# Adding instance context to alerts for Teams Connector

**URL:** <https://discuss.elastic.co/t/adding-instance-context-to-alerts-for-teams-connector/380900>\
**Category:** Kibana\
**Created:** [August 8, 2025, 10:23am UTC](https://discuss.elastic.co/t/adding-instance-context-to-alerts-for-teams-connector/380900 "2025-08-08T10:23:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chickpea](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chickpea](https://discuss.elastic.co/u/Chickpea)\
**Post date:** [August 8, 2025, 10:23am UTC](https://discuss.elastic.co/t/adding-instance-context-to-alerts-for-teams-connector/380900/1 "2025-08-08T10:23:25Z")

</div>

Hello,

I manage multiple isolated Elastic instances, on each I configured a Teams connector.  
Now by default alerts in our Teams channel are pretty generic, for instance “Rule Spike in Logon Events from a Source IP generated 1 alerts”. They completely miss instance context by default.  
What would be best practice or a good approach to enrich alerts with context.  
I was thinking about just adding customer/instance tag to the rule name, i.e. “Rule Spike Logon [instance\_xy]” manually. But I think this might not be possible for rules managed by Elastic.

What would be the best option in my situation?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 8, 2025, 12:57pm UTC](https://discuss.elastic.co/t/adding-instance-context-to-alerts-for-teams-connector/380900/2 "2025-08-08T12:57:23Z")

</div>

Hello @Chickpea

Welcome to the Community!!

I am not sure if it is needed to edit the current Rule name by adding static instance id, if we check as part of {{context}} it captures the clusterName, can we try adding {{context.clusterName}} to the existing message. Also if needed Tag field can be also used to add the instance name & calling by {{rule.tags}}

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec0e0ffb189293b5e3dfb1676beae13933ed24c6.png)

Thanks!!

---

<div class="post-metadata">

**Author:** ![Chickpea](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chickpea](https://discuss.elastic.co/u/Chickpea)\
**Post date:** [September 9, 2025, 1:46pm UTC](https://discuss.elastic.co/t/adding-instance-context-to-alerts-for-teams-connector/380900/3 "2025-09-09T13:46:21Z")

</div>

Thank you. In general a good approach that I would use. But it seems that security rules cannot access the Cluster Name since I don’t get any output when I put {{context.clusterName}} in my alert message.

However, I used {{{context.results\_link}}} instead which provides a link to the alert which is also useful.
