# How to send JSON body in rule?

**URL:** <https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [January 25, 2024, 6:08am UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768 "2024-01-25T06:08:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![navin547](https://avatars.discourse-cdn.com/v4/letter/n/779978/32.png) [@navin547](https://discuss.elastic.co/u/navin547)\
**Post date:** [January 25, 2024, 6:08am UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768/1 "2024-01-25T06:08:41Z")

</div>

Hi,

I have created a webhook connector which uses servicenow api to send, then I have created a rule and used that webhook connector so whenever that rule trigger I need to send that alert data in body as a JSON as servicenow api expect data in json format.

Example:  
{"caller\_id": "xyz", "u\_ticket\_classification": "ticket", "impact": "3", "urgency": "3", "short\_description": "{{rule.name}}", "description": "{{rule.description}}", "opened\_by": "xyz", "contact\_type": "email"}

but this is not working not getting data, please let me know the correct way.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [January 25, 2024, 2:48pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768/2 "2024-01-25T14:48:48Z")

</div>

Welcome @navin547. Thanks for reaching out.

Do you have a code sample you are using? Are you encountering any errors? You may want to double-check that your Content-Type header is set to application/json.

---

<div class="post-metadata">

**Author:** ![navin547](https://avatars.discourse-cdn.com/v4/letter/n/779978/32.png) [@navin547](https://discuss.elastic.co/u/navin547)\
**Post date:** [January 29, 2024, 8:13am UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768/3 "2024-01-29T08:13:09Z")

</div>

Hey @jessgarson thanks, I am able to send the body in JSON format by using {{#ParseHjson}}, but I am not able to get the document details ({{context.hits.0.\_source.message}}) could you please help me.

I am using below code.

```auto
{{#ParseHjson}}
{"caller_id": "xyz", "u_ticket_classification": "ticket", "impact": "3", "urgency": "3", "short_description": "{{rule.name}}", "description": "{{context.hits.0._source.message}}", "opened_by": "xyz", "contact_type": "email"}
{{/ParseHjson}}

```

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [January 29, 2024, 3:45pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768/4 "2024-01-29T15:45:43Z")

</div>

Thanks for following up, @navin547.

[It seems](https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903) you can use the [Mustache](https://mustache.github.io/) template array syntax to iterate the hits. [This similar forum](https://discuss.elastic.co/t/kibana-email-alert/303013) post suggests that you can add `{{.}}` within that message to get a listing of all the available variables.

Hope this helps!  
Jess

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2024, 3:46pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768/5 "2024-02-26T15:46:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
