# Problem with threshold alert and index connector

**URL:** <https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [April 17, 2024, 6:12am UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564 "2024-04-17T06:12:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bot\_aro](https://avatars.discourse-cdn.com/v4/letter/b/e56c9b/32.png) [@bot\_aro](https://discuss.elastic.co/u/bot_aro)\
**Post date:** [April 17, 2024, 6:12am UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/1 "2024-04-17T06:12:05Z")

</div>

Good afternoon, I am facing a problem with kibana alerts. I am using threshold alert with index connector. I'm trying to write a json like this

```auto
{
  "message": """{{{#context.alerts}}}
host.name: {{{host.name}}}
{{/context.alerts}}"""
}

```

But it ends up writing this `host.name:` to the index.  
As I understand it, this is because in the original json host.name is not written as an object, but as on the screenshot. How to make it to be recorded as event.kind? Has anyone encountered this? Is there a solution for this?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69d65d6cc6d6ecada8fd1b948dc230b88a759b91.png)

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [April 30, 2024, 1:17pm UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/2 "2024-04-30T13:17:40Z")

</div>

I don't understand your question. Your template is creating a string value for the `message` key, but you want to write a full object instead?

---

<div class="post-metadata">

**Author:** ![bot\_aro](https://avatars.discourse-cdn.com/v4/letter/b/e56c9b/32.png) [@bot\_aro](https://discuss.elastic.co/u/bot_aro)\
**Post date:** [May 2, 2024, 1:12pm UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/3 "2024-05-02T13:12:16Z")

</div>

Yes, because when you address this field, it tries to fail like this

```auto
{ 
"source": {
      "ip": "8.8.8.8.8"
    }
}

```

And the actual format there is like this

```auto
{
 "source.ip": "8.8.8.8.8"
}

```

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [May 2, 2024, 1:31pm UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/4 "2024-05-02T13:31:51Z")

</div>

have you tried escaping the dot as in `{{{host\.name}}}` (I haven't tested this)

---

<div class="post-metadata">

**Author:** ![bot\_aro](https://avatars.discourse-cdn.com/v4/letter/b/e56c9b/32.png) [@bot\_aro](https://discuss.elastic.co/u/bot_aro)\
**Post date:** [May 2, 2024, 1:41pm UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/5 "2024-05-02T13:41:01Z")

</div>

Yeah, unfortunately that didn't work

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [May 2, 2024, 1:49pm UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/6 "2024-05-02T13:49:44Z")

</div>

There's [an issue on the topic,](https://github.com/elastic/kibana/issues/127748) but after reading it I'm not fully sure if it was fixed on [this PR](https://github.com/elastic/kibana/pull/143703), released at 8.6. Yet worth checking the comments and workarounds mentioned there.

Which version are you?

---

<div class="post-metadata">

**Author:** ![bot\_aro](https://avatars.discourse-cdn.com/v4/letter/b/e56c9b/32.png) [@bot\_aro](https://discuss.elastic.co/u/bot_aro)\
**Post date:** [May 4, 2024, 1:27am UTC](https://discuss.elastic.co/t/problem-with-threshold-alert-and-index-connector/357564/7 "2024-05-04T01:27:54Z")

</div>

I'm on version 7.17.18. I've tested with latest version of elasticsearch and it works. Thank you!
