Elastic Detection Actions - any way to add fields?

We are creating numerous threshold detections for a specific client. This client is asking the threshold detections to email them when the alert is triggered, but they are asking us to include details about the original event(s) that do not currently show up in {{context.alerts}} (or obviously the signals index).

Is there a way to force a detection to include specific fields - fields that it does not include by default -- when alerting? The client wants specific event details for each of the threshold rule's associated events.

1 Like

No, there currently is not a method to do this except for using the field in the threshold determination.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.