I am creating elasticsearch query type alerts in Kibana Alerts and Action section. I have put a condition to send an alert when blacklist IP met with threshold condition in my query.
Alerts are generated in index with predefined variables only. Is it possible to add some additional fields in notification message from index on which query is applied ? for eg: I am using destination.ip in my query as a blacklist ip and I want to add destination.ip field in notification message. My document to index in alert is below:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.