# How to expose custom fields from alert JSON in the Slack API connector?

**URL:** <https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142>\
**Category:** SIEM\
**Created:** [May 14, 2025, 1:48pm UTC](https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142 "2025-05-14T13:48:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![iTiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itiago/32/142800_2.png) [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Post date:** [May 14, 2025, 1:48pm UTC](https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142/1 "2025-05-14T13:48:40Z")

</div>

Hello Team

I'm implementing detection rules in Elastic Security (Kibana v8.x) and want to notify alerts in Slack using the Slack API connector. However, I can only use the predefined variables listed in the + Add variable selector (e.g., alert.severity, alert.risk\_score, alerts.new.count, etc.) [Elastic](https://www.elastic.co/guide/en/kibana/current/rule-action-variables.html?utm_source=chatgpt.com).

My **goal** is to also include custom fields that I add to the alert document (e.g., user metadata or labels defined in the index), but when I try to reference them with Mustache (`{{my_custom_field}}` or `{{context.alerts.0.my_custom_field}}`), Slack ignores them or expands them to empty...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f3cb58eb6c384e5a2d1f40d418d90d80dbe557b.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d0eb2bd42b34c74b7dd45784661401c8de19eb5.png)

## What I've tried

1. **Slack API connector** with standard Mustache (`{{alert.*}}`, `{{alerts.*}}`, `{{context.results_link}}`): works only with predefined variables.
2. Trying to reference `context.rule.*`: It doesn't work because those scopes only contain rule metadata, not the alert itself [Stack Overflow](https://stackoverflow.com/questions/75786680/in-elasticsearch-complete-error-keyword-context-in-slack-web-hook-channel?utm_source=chatgpt.com).
3. In Kibana 8.8+, I've seen that `context.alerts` exists as an array, but when using it in the Slack connector, it doesn't recognize it directly [Discuss the Elastic Stack](https://discuss.elastic.co/t/webhook-with-variables-from-query-dsl-hits/318319?utm_source=chatgpt.com).

Is there a native way, without using intermediate Webhooks, for the **Slack API connector** to expose arbitrary fields that come in the alert JSON?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2025, 2:48pm UTC](https://discuss.elastic.co/t/how-to-expose-custom-fields-from-alert-json-in-the-slack-api-connector/378142/2 "2025-07-18T14:48:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
