# Adding a custom field in alerts

**URL:** <https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216>\
**Category:** Kibana\
**Tags:** detection-rules\
**Created:** [September 9, 2024, 3:51am UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216 "2024-09-09T03:51:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mangeshmj1992](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Post date:** [September 9, 2024, 3:51am UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216/1 "2024-09-09T03:51:56Z")

</div>

Hello team,  
I am trying to create new rule in kibana for cpu utilization is more than 80 %. I am monitoring 3 host in my community version of Kibana.

When it meet threshold criteare i am creating index and data is getting ingested into new index and in alert index with default fields only like rule.name, alert.uuid, .

I need to add custom fields like host.name and and host.ip

Can you please help me to achieve this?

---

<div class="post-metadata">

**Author:** ![Fiza](https://avatars.discourse-cdn.com/v4/letter/f/c4cdca/32.png) [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Post date:** [September 11, 2024, 1:54pm UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216/2 "2024-09-11T13:54:53Z")

</div>

Hi @mangeshmj1992,

If I am not wrong, from the scenario you mentioned, you would be using Inventory Threshold or Metric Threshold rule. As per my knowledge for these rules, we don't have option to directly add fields from indices .

The other way around is to use "Group alerts by (optional)". This option is present for metric threshold rule. Here in your scenario you can use host.ip.  
The alerts will come specifically for each ip and you can use "context.group" or "alert.id" to get the value.

Thanks,  
Fiza
