# Kibana Alert variable declaration

**URL:** <https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring, elastic-stack-alerting\
**Created:** [July 11, 2022, 12:08pm UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316 "2022-07-11T12:08:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ilanchezhian](https://avatars.discourse-cdn.com/v4/letter/i/b38774/32.png) [@ilanchezhian](https://discuss.elastic.co/u/ilanchezhian)\
**Post date:** [July 11, 2022, 12:08pm UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/1 "2022-07-11T12:08:08Z")

</div>

Hi All,

I'm creating a alert in kibana for IP monitoring, how can I pass the index field values as a parameter in alert body for easy identification @Simon_Becker

---

<div class="post-metadata">

**Author:** ![emmma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emmma/32/100838_2.png) [@emmma](https://discuss.elastic.co/u/emmma)\
**Post date:** [July 18, 2022, 1:59pm UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/2 "2022-07-18T13:59:48Z")

</div>

@ilanchezhian

To answer your question, we would need more detail about the type of rule you are creating (e.g. Uptime Monitor Status) and what information you would like to include in the alert notification.

Thanks

---

<div class="post-metadata">

**Author:** ![aji.shinde7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aji.shinde7/32/115498_2.png) [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Post date:** [July 18, 2022, 2:23pm UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/3 "2022-07-18T14:23:55Z")

</div>

Hello All,

Me too have same question.

In heartbeat-\* index i have multiple server's data. 5 servers are dedicated to a common task.

So, I want to check monitor.status of all 5 servers at once.

And

Provide list of servers which are down , in alert email message body.

There is no existing rule variables where I can assign list of servers.

Any solution for this.🙏

Thank you🙏

---

<div class="post-metadata">

**Author:** ![aji.shinde7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aji.shinde7/32/115498_2.png) [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Post date:** [July 18, 2022, 2:25pm UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/4 "2022-07-18T14:25:27Z")

</div>

Additional info.

I am using "uptime" and "Elasticsearch query" type rule

---

<div class="post-metadata">

**Author:** ![ilanchezhian](https://avatars.discourse-cdn.com/v4/letter/i/b38774/32.png) [@ilanchezhian](https://discuss.elastic.co/u/ilanchezhian)\
**Post date:** [July 19, 2022, 10:28am UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/5 "2022-07-19T10:28:10Z")

</div>

My Rule is Customized Query Rule, I am checking if any IP lists in the logs from the index it should alert me and the index has multiple filed name, So when a alert triggers it should trigger me with an one of the index field value(Host.name).

Here my issue is I'm unable to print my needed index field value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2022, 10:29am UTC](https://discuss.elastic.co/t/kibana-alert-variable-declaration/309316/6 "2022-08-16T10:29:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
