Including the query in an alert notification

I’ve got some alerts going to a Slack channel and am looking to enhance them a bit more. I’ve got links to individual errors (the links go to that specific error in Kibana on an EFK instance). However, I’d like to add a link to the time-boxed query itself. That is…a link to the query that resulted in the alert triggering that particular time. There are lots of usable goodies in the alert ctx structure, but I haven’t found anything yet that looks like a variable with the query itself in it. Has anyone gone down this path? Any pointers I could follow?

I too am looking for the same. One option that I am using as a workaround is to insert the URL of the dashboard in the alert message.

Yes, I’ve done something similar. It’s a bit of a Franken-URL, which does resolve correctly. However, the trick is that the query portion of the link URL has to be manually updated if we tweak the query that forms the basis of the alert. Some way of exposing the query terms (or the query in all its glory, actually) via the ctx variables would be fantastic. I believe that I saw a similar request in the project’s GitHub Issues, but I’m not sure of the status (haven’t revisited the Issues lately). Hopefully something can come of the discussion, as it would be wonderful feature. :slight_smile: