# Missing "Custom Fields" in alerts generated from "endpoint" indexes

**URL:** <https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436>\
**Category:** Elastic Security\
**Created:** [October 25, 2024, 2:39pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436 "2024-10-25T14:39:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aptfinf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aptfinf/32/137147_2.png) [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Post date:** [October 25, 2024, 2:39pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/1 "2024-10-25T14:39:59Z")

</div>

Hello,

I would like to ask a question about Custom Fields.

I had just added a "Custom Field" inside one of my Fleet Policy, as shown on the below screenshot:  
 ![Screenshot 2024-10-25 162902](https://us1.discourse-cdn.com/elastic/optimized/3X/e/1/e129f988044f688490aec759c65e8b07c6c8a4aa_2_689x46.png)

I get the field correctly added to all the logs (and therefore transposed to all the alerts) that are generated, for example, from rules that check inside `winlogbeat-*` or `logs-windows.*` index:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3facce03fd253df524d350f95cba4c2e474655ff.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34088057f75196ae5b28d3ae6763fdc38a58235d.png)

The issue i'm facing is that the field isn't added on the logs (and alerts) that are inside the `logs-endpoint.*` indexes:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/3/235df03ccc9db873078c7dc4597c42c23267ffec.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/7/576966ecbdffc92781fbd775238c30268d8e267a.png)

Am i doing something wrong?

Thank you

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [October 28, 2024, 1:55pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/2 "2024-10-28T13:55:46Z")

</div>

The Fleet settings apply to a feature called "processors" which only Beats have. Endpoint doesn't have support for it, but it also has a means to inject simple key-value pairs into documents, see advanced option  
`[platform].advanced.document_enrichment.fields`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9488a44c6dc7e505e71e5fefb530a9c3c61c1c2.png)

---

<div class="post-metadata">

**Author:** ![aptfinf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aptfinf/32/137147_2.png) [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Post date:** [October 29, 2024, 10:56am UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/3 "2024-10-29T10:56:00Z")

</div>

Hello @lesio,

Thank you for your answer, i confirm that with this field it's possible to add custom fields to Endpoint documents.

However, i'm facing another related issue: with the Fleet custom field i'm able to filter alerts, but the Endpoint document enrichment fields that i add aren't available to use as queries in Security Alerts.

May be caused by some missing index mapping?

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [October 29, 2024, 2:43pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/4 "2024-10-29T14:43:47Z")

</div>

I haven't tested this, but if you add these custom fields to index mappings does that fix it?

---

<div class="post-metadata">

**Author:** ![aptfinf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aptfinf/32/137147_2.png) [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Post date:** [October 29, 2024, 2:55pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/5 "2024-10-29T14:55:22Z")

</div>

Actually i fixed the issue by creating a new Field from the Alerts table

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/464f2c4b9a5fac37115f60c0d64076c83635ee5e.png)

Now i can filter every alert, generated either from Beats or Endpoint.

Thank you everyone, problem fixed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2024, 2:55pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/6 "2024-11-26T14:55:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
