clickthrough and investigate the messages, then mark the slack message as seen / green tick to indicate its been investigated.

I am not sure where to start. Any ideas?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 7, 2017, 3:46pm UTC](https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228/2 "2017-07-07T15:46:50Z")

</div>

Hey,

would linking to the watcher UI work for you? sth like

```auto
http://localhost:5601/app/kibana#/management/elasticsearch/watcher/watches/watch/YOUR_WATCH_ID/status?_g=()

```

will show you directly the latest history entries of that particular watch.

--Alex

---

<div class="post-metadata">

**Author:** ![AndyBCDL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andybcdl/32/19897_2.png) [@AndyBCDL](https://discuss.elastic.co/u/AndyBCDL)\
**Post date:** [July 10, 2017, 9:35am UTC](https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228/3 "2017-07-10T09:35:15Z")

</div>

Its a good starter for 10 for sure, but as time goes one we'd probably want to be able to specifically grab the information that caused the alert.

I had a few ideas over the weekend but not sure how feasible they are;

1. Putting the alert into an index and then linking to that index
2. Creating a discover URL with the same timescale and query value used in watcher

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2017, 9:40am UTC](https://discuss.elastic.co/t/watcher-generating-urls-to-link-back-to-watch-history/92228/4 "2017-08-07T09:40:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
