# Kibana alert type Metric threshold add fields index to body Email

**URL:** <https://discuss.elastic.co/t/kibana-alert-type-metric-threshold-add-fields-index-to-body-email/311777>\
**Category:** Kibana\
**Created:** [August 10, 2022, 12:33am UTC](https://discuss.elastic.co/t/kibana-alert-type-metric-threshold-add-fields-index-to-body-email/311777 "2022-08-10T00:33:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jorge\_Flores\_Machuca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jorge_flores_machuca/32/101395_2.png) [@jorge\_Flores\_Machuca](https://discuss.elastic.co/u/jorge_Flores_Machuca)\
**Post date:** [August 10, 2022, 12:33am UTC](https://discuss.elastic.co/t/kibana-alert-type-metric-threshold-add-fields-index-to-body-email/311777/1 "2022-08-10T00:33:14Z")

</div>

Hello everyone, how can I take fields from the metricbeat index and add them to the body of my email, as shown in the example on the green line?  
this my rule

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d3836b07a9c3426501e68b477443b88b6dad8df9.png)  
and this my definition email  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/91cddf6d0e9341185afc5776d708e98d9ea5c4db.png)

if you could guide me thank you

Regards

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [September 6, 2022, 12:48pm UTC](https://discuss.elastic.co/t/kibana-alert-type-metric-threshold-add-fields-index-to-body-email/311777/2 "2022-09-06T12:48:59Z")

</div>

Think that the alert is going to run an aggregation so when the alert triggers it does not know from which server it's coming. You need to group by `host.name` or `host.ip` to create alert groups.

From the [docs](https://www.elastic.co/guide/en/observability/8.4/metrics-threshold-alert.html):

> The Group alerts by creates an instance of the alert for every unique value of the field added. For example, you can create a rule per host or every mount point of each host. You can also add multiple fields. In this example, the rule will individually track the status of each host.name in your infrastructure. You will only receive an alert about host-1, if `host.name: host-1 passes the threshold, but host-2 and host-3 do not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-alert-type-metric-threshold-add-fields-index-to-body-email/311777/3 "2022-10-04T12:49:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
