# Attribute detection to original doc

**URL:** <https://discuss.elastic.co/t/attribute-detection-to-original-doc/261010>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [January 13, 2021, 2:35pm UTC](https://discuss.elastic.co/t/attribute-detection-to-original-doc/261010 "2021-01-13T14:35:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samsquantch](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@Samsquantch](https://discuss.elastic.co/u/Samsquantch)\
**Post date:** [January 13, 2021, 2:35pm UTC](https://discuss.elastic.co/t/attribute-detection-to-original-doc/261010/1 "2021-01-13T14:35:56Z")

</div>

Is there a way to include the original \_id of the doc that triggered an alert in the metadata of a detection? When working IR, we would like to efficiently trace an alert to an event.

I can create a filter based off of several attributes of the detection (host, imphash, timestamp, etc) and eventually narrow it down to a single event but in an effort to orchestrate IR, it would make more sense to search for the originating \_id of the doc.

Am I missing something or do we need to approach this differently?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 18, 2021, 6:51pm UTC](https://discuss.elastic.co/t/attribute-detection-to-original-doc/261010/2 "2021-01-18T18:51:53Z")

</div>

Hi @Samsquantch, you should have that information available to you in the detection underneath:

```auto
signal.parent

```

and

```auto
signal.ancestors

```

 ![Screen Shot 2021-01-18 at 11.49.01 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/4/44d32ce62713ec2d58b02144facf265c08cc79c1.png) ![Screen Shot 2021-01-18 at 11.49.16 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/8/4815a73a0133326b50ca8ffa5c59af38945201a7.png)

They have information back to the parent/original \_id of the doc and index information. One important item of note is that not all detections are going to have this fidelity. For example thresholds will not have it and machine learning does not have it. If we can trace it back then we will trace it back in those areas, however.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:21am UTC](https://discuss.elastic.co/t/attribute-detection-to-original-doc/261010/3 "2022-11-04T08:21:33Z")

</div>


