# Problem adding document field to alert's webhook body

**URL:** <https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [November 13, 2022, 10:12am UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794 "2022-11-13T10:12:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![TXBigDawg1836](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@TXBigDawg1836](https://discuss.elastic.co/u/TXBigDawg1836)\
**Post date:** [November 13, 2022, 10:12am UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794/1 "2022-11-13T10:12:51Z")

</div>

New to ES and having an issue with adding details in the body of a webhook. I am wanting to add the field information (ex: city) so that it will be included in the alert details. I have tried adding "City": "{{\_source.city}}" but returned no details when the alert was generated.  
I have attempted this in both a Elastic Query and a Metric-based alerts.  
Thanks in advance for the help!

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [November 14, 2022, 1:19pm UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794/2 "2022-11-14T13:19:23Z")

</div>

Can you provide your complete mustache template? I'm wondering if you forgot a mustache section for `{{#context.hits}}`, like this:

```auto
{{#context.hits}}
city: {{_source.city}}
{{/context.hits}}

```

More info here: [Elasticsearch query | Kibana Guide [8.5] | Elastic](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html#_add_action_variables_2)

Also, if you want to see all the context variables available, to see what's available, as a nested JSON string, use the following in your template: `{{.}}`

---

<div class="post-metadata">

**Author:** ![TXBigDawg1836](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@TXBigDawg1836](https://discuss.elastic.co/u/TXBigDawg1836)\
**Post date:** [November 14, 2022, 2:38pm UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794/3 "2022-11-14T14:38:43Z")

</div>

This is what I'm currently using:

{  
"elasticsearch\_query\_alert": "{{alertName}}",  
"value": "{{context.value}}",  
"conditions\_met": "{{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}",  
"timestamp": "{{context.date}}",  
"environment": "Minotaur",  
"status": "[Alerting]",  
"provider\_city": "{{alert.actionGroupName}}",  
"Provider-City": "{{#context.hits}}{{\_source.Provider-City}}{{/context.hits}}"

}

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [November 14, 2022, 4:23pm UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794/4 "2022-11-14T16:23:49Z")

</div>

I was a little worried about the `-` in `Provider-City`, but a test at [https://codepen.io/adrianroworth/pen/RgxmYM](https://codepen.io/adrianroworth/pen/RgxmYM) (generic online mustache tester) shows that this should work.

Could you try the following:

- create a server log action and use the same mustache template for the message body - it will come out a bit scrambled (we convert n/l to semicolon, kinda thing), but should show what the expansion is.

- change that server log action to just be `{{.}}` so we can see a list of all the variables available.

One last thing, was this for a recovered action, or active alert? Recovered actions typically do not have as many mustache variables available, and I don't believe any rules populate `context.hits` in recovery actions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2022, 4:24pm UTC](https://discuss.elastic.co/t/problem-adding-document-field-to-alerts-webhook-body/318794/5 "2022-12-12T16:24:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
