# Missing "Custom Fields" in alerts generated from "endpoint" indexes

**URL:** <https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436>\
**Category:** Elastic Security\
**Created:** [October 25, 2024, 2:39pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436 "2024-10-25T14:39:59Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [October 28, 2024, 1:55pm UTC](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436/2 "2024-10-28T13:55:46Z")

</div>

The Fleet settings apply to a feature called "processors" which only Beats have. Endpoint doesn't have support for it, but it also has a means to inject simple key-value pairs into documents, see advanced option  
`[platform].advanced.document_enrichment.fields`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9488a44c6dc7e505e71e5fefb530a9c3c61c1c2.png)

---

_[View the full topic](https://discuss.elastic.co/t/missing-custom-fields-in-alerts-generated-from-endpoint-indexes/369436)._
