# Kibana Alerts add fields property

**URL:** <https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting, runtime-fields\
**Created:** [November 2, 2022, 2:21pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999 "2022-11-02T14:21:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [November 2, 2022, 2:21pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/1 "2022-11-02T14:21:40Z")

</div>

I am trying to add an extra fields using script\_fields or runtime\_mappings to Kibana alerts. But Kibana replaces the property fields with some timestamp.

Is there a solution or workaround?

### Edit #1 to add code

#### Query

```auto
/myindex*/_search?pretty
{
  "query": {
    "match_all": {}
  },

  "fields": [
    "test_field"
  ],
  "script_fields": {
    "test_field": {
      "script": {
        "lang": "painless",
        "source": "params.test_pram",
        "params": {
          "test_pram": 1
        }
      }
    }
  },
  "_source": true
}

```

### Response from Elasticsearch

```auto
{
  "took": 8,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 10000,
      "relation": "gte"
    },
    "max_score": 1,
    "hits": [
      {
        "_index": "myindex1",
        "_type": "_doc",
        "_id": "1",
        "_score": 1,
        "_source": {
          "color": "red"
        },
        "fields": {
          "test_field": [
            1
          ]
        }
      },...

```

### Response from Kibana

```auto
{
  "took": 8,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 10000,
      "relation": "gte"
    },
    "max_score": 1,
    "hits": [
      {
        "_index": "myindex1",
        "_type": "_doc",
        "_id": "1",
        "_score": 1,
        "_source": {
          "color": "red"
        },
      "fields": {
        "@timestamp": [
          "2022-11-02T14:00:11.754Z"
        ]
      },
      "sort": [
        1667397611754
      ]
        }
      },...

```

### Edit #2 to add code

### Kibana create alert request

```auto
/s/myspace/api/alerting/rule/:id
{
  "consumer": "alerts",
  "name": "my_alert",
  "schedule": {
    "interval": "1m"
  },
  "params": {
    "esQuery": "{\n\"query\":{\n\"match_all\":{}\n},\n\n\"fields\":[\n\"test_field\"\n],\n\"script_fields\":{\n\"test_field\":{\n\"script\":{\n\"lang\":\"painless\",\n\"source\":\"params.test_pram\",\n\"params\":{\n\"test_pram\":1\n}\n}\n}\n},\n\"_source\":true\n}",
    "index": [
      "myindex*"
    ],
    "timeField": "@timestamp",
    "timeWindowSize": 30,
    "timeWindowUnit": "m",
    "thresholdComparator": ">",
    "threshold": [
      0
    ],
    "size": 10
  },
  "rule_type_id": ".es-query",
  "notify_when": "onActionGroupChange",
  "actions": [
    {
      "group": "query matched",
      "id": "mailConnector",
      "params": {
        "subject": "My Alert",
        "to": [
          "email@example.com"
        ],
        "message": "{{context}}"
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 2, 2022, 2:30pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/2 "2022-11-02T14:30:17Z")

</div>

Hi, could you please share the script you are trying to run?

---

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [November 2, 2022, 3:45pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/3 "2022-11-02T15:45:27Z")

</div>

@jcger added the example

---

<div class="post-metadata">

**Author:** ![Xavier\_Mouligneau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavier_mouligneau/32/49188_2.png) [@Xavier\_Mouligneau](https://discuss.elastic.co/u/Xavier_Mouligneau)\
**Post date:** [November 2, 2022, 4:56pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/4 "2022-11-02T16:56:06Z")

</div>

Hi,

Will be possible to define which kibana alerts are you using stack and/or observability and/or security solution? or which rule are you using? and can you please provide the version of kibana that you are using?

---

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [November 2, 2022, 5:24pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/5 "2022-11-02T17:24:41Z")

</div>

@Xavier_Mouligneau added the API request [Kibana Alerts add fields property](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999#kibana-create-alert-request-6)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2022, 7:27pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/6 "2022-11-29T19:27:21Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2022, 7:27pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999/7 "2022-12-27T19:27:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
