# Kibana: Cannot update rule

**URL:** <https://discuss.elastic.co/t/kibana-cannot-update-rule/382845>\
**Category:** Kibana\
**Created:** [October 20, 2025, 6:03pm UTC](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845 "2025-10-20T18:03:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cristian\_Pereyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristian_pereyra/32/126779_2.png) [@Cristian\_Pereyra](https://discuss.elastic.co/u/Cristian_Pereyra)\
**Post date:** [October 20, 2025, 6:03pm UTC](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845/1 "2025-10-20T18:03:41Z")

</div>

Hello everyone, I hope you're doing well.  
I'm creating a rule of type **"Elasticsearch query"** that uses a connector to a Python microservice, which then sends an email. The rule works fine.

However, when I try to update the message block to send with:

`{{#context.hits}} `  
`- User **{{_source.user}}:** The token expires in ***{{_source.remaining_days}} days***. {{/context.hits}}`

I get this error: **Cannot update rule.**

But if I remove that block of text, Kibana successfully saves the configured rule.  
Do you have any recommendations or alternatives that could help me?

Tests performed

- **Removing** only that block: the rule works.

- Creating the rule with the ‘context.hits’ text block using the superuser account: the rule works.

- I don’t get any response in the Kibana logs

### 

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9d37e298c8d4a0967ce7c9b311bb62cc78e6f82.png)

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [October 21, 2025, 3:09am UTC](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845/2 "2025-10-21T03:09:13Z")

</div>

> [@Cristian\_Pereyra](#):
>
> `{{#context.hits}} `  
> `- User **{{_source.user}}:** The token expires in ***{{_source.remaining_days}} days***. {{/context.hits}}`

Hello @Cristian_Pereyra

I tried on kibana default index and do not see any issues :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf107831753f3862d8880727c0c0e936b7ead31c.png)

Only used below :

```auto
{{#context.hits}}
- User **{{_source.customer_full_name}}:** has the order id is ***{{_source.order_id}}***.
{{/context.hits}}

```

Output :

```auto
IP - - [21/Oct/2025 03:01:17] "POST /alert HTTP/1.1" 200 -
Received alert: - User **Pia Bradley:** has the order id is ***712866***.
- User **Sultan Al Caldwell:** has the order id is ***576185***.
- User **Marwan Figueroa:** has the order id is ***576175***.
- User **Kamal Cortez:** has the order id is ***576171***.

```

I see in your screenshot of message few emojis added as well not sure if that is causing issue while saving the rule, for plain text i do not see issue.

Thanks!!

---

<div class="post-metadata">

**Author:** ![Cristian\_Pereyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristian_pereyra/32/126779_2.png) [@Cristian\_Pereyra](https://discuss.elastic.co/u/Cristian_Pereyra)\
**Post date:** [October 21, 2025, 11:54am UTC](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845/3 "2025-10-21T11:54:55Z")

</div>

@Tortoise Thanks for replying.

I have a few questions:

1. When you created the rule, did you do it with the root user?

2. If you created it with your own user, what are you using as the identity provider — SAML, LDAP, etc.?

Question 1 is related to the fact that when I create the same rule with the `#context.hits` block using the root (elastic) user, it works correctly and doesn’t cause any issues.

As for emojis, they are supported by both Kibana and the MS that forwards the notification — we haven’t had any issues with that.

By the way, I’m running ELK **8.18.1** and ECK **3.1.0**.
