# Action variables for a Logs threshold rule

**URL:** <https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [November 17, 2023, 9:53am UTC](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394 "2023-11-17T09:53:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arty](https://avatars.discourse-cdn.com/v4/letter/a/3ab097/32.png) [@Arty](https://discuss.elastic.co/u/Arty)\
**Post date:** [November 17, 2023, 9:53am UTC](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394/1 "2023-11-17T09:53:57Z")

</div>

Hi everyone,

I have set up a log threshold rule to retrieve incoming suricata alerts data and send them to another tool using a webhook action.

I tried accessing available variables using mustache such as `{{#context.alerts}}{{.}}{{/context.alerts}` or `{{#context}}{{.}}{{/context}}` but nothing shows or the variables are just rule related, I feel like I am very constrained in the variables I can use, exept from the one I can access though the scrolling menu when setting up my action body.  
Is there a way to get variables such as suricata.eve part (source ip address and stuff like that), as I would do using `{{context.hits}}` or `{{context.alerts}}` in other rule types ?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2023, 9:54am UTC](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394/2 "2023-12-15T09:54:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
