# Kibana Alert Index Threshold and Log Threshold Host.ip Fields

**URL:** <https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [March 13, 2023, 1:52am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510 "2023-03-13T01:52:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![OmFJ](https://avatars.discourse-cdn.com/v4/letter/o/8e7dd6/32.png) [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Post date:** [March 13, 2023, 1:52am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/1 "2023-03-13T01:52:04Z")

</div>

Hi Everyone, i have question regarding Kibana's Alerting feature. As we know, we could use 'Group by' to include field into the alert message. But i have trouble to include host.ip field.

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b76ed1744f37d0aae4f479928c92161d8d8a6e4a.png)

Any Suggestion or workaround i can do?  
PS: it's the same hostname. that's why i don't use host.hostname.

---

<div class="post-metadata">

**Author:** ![Ersin\_Erdal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ersin_erdal/32/114575_2.png) [@Ersin\_Erdal](https://discuss.elastic.co/u/Ersin_Erdal)\
**Post date:** [March 13, 2023, 11:07am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/2 "2023-03-13T11:07:48Z")

</div>

Hi @OmFJ

As you can see [here](https://www.elastic.co/guide/en/ecs/current/ecs-host.html) host.ip field is an array. Array fields can't be used for "Group by".

---

<div class="post-metadata">

**Author:** ![OmFJ](https://avatars.discourse-cdn.com/v4/letter/o/8e7dd6/32.png) [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Post date:** [March 14, 2023, 1:30am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/3 "2023-03-14T01:30:29Z")

</div>

Hi @Ersin_Erdal,

Thank you for replying. is there any way i can do to use the IP address ? or is it recommended if i create runtime field from mapping or index template?

Thanks!

---

<div class="post-metadata">

**Author:** ![Ersin\_Erdal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ersin_erdal/32/114575_2.png) [@Ersin\_Erdal](https://discuss.elastic.co/u/Ersin_Erdal)\
**Post date:** [March 14, 2023, 3:31pm UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/4 "2023-03-14T15:31:06Z")

</div>

Hi @OmFJ

Sure, if you have control on your index and know which ip you should use from the host.ip array, you can create new a field out of it and use for grouping.

---

<div class="post-metadata">

**Author:** ![OmFJ](https://avatars.discourse-cdn.com/v4/letter/o/8e7dd6/32.png) [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Post date:** [March 16, 2023, 1:47am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/5 "2023-03-16T01:47:40Z")

</div>

Hi @Ersin_Erdal

Thank you so much for the response. I will update this post once i get the result as soon as possible.  
Once again, Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 1:48am UTC](https://discuss.elastic.co/t/kibana-alert-index-threshold-and-log-threshold-host-ip-fields/327510/6 "2023-04-13T01:48:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
