# Elastic Security field values in connector getting duplicated

**URL:** <https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting\
**Created:** [September 6, 2022, 3:01am UTC](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725 "2022-09-06T03:01:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RaonyO](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Post date:** [September 6, 2022, 3:01am UTC](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725/1 "2022-09-06T03:01:08Z")

</div>

hello everyone, I'm trying to create a rule in elastic security via query in a specific index, and the rule detects it normally, but in the action part the events are going with duplicate fields. for example:

```auto
"result": "QuarantinedQuarantined"
"deviceAction": "QuarantineQuarantine"
"deviceHostName": "ubcloud123ubcloud123"
"severity": "66"

```

and here is the body of my alert action(via webhook):

```auto
{
"filePath":"{{#context.alerts}}{{filePath}}{{/context.alerts}}",
"severity":"{{#context.alerts}}{{severity}}{{/context.alerts}}",
"TrendMicroFileSHA1":"{{#context.alerts}}{{TrendMicroFileSHA1}}{{/context.alerts}}",
"result":"{{#context.alerts}}{{result}}{{/context.alerts}}",
"id": "{{#context.alerts}}{{_id}}{{/context.alerts}}",
"deviceAction":"{{#context.alerts}}{{deviceAction}}{{/context.alerts}}",
"deviceHostName":"{{#context.alerts}}{{deviceHostName}}{{/context.alerts}}",
"name":"{{#context.alerts}}{{name}}{{/context.alerts}}"
}

```

Does anyone know how to tell me why the content of the fields are sent duplicates?

---

<div class="post-metadata">

**Author:** ![Pedro\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pedro_jaramillo/32/45904_2.png) [@Pedro\_Jaramillo](https://discuss.elastic.co/u/Pedro_Jaramillo)\
**Post date:** [September 7, 2022, 7:12pm UTC](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725/2 "2022-09-07T19:12:49Z")

</div>

Hi @RaonyO, the current behavior of rule actions is that the triggered action will have the context of all the alerts generated during the "action frequency" timeframe (i.e. on each rule execution, hourly, etc). If, for example, you selected "on each rule execution" for action frequency and the rule executes and generates 10 alerts in that rule execution, then the rule action will have 10 alerts in the context. This means that the mustache `{{#context.alerts}}{{result}}{{/context.alerts}}` will output `result` 10 times.

My guess is that you are seeing "duplicate" values in the example above because your rule generated 2 alerts during the "action frequency" timeframe. This resulted in mustache outputting 2 values for `result`, `deviceAction`, and `deviceHostname`. Let us know if this helps explain the behavior.

---

<div class="post-metadata">

**Author:** ![RaonyO](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Post date:** [September 9, 2022, 12:30am UTC](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725/3 "2022-09-09T00:30:38Z")

</div>

yes, that's right you were right! I used {{context.alerts.0.result}}, {{context.alerts.0.deviceHostname}} and it didn't send a duplicate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2022, 12:31am UTC](https://discuss.elastic.co/t/elastic-security-field-values-in-connector-getting-duplicated/313725/4 "2022-10-07T00:31:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
