# Email alerts syntax issue

**URL:** <https://discuss.elastic.co/t/email-alerts-syntax-issue/366610>\
**Category:** Elastic Security\
**Created:** [September 16, 2024, 7:40am UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610 "2024-09-16T07:40:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aman\_kumar4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aman_kumar4/32/137605_2.png) [@aman\_kumar4](https://discuss.elastic.co/u/aman_kumar4)\
**Post date:** [September 16, 2024, 7:40am UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610/1 "2024-09-16T07:40:41Z")

</div>

I have created a security alert by defining the proper rules ( i am using custom query in defination where I have written the query as "username: missing\_name"  
uploaded a csv in which there is a column "username" if the missing\_name is encountered then we have to send the email alerts along with the address of corresponding to the missing\_name there is column with "address" I have connected the email connector , the alerts are generated and triggered also but the address and other dynamic part is missing in the email,  
I am using the below syntax to send the email, how to fix it??

```auto
Hello Team,
 
An alert has been triggered for missing name in the security logs. Below are the details of the detected issue:
 
**Alert Details:**
- **Rule Name** : {{rule.name}}
- **Date Triggered** : {{date}}
- **Alert Count** : {{alerts.new.count}}
{{#alerts.new.data}}

**Detected address** : {{context.address}}  

```

---

<div class="post-metadata">

**Author:** ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)\
**Post date:** [September 16, 2024, 8:27am UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610/2 "2024-09-16T08:27:08Z")

</div>

Hi @aman_kumar4, Welcome to Elastic community,

As I tested, It worked for me -

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/94242efb78f5f0c9ea13669aac395a9fe7a081a5.png)

Email I received -

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/bafcae73de0ffc206af2578b058cb28bb699e235.png)

Could you please tell me which data view you are using?

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [September 16, 2024, 9:21am UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610/3 "2024-09-16T09:21:54Z")

</div>

Hey @aman_kumar4, welcome to our community!

Looks like moustache syntax used in email body is not correct.

I can see there variable `{{#alert.new.data}}`, Symbol `#` is used when looping through array required and it needs a closing statement: `{{/alert.new.data}}`, as per [Rule action variables | Kibana Guide [8.15] | Elastic](https://www.elastic.co/guide/en/kibana/current/rule-action-variables.html#defining-rules-actions-variable-context)

So, if you would like to loop through new alerts, this syntax should be used

```auto
{{#alerts.new.data}}{{.}}{{/alerts.new.data}

```

Or, simply

```auto
{{alerts.new.data}}

```

---

<div class="post-metadata">

**Author:** ![WinterKnight](https://avatars.discourse-cdn.com/v4/letter/w/50afbb/32.png) [@WinterKnight](https://discuss.elastic.co/u/WinterKnight)\
**Post date:** [September 16, 2024, 2:16pm UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610/4 "2024-09-16T14:16:50Z")

</div>

For us, we wrap the dynamic entries between {{#context.alerts}} and {{/context.alerts}}. So your code would look like...

{{#context.alerts}}  
**Alert Details:**

- **Rule Name** : {{rule.name}}
- **Date Triggered** : {{date}}
- **Alert Count** : {{alerts.new.count}}  
{{#alerts.new.data}}

**Detected address** : {{context.address}}

R -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- R

{{/context.alerts}}

Because it's possible for more than one alert hit to appear in each email, we include a couple of carrige returns along with the R----R to differentiate between the different alerts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2024, 2:17pm UTC](https://discuss.elastic.co/t/email-alerts-syntax-issue/366610/5 "2024-10-14T14:17:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
