# Escape dot in mustache to access elastic query \_source field in alerts

**URL:** <https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [December 23, 2022, 12:32pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912 "2022-12-23T12:32:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nabeel\_Ahmed\_NAK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nabeel_ahmed_nak/32/133673_2.png) [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Post date:** [December 23, 2022, 12:32pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/1 "2022-12-23T12:32:21Z")

</div>

Hi All  
I have enabled elastic defend and enabled rules to detect security events.  
Now I want to generate alerts from the Kibana rule and connector to slack.  
I have encountered that Elasticsearch mapping of kibana rule fields are not in that form which I can access it in mustache to generate body of alerts.  
for example:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34209a7f5865c2435bb900c88dda2700e0360773.png)

here you can see that field name are in this form kibana.alert.rule.name where as it has to be in json object like  
kibana :{  
alert : {  
.............  
}  
}  
now the dot **.** containing fields name are not able access in mustache due to especial character.  
I want to now how can I access those fields?  
Thanks

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [December 23, 2022, 1:27pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/2 "2022-12-23T13:27:11Z")

</div>

Hey,

Rule name can be used as {{rule.name}}. You'll see all available variables that can be accessed by selecting the add variable button ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc4518996ac49e9b1da28a05da20ab3aa23dbf15.png) just above the textarea in the message field

---

<div class="post-metadata">

**Author:** ![Nabeel\_Ahmed\_NAK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nabeel_ahmed_nak/32/133673_2.png) [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Post date:** [December 23, 2022, 3:36pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/3 "2022-12-23T15:36:28Z")

</div>

> [@jcger](#):
>
> t above the textarea in the message field

Hi  
Rule name are not usable for me because I'm not gonna manage alerts for particular thread level.  
I want to create general alert using Elasticsearch query and wants to access like this  
{{#context.hits}}  
Time: {{\_source.@timestamp}}  
Rule Name: {{\_source.kibana.alert.rule.name}}  
Destination IP and Port: {{\_source.destination.ip}} : {{\_source.destination.port}}  
Destination Country: {{\_source.destination.geo.country\_name}}  
Source IP and Port: {{\_source.source.ip}} : {{\_source.source.port}}  
Source Country: {{\_source.source.geo.country\_name}}  
Event Provider: {{\_source.event.provider}}  
Event Action: {{context.event.action}}  
{{/context.hits}}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c154102981e7a4ebb8c78b5064e6f000700893f.png)

as I have mentioned before kibana.alert.rule.name is not parse by elasticsearch itself and not able to fetch its information in mustache. So, is there any way to fix it.

---

<div class="post-metadata">

**Author:** ![Nabeel\_Ahmed\_NAK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nabeel_ahmed_nak/32/133673_2.png) [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Post date:** [December 27, 2022, 7:21am UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/4 "2022-12-27T07:21:39Z")

</div>

@jcger

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [December 27, 2022, 11:32am UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/5 "2022-12-27T11:32:16Z")

</div>

Hi @Nabeel_Ahmed_NAK ,

Sorry for the delay.

I'm gonna forward your question. In the meantime, have you tried with the fields response as mentioned here ?

> As the [`fields`](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/search-fields.html#search-fields-response) response always returns an array of values for each field, the [Mustache](https://mustache.github.io/) template array syntax is used to iterate over these values in your actions as the following example shows:
> 
> {{#context.hits}} Labels: {{#fields.labels}} - {{.}} {{/fields.labels}} {{/context.hits}}

---

<div class="post-metadata">

**Author:** ![Nabeel\_Ahmed\_NAK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nabeel_ahmed_nak/32/133673_2.png) [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Post date:** [December 27, 2022, 12:18pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/6 "2022-12-27T12:18:32Z")

</div>

> [@jcger](#):
>
> m gonna forward your question

Yeah I did it rule.name will fetch the title name of alert which is hardcoded means I define it when I do create alert well In my case it's generic and I need to access more fields it was just an example.  
Thanks

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [December 27, 2022, 1:58pm UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/7 "2022-12-27T13:58:30Z")

</div>

There is a problem today with accessing mustache fields that have the "`.`" character in them. We've added some code to make those accessible, which should be available in version 8.6.0, added in this PR [[ResponseOps][Actions] support mustache context variables with periods in the name by doakalexi · Pull Request #143703 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/143703)

If you happen to be using 8.5.0, and this is the Elasticsearch Query rule type, there's a work-around using runtime fields, but it will require some work - basic idea is outlined here: [[responseOps] support mustache context variables with periods in the name · Issue #127748 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/127748#issuecomment-1223775425) . That's the only work-around I'm aware of until the real fix in 8.6.0.

---

<div class="post-metadata">

**Author:** ![Nabeel\_Ahmed\_NAK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nabeel_ahmed_nak/32/133673_2.png) [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Post date:** [December 29, 2022, 9:03am UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/8 "2022-12-29T09:03:35Z")

</div>

@Patrick_Mueller  
Thanks for your help now I'm using runtime fields and hopefully latest version will update this fix.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2023, 9:04am UTC](https://discuss.elastic.co/t/escape-dot-in-mustache-to-access-elastic-query-source-field-in-alerts/321912/9 "2023-01-26T09:04:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
