# Alert mail siem format question

**URL:** <https://discuss.elastic.co/t/alert-mail-siem-format-question/271849>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting\
**Created:** [May 1, 2021, 4:53am UTC](https://discuss.elastic.co/t/alert-mail-siem-format-question/271849 "2021-05-01T04:53:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [May 1, 2021, 4:53am UTC](https://discuss.elastic.co/t/alert-mail-siem-format-question/271849/1 "2021-05-01T04:53:26Z")

</div>

Hi all i have a question regarding elastic alert mail in siem.  
last time i get the test mail send was successfully parse the field to the mail.  
but this time i want to know that if the data that i have is not like json type of field would it work.  
ex: normally the data dns.question.name would be like this

```auto
 question: {
    name: something
  }
}

```

but mine due to some problems appear like this:

```auto
dns.question.name: something

```

and now the mail that it send no longer parse the dns field for me anymore  
since {{dns.question.name}} doesnot work any more.  
So is there a syntax to send the mail with field that look like json type but not.

Thanks for your time.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 6, 2021, 1:15am UTC](https://discuss.elastic.co/t/alert-mail-siem-format-question/271849/2 "2021-05-06T01:15:50Z")

</div>

Hey there @lusynda! 👋

I'm not sure I completely follow, but sounds like you're just trying to deal with a field mis-match and need to determine what the right syntax is for accessing the desired field.

For this sorta thing I recommend setting up an action with the below message ([docs](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#placeholder-examples)):

```auto
{{#context.alerts}} {{.}} {{/context.alerts}}

```

This will print _every field in the alert_, and you can then determine which key matches the field.

Alternatively of course, you can just look at the `Alert Details` for an alert from that rule and determine the exact `key` you should be referencing. E.g.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50312accdca3dfcbddd59549387342c041f3fe9a.png)

As above, please check out the [docs](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#placeholder-examples) for all the right syntax in looping over the alert fields, as you may just have something incorrect there.

Hope that helps -- and let us know if you have any more details to add from the above!

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 1:16am UTC](https://discuss.elastic.co/t/alert-mail-siem-format-question/271849/3 "2021-06-03T01:16:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
