# Format SIEM alerts

**URL:** <https://discuss.elastic.co/t/format-siem-alerts/272772>\
**Category:** SIEM\
**Tags:** elastic-stack-alerting\
**Created:** [May 12, 2021, 7:21am UTC](https://discuss.elastic.co/t/format-siem-alerts/272772 "2021-05-12T07:21:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnug](https://avatars.discourse-cdn.com/v4/letter/v/34f0e0/32.png) [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Post date:** [May 12, 2021, 7:21am UTC](https://discuss.elastic.co/t/format-siem-alerts/272772/1 "2021-05-12T07:21:07Z")

</div>

Hi,

I'm using ELK v7.12.1. I have enabled few SIEM rules and configured an email action. I'm able to access the event details through `{{#context.alerts}} {{.}}{{/context.alerts}}`.

But when sending the mail the content is coming in one line. Is there any way to format the SIEM alert using HTML tags?

Thanks

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [May 12, 2021, 4:36pm UTC](https://discuss.elastic.co/t/format-siem-alerts/272772/2 "2021-05-12T16:36:53Z")

</div>

Hi @vishnug !

Thanks for your post. Have you taken a look at our documentation for email action [here](https://www.elastic.co/guide/en/kibana/7.12/email-action-type.html#email-action-type)? Markdown is supported in formatting the email message.

This [PR](https://github.com/elastic/kibana/pull/85488) description may also be helpful in understanding how to customize your action.

I hope this helps! Let us know if you need further assistance.

Best,  
Yara

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 6:46pm UTC](https://discuss.elastic.co/t/format-siem-alerts/272772/3 "2021-05-12T18:46:50Z")

</div>

So you platform that the alert is going to be rendered, you must know how it renders

So if you see the following example that I use for JIRA (it uses it own Markdown [Text Formatting Notation Help.](https://jira.atlassian.com/secure/WikiRendererHelpAction.jspa?section=all), so I had to add the JIRA Markup syntax around Elastic syntax

```auto
- *Number of Alerts*: {{state.signals_count}}
- *Risk score*: {{context.rule.risk_score}}
- *Severity*: {{context.rule.severity}}

 h2. Rule Details
 [View Detection Alert|{{{context.results_link}}}]
- *Rule Description*: {quote}{{context.rule.description}}{quote}
- *Rule Query*: {quote}{{context.rule.query}}{quote}

 h2. Source
 {{#context.alerts}}
- *Source IP Address*: {noformat}{{source.ip}}{noformat}
- *Source Port*: {noformat}{{source.port}}{noformat}
 {{/context.alerts}}

 h2. Destination
 {{#context.alerts}}
- *Destination IP Address*: {noformat}{{destination.ip}}{noformat}
- *Destination Port*: {noformat}{{destination.port}}{noformat}
 {{/context.alerts}}

 h3. Process
 {{#context.alerts}}
- *Hash MD5*: {noformat}{{process.hash.md5}}{noformat}
- *Hash SH1*: {noformat}{{process.hash.sha1}}{noformat}
- *Hash SHA25*: {noformat}{{process.hash.sha256}}{noformat}
- *Process Name*: {noformat}{{process.name}}{noformat}
- *Process Parent Executable*: {noformat}{{process.parent.executable}}{noformat}
- *Process Parent Name*: {noformat}{{process.parent.name}}{noformat}
 {{/context.alerts}}

 h3. File
 {{#context.alerts}}
- *File Name*: {noformat}{{file.name}}{noformat}
- *File Owner*: {noformat}{{file.owner}}{noformat}
- *File Path*: {noformat}{{file.path}}{noformat}
- *File size*: {noformat}{{file.size}}{noformat}
- *File Target Path*: {noformat}{{file.target_path}}{noformat}
- *File Type*: {noformat}{{file.type}}{noformat}
 {{/context.alerts}}

