# Namespace Option in Slack Connector

**URL:** <https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292>\
**Category:** Kibana\
**Created:** [January 25, 2022, 2:30am UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292 "2022-01-25T02:30:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [January 25, 2022, 2:30am UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/1 "2022-01-25T02:30:16Z")

</div>

Is it possible to add the namespace information in the slack connector?

i.e

```auto
Rule {{context.rule.name}} with severity {{context.rule.severity}} generated {{state.signals_count}} alerts in the {{context.data_stream.namespace}} namespace.

```

I don't see the option in the mustache syntax, but maybe it's possible?

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 3, 2022, 5:27pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/2 "2022-02-03T17:27:02Z")

</div>

The Kibana space id is available via mustache variable `rule.spaceId` .

see: [Create and manage rules | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/current/create-and-manage-rules.html#defining-rules-actions-variables)

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [February 3, 2022, 5:46pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/3 "2022-02-03T17:46:59Z")

</div>

So that is the Space, not the actual namespace. We use namespaces for data segmentation, so the Space ID doesn't help too much.

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 3, 2022, 6:59pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/4 "2022-02-03T18:59:53Z")

</div>

Sorry, not sure what "namespace" is then - I thought you were referring to Kibana spaces.

I assume then it must be something specific to the rule you are using. Which rule type are you using? The rule types provide the context variables ... it seems like a SIEM-related alert, but could you validate?

The drop-down list next to the text editor should show all the variables available, and rule-specific variables are always in the `context` object container. If it's not listed, it likely isn't available, in which case you could open a feature request issue in Kibana for it:

(note, the link to the "create new issue" page is below in the GitHub ad box - not sure why it did that kind of formatting on it ...)

> **[Build software better, together](https://github.com/elastic/kibana/issues/new?assignees=&labels=Team:Security%2BSolution%2BPlatform&template=Feature_request.md)**
>
> GitHub is where people build software. More than 73 million people use GitHub to discover, fork, and contribute to over 200 million projects.

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [February 3, 2022, 8:43pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/5 "2022-02-03T20:43:30Z")

</div>

Hey there @bm11100! 👋

I believe you're talking about this [namespace](https://www.elastic.co/guide/en/ecs/master/ecs-data_stream.html#field-data-stream-namespace) field correct?

If so, it'll exist on each individual alert document, so you'll need to loop over the alerts and fetch each one (instead of it being on the root `context` obj itself).

I just tested with the following template and was able to retrieve the `data_stream.namespace` off each alert generated:

```auto
{{#context.alerts}}
  {{data_stream.namespace}}
{{/context.alerts}}

```

Hope this helps! 🙂

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [February 4, 2022, 7:59pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/6 "2022-02-04T19:59:25Z")

</div>

Wizard!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2022, 7:59pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292/7 "2022-03-04T19:59:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
