# I have set one alert rule, i see some fields are not populated correctly in the alert document, so in the index makes empty fields

**URL:** <https://discuss.elastic.co/t/i-have-set-one-alert-rule-i-see-some-fields-are-not-populated-correctly-in-the-alert-document-so-in-the-index-makes-empty-fields/375643>\
**Category:** Metrics\
**Created:** [March 10, 2025, 10:48am UTC](https://discuss.elastic.co/t/i-have-set-one-alert-rule-i-see-some-fields-are-not-populated-correctly-in-the-alert-document-so-in-the-index-makes-empty-fields/375643 "2025-03-10T10:48:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![sayid](https://avatars.discourse-cdn.com/v4/letter/s/ec9cab/32.png) [@sayid](https://discuss.elastic.co/u/sayid)\
**Post date:** [March 10, 2025, 10:48am UTC](https://discuss.elastic.co/t/i-have-set-one-alert-rule-i-see-some-fields-are-not-populated-correctly-in-the-alert-document-so-in-the-index-makes-empty-fields/375643/1 "2025-03-10T10:48:07Z")

</div>

i have set one alert rule, i see some fields are not populated correctly in the alert document, so in the index makes empty fields.

here is my alert rule:  
PUT kbn:/api/alerting/rule/6aeaa6d9-8795-4c63-9623-975a20e61bd9  
{  
"name": "service\_state\_watch rule",  
"tags": ,  
"schedule": {  
"interval": "1m"  
},  
"params": {  
"searchConfiguration": {  
"query": {  
"query": "(system.service.state : "inactive" OR system.service.state : "deactivating" OR system.service.state : "failed" OR system.service.sub\_state : "dead" OR system.service.sub\_state : "exited" OR system.service.sub\_state : "failed") AND \n(system.service.name : "mysqld.service" OR system.service.name : "ussddispatcher.service" OR system.service.name : "sugw.service")\n",  
"language": "kuery"  
},  
"index": "metricbeat-\*"  
},  
"timeField": "@timestamp",  
"searchType": "searchSource",  
"timeWindowSize": 5,  
"timeWindowUnit": "m",  
"threshold": [  
1  
],  
"thresholdComparator": "\>=",  
"size": 100,  
"aggType": "count",  
"groupBy": "top",  
"termField": [  
"system.service.name",  
"system.service.state",  
"system.service.sub\_state"  
],  
"termSize": 1,  
"excludeHitsFromPreviousRun": true,  
"sourceFields": [  
{  
"label": "host.hostname",  
"searchPath": "host.hostname"  
},  
{  
"label": "host.id",  
"searchPath": "host.id"  
},  
{  
"label": "host.name",  
"searchPath": "host.name"  
}  
]  
},  
"actions": [  
{  
"group": "query matched",  
"id": "df177a7d-936d-4de6-b34a-00d9587a27b4",  
"params": {  
"documents": [  
{  
"@timestamp": "{{context.execution\_time}}",  
"rule\_id": "{{rule.id}}",  
"rule\_name": "{{rule.name}}",  
"alert\_id": "{{alert.id}}",  
"alert\_type": "Service State Change",  
"service\_name": "{{context.system.service.name}}",  
"service\_state": "{{context.system.service.state}}",  
"service\_sub\_state": "{{context.system.service.sub\_state}}",  
"message": "Service '{{context.system.service.name}}' changed state to '{{context.system.service.state}}'."  
}  
]  
},  
"frequency": {  
"notify\_when": "onActionGroupChange",  
"throttle": null,  
"summary": false  
},  
"uuid": "6845c802-4b41-470f-969d-7a88614c93f7"  
},  
{  
"group": "recovered",  
"id": "df177a7d-936d-4de6-b34a-00d9587a27b4",  
"params": {  
"documents": [  
{  
"@timestamp": "{{context.execution\_time}}",  
"rule\_id": "{{rule.id}}",  
"rule\_name": "{{rule.name}}",  
"alert\_id": "{{alert.id}}",  
"alert\_type": "Service State Change",  
"service\_name": "{{context.system.service.name}}",  
"service\_state": "{{context.system.service.state}}",  
"service\_sub\_state": "{{context.system.service.sub\_state}}",  
"message": "Service '{{context.system.service.name}}' has recovered and changed state to '{{context.service.state}}'."  
}  
]  
},  
"frequency": {  
"notify\_when": "onActionGroupChange",  
"throttle": null,  
"summary": false  
},  
"uuid": "020f6fc4-2cce-4395-94ab-ac8a734aef25"  
}  
]  
}

the index mapping to is also here:  
{  
"mappings": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"alert\_id": {  
"type": "keyword"  
},  
"alert\_type": {  
"type": "keyword"  
},  
"error": {  
"properties": {  
"message": {  
"type": "text"  
}  
}  
},  
"host\_hostname": {  
"type": "keyword"  
},  
"message": {  
"type": "text"  
},  
"metric\_name": {  
"type": "keyword"  
},  
"metric\_value": {  
"type": "float"  
},  
"rule\_id": {  
"type": "keyword"  
},  
"rule\_name": {  
"type": "keyword"  
},  
"service\_name": {  
"type": "keyword"  
},  
"service\_state": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"service\_status": {  
"type": "keyword"  
},  
"service\_sub\_state": {  
"type": "keyword"  
},  
"threshold": {  
"type": "float"  
}  
}  
}  
}

## if status change from one of these systemctl services metrics in the rule , alert is triggered and perform action and document is written in the index @timestamp Mar 10, 2025 @ 13:26:56.624 alert\_id ussddispatcher.service,inactive,dead alert\_type Service State Change message Service '' changed state to ''. rule\_id 6aeaa6d9-8795-4c63-9623-975a20e61bd9 rule\_name service\_state\_watch rule service\_name (empty) service\_state (empty) service\_sub\_state (empty) \_id PraXf5UBmHmFUE1Z5\_\_x \_ignored

\_index  
metricindexv1  
\_score  
1

 ![index](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0aa7ea05fdf0091569c570bff761e431dfad72d.png)  
why these empty fields? that is my issue for my case.
