# How to get the different counts mentioned for threat matches detected and fields enriched with threat intelligence under threat intelligence overview in Security Alerting

**URL:** <https://discuss.elastic.co/t/how-to-get-the-different-counts-mentioned-for-threat-matches-detected-and-fields-enriched-with-threat-intelligence-under-threat-intelligence-overview-in-security-alerting/378346>\
**Category:** Elastic Security\
**Created:** [May 20, 2025, 1:31pm UTC](https://discuss.elastic.co/t/how-to-get-the-different-counts-mentioned-for-threat-matches-detected-and-fields-enriched-with-threat-intelligence-under-threat-intelligence-overview-in-security-alerting/378346 "2025-05-20T13:31:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergie](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Sergie](https://discuss.elastic.co/u/Sergie)\
**Post date:** [May 20, 2025, 1:31pm UTC](https://discuss.elastic.co/t/how-to-get-the-different-counts-mentioned-for-threat-matches-detected-and-fields-enriched-with-threat-intelligence-under-threat-intelligence-overview-in-security-alerting/378346/1 "2025-05-20T13:31:42Z")

</div>

Under threat intelligence overview tab, how can I calculate the different counts mentioned for threat matches detected and fields enriched with threat intelligence

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/6/76d2c4eba747d9b6d428cd7db4e590db33a18cc8.png)

For my use case I wanted to understand is there an API associated, or it this handled on the Kibana source code level.

If it is kibana source code, kindly explain and help me with the logic along with the links to the exact kibana code where this logic is getting built.

---

<div class="post-metadata">

**Author:** ![Philippe\_Oberti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippe_oberti/32/118677_2.png) [@Philippe\_Oberti](https://discuss.elastic.co/u/Philippe_Oberti)\
**Post date:** [June 3, 2025, 8:46pm UTC](https://discuss.elastic.co/t/how-to-get-the-different-counts-mentioned-for-threat-matches-detected-and-fields-enriched-with-threat-intelligence-under-threat-intelligence-overview-in-security-alerting/378346/2 "2025-06-03T20:46:44Z")

</div>

If anyone is looking at this, this question is a duplicate of [this one](https://discuss.elastic.co/t/how-to-get-the-list-of-highlighted-fields-attached-per-rule-in-alerts-flyout-in-security-analytics/377423/7) and was answered [here](https://discuss.elastic.co/t/how-to-get-the-list-of-highlighted-fields-attached-per-rule-in-alerts-flyout-in-security-analytics/377423/8) 😃