```

This is what it looks like if I use the Detection API to update my rules.

```auto
- *Number of Alerts*: {{state.signals_count}}\n- *Risk score*: {{context.rule.risk_score}}\n- *Severity*: {{context.rule.severity}}\n\n h2. Rule Details\n [View Detection Alert|{{{context.results_link}}}]\n- *Rule Description*: {quote}{{context.rule.description}}{quote}\n- *Rule Query*: {quote}{{context.rule.query}}{quote}\n\n h2. Source\n {{#context.alerts}}\n- *Source IP Address*: {noformat}{{source.ip}}{noformat}\n- *Source Port*: {noformat}{{source.port}}{noformat}\n {{/context.alerts}}\n\n h2. Destination\n {{#context.alerts}}\n- *Destination IP Address*: {noformat}{{destination.ip}}{noformat}\n- *Destination Port*: {noformat}{{destination.port}}{noformat}\n {{/context.alerts}}\n\n h3. Process\n {{#context.alerts}}\n- *Hash MD5*: {noformat}{{process.hash.md5}}{noformat}\n- *Hash SH1*: {noformat}{{process.hash.sha1}}{noformat}\n- *Hash SHA25*: {noformat}{{process.hash.sha256}}{noformat}\n- *Process Name*: {noformat}{{process.name}}{noformat}\n - *Process Parent Executable*: {noformat}{{process.parent.executable}}{noformat}\n- *Process Parent Name*: {noformat}{{process.parent.name}}{noformat}\n {{/context.alerts}}\n\n h3. File\n {{#context.alerts}}\n- *File Name*: {noformat}{{file.name}}{noformat}\n- *File Owner*: {noformat}{{file.owner}}{noformat}\n- *File Path*: {noformat}{{file.path}}{noformat}\n- *File size*: {noformat}{{file.size}}{noformat}\n- *File Target Path*: {noformat}{{file.target_path}}{noformat}\n- *File Type*: {noformat}{{file.type}}{noformat}\n {{/context.alerts}}\n

```

This is my setup [Elastic-Security/Bulk Rule Modification at main · austinsonger/Elastic-Security (github.com)](https://github.com/austinsonger/Elastic-Security/tree/main/Bulk%20Rule%20Modification)

**And this is what it looks like when it formats in JIRA**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c8cdd11f1c4c514cbfbb076c62e1eb1f3ebd796.png)

**Here are the HTML Tags supported for Email**

> <https://gist.github.com/austinsonger/ca86e8bd882607cc00c12af06e945e05#file-html-tags-4-email-md>

So here is a example for you, if this helps.

```auto
<h3>File<h3>
 {{#context.alerts}}
<ul>
<li>File Name: {{file.name}}</li>
<li>File Owner: {{file.owner}}</li>
<li>File Path: {{file.path}}</li>
<li>File size: {{file.size}}</li>
<li>File Target Path: {{file.target_path}}</li>
<li>File Type: {{file.type}}</li>
</ul>
 {{/context.alerts}}

```

Now to place that in a code block would look like this, but a lot email providers won't render `<pre>` or `<code>` HTML tags.

```auto
<pre><code>&lt;h3&gt;File&lt;h3&gt;
 {{#context.alerts}}
&lt;ul&gt;
&lt;li&gt;File Name: {{file.name}}&lt;/li&gt;
&lt;li&gt;File Owner: {{file.owner}}&lt;/li&gt;
&lt;li&gt;File Path: {{file.path}}&lt;/li&gt;
&lt;li&gt;File size: {{file.size}}&lt;/li&gt;
&lt;li&gt;File Target Path: {{file.target_path}}&lt;/li&gt;
&lt;li&gt;File Type: {{file.type}}&lt;/li&gt;
&lt;/ul&gt;
 {{/context.alerts}}
</code></pre>

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 6:47pm UTC](https://discuss.elastic.co/t/format-siem-alerts/272772/4 "2021-06-09T18:47:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
