# How to Show the Value of tags When Using Server Log Connector

**URL:** <https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [January 18, 2023, 2:37am UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372 "2023-01-18T02:37:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 18, 2023, 2:37am UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/1 "2023-01-18T02:37:00Z")

</div>

Hello everyone,

i want to ask something about alerting here. i already create a rule to notify me if there is a certificate that will be expire in few days through server log which is kibana.log like this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b51efb821849867055428221561b8a31e36902f6.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d20bedabae25748100dce2fd844680f4bfbf9826.png)

Due to different types of certificates that exist, in which there is manual-renew and auto-renew, I want to display those tags in the message. so that the script that I made can be given conditions(if else) based on the value of field tags. What variables can I use to display the tags there? i was tried using {{\_source.tags}} but it didn't work

this is the tags value from discover  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac0072f8a51f2bdf5ef1ad0e7465195ff6b4e0e.png)

and fyi, i used elastic 7.17.0 version

Thanks

---

<div class="post-metadata">

**Author:** ![faisal-k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisal-k/32/103817_2.png) [@faisal-k](https://discuss.elastic.co/u/faisal-k)\
**Post date:** [January 18, 2023, 12:26pm UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/2 "2023-01-18T12:26:17Z")

</div>

Hi @yuswanul

The rule message template has a **predefined** list of variables, so `{{_source.tags}}` won't work. You can see and add these variables by clicking on the add button. Please check the screenshot below.

 ![rule message](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ecedc25704c08c7745fa6b34e5707f0f91996593.png)

Have a great day, and thanks for reaching out!  
Faisal

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [January 18, 2023, 1:04pm UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/3 "2023-01-18T13:04:45Z")

</div>

Hi @yuswanul, as mentioned above, the available action variables can be seen in the dropdown. For this specific case, you should be able to access the tags under {{rule.tags}}

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 18, 2023, 2:06pm UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/4 "2023-01-18T14:06:10Z")

</div>

so, it is not possible to retrieve the value of the field from the index in this version? or in the next version will be available? because it really help, so i hope this feature will be considered for the next version

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 19, 2023, 2:53am UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/5 "2023-01-19T02:53:18Z")

</div>

> [@ying.mao](#):
>
> you should be able to access the tags under {{rule.tags}}

{{rule.tags}} just give me the tags of the rule not the tags of the data in discover

---

<div class="post-metadata">

**Author:** ![ying.mao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ying.mao/32/88151_2.png) [@ying.mao](https://discuss.elastic.co/u/ying.mao)\
**Post date:** [January 19, 2023, 1:22pm UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/6 "2023-01-19T13:22:14Z")

</div>

@yuswanul Gotcha. I misunderstood. The availability of the fields inside \_source is dependent on the rule type and it does not look like the Uptime TLS alert gives access to that as an action variable.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 19, 2023, 1:36pm UTC](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/7 "2023-01-19T13:36:46Z")

</div>

How about Elasticsearch query? Is it possible to use that? Maybe we can calculate the expire date of the certificate then we substract it with today date first. After that, maybe we call the value of tags field in the alert message

Pada tanggal Kam, 19 Jan 2023 20.32, Ying M via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:
