# Missing Fields when Creating Alert in Kibana

**URL:** https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [June 9, 2021, 2:04pm UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448 "2021-06-09T14:04:19Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)
#### Post date: [June 9, 2021, 2:04pm UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448/1 "2021-06-09T14:04:19Z")

</div>

Hi guys,  
so i tried to setup a few simple Kibana Alerts combined with a log-connector.  
I'm running Elastic-Stack 7.11 on 3 CentOS 7 Servers.

There was no problem in enabeling the alerts, but now when i try to create an Alert on my Winlogbeat-Index, i cannot see any of the fields used in the index in the dropdown menu.

I can see various fields from the fortinet-filebeat module or panw-filebeat module. But there are no winlogbeat.X Fields at all available to select. What do i have to to, to be able to access them just as any other field.

Thanks in advance!

---

<div class="post-metadata">

### Author: ![Aaron\_Caldwell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_caldwell/32/45755_2.png) [@Aaron\_Caldwell](https://discuss.elastic.co/u/Aaron_Caldwell)
#### Post date: [June 9, 2021, 3:25pm UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448/2 "2021-06-09T15:25:41Z")

</div>

Hello,

This is usually because the fields in your index don't meet the criteria for creating an alert. I would double-check the fields in your index and compare to what fields can be used. Here's [one example](https://www.elastic.co/guide/en/observability/current/logs-threshold-alert.html) that includes criteria, there are a few more listed [here](https://www.elastic.co/guide/en/observability/current/create-alerts.html).

Regards,  
Aaron

---

<div class="post-metadata">

### Author: ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)
#### Post date: [June 10, 2021, 6:45am UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448/3 "2021-06-10T06:45:14Z")

</div>

This is the field i want to access in my Alerts:  
But i cannot find the difference between this one, and for example fortinet fields which are available to me.

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/9/7/9736a8a7193d95c1fbfaad60c7756945bf0d93ea.png)  
 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e334823024574a16551ebd3c9d10cc0d59caf91.png)

I am totally new to this topic, sorry if i act dumb.

---

<div class="post-metadata">

### Author: ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)
#### Post date: [June 29, 2021, 7:05pm UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448/4 "2021-06-29T19:05:56Z")

</div>

What alert are you trying to use? The [index threshold alerting rule type](https://www.elastic.co/guide/en/kibana/current/rule-type-index-threshold.html) should support building conditions against numeric fields, like the one you show above. Other alerting rule types may be expecting keywords or text for certain fields.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 27, 2021, 7:06pm UTC](https://discuss.elastic.co/t/missing-fields-when-creating-alert-in-kibana/275448/5 "2021-07-27T19:06:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
