# Add winlogbeat Info to Email Action

**URL:** <https://discuss.elastic.co/t/add-winlogbeat-info-to-email-action/249523>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting\
**Created:** [September 22, 2020, 1:08pm UTC](https://discuss.elastic.co/t/add-winlogbeat-info-to-email-action/249523 "2020-09-22T13:08:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nyhmesis](https://avatars.discourse-cdn.com/v4/letter/n/6f9a4e/32.png) [@Nyhmesis](https://discuss.elastic.co/u/Nyhmesis)\
**Post date:** [September 22, 2020, 1:08pm UTC](https://discuss.elastic.co/t/add-winlogbeat-info-to-email-action/249523/1 "2020-09-22T13:08:49Z")

</div>

Hello all!

I'm very new to the Elastic stack so I'll try to not sound completely dumb.

Under Security -\> Detections, I have modified the existing detection rule that detects when the process whoami.exe is ran and added an action to send me an email. The problem is that when I try to use the Mustache language to reference some of the winlogbeat info inside the detection, I am unable to do so.

For instance, in the detection, it clearly outlines agent.hostname and user.name but when I try to add those to the body of the email using {{agent.hostname}} and {{user.name}} it does not work. What am I doing wrong? When I click the + to add alert variables, there's a bunch of pre-defined {{context.rule.XXXXX}} but none of that info is helpful about the alert.

I've done hours worth of searching online and on the forum but was unable to find an answer. Please help, thanks!

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [September 25, 2020, 2:06pm UTC](https://discuss.elastic.co/t/add-winlogbeat-info-to-email-action/249523/2 "2020-09-25T14:06:42Z")

</div>

Hi @Nyhmesis, thanks for trying things out. The variables are limited at the moment but you can follow any number of tickets we have for expanding them for alerting:

> <https://github.com/elastic/kibana/issues/68438>
>
> Problem
> When creating a rule action, users are provided with a list of variables that they can use to reference alert-specific data:
> For...

  

> <https://github.com/elastic/kibana/issues/69611>
>
> Describe the feature:
> When using Alerting from Kibana within Elasticsearch 7.7, it would be brilliant if it was possible to pull specific...

  

> <https://github.com/elastic/kibana/issues/66587>
>
> Describe the feature:
> As a security analyst often use my mobile device to keep an eye on high priority and critical alerts...

And then when you see it solved, you will know which release it will be in and then upgrade to get the feature when it is released.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2020, 2:06pm UTC](https://discuss.elastic.co/t/add-winlogbeat-info-to-email-action/249523/3 "2020-10-23T14:06:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
