# Rules ( EMail variables Alerts )

**URL:** <https://discuss.elastic.co/t/rules-email-variables-alerts/304811>\
**Category:** Elastic Security\
**Tags:** elastic-stack-alerting\
**Created:** [May 16, 2022, 11:02am UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811 "2022-05-16T11:02:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbemiller](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sbemiller](https://discuss.elastic.co/u/sbemiller)\
**Post date:** [May 16, 2022, 11:02am UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/1 "2022-05-16T11:02:56Z")

</div>

We have email alerts on two rules that stopped working upon the Update to 8.1.3

This example shown below is the Rule that shows the Windows Service Accounts that have failed log ons. I have this working as shown below _and the issue is shown below._

Query is

winlog.event\_id : "4625" and (user.name : svc\* or user.name : _svc or user.name : WIN-_ or user.name : .\* or user.name : _Svc or user.name : Svc_ or user.name : \*$ )

Group by is

user.name and winlog.computer\_name

Threshold

Results aggregated by user.name,winlog.computer\_name \>= 10

Under Actions of the Rule Settings we currently have this set to Email, and the following works:

Rule {{context.rule.name}} generated {{state.signals\_count}} alerts

{{context.rule.description}}

Below is a list of the Failed Logons for the Windows Service Accounts :

{{#context.alerts}}

User Name : {{user.name}}

Source Computer: {{winlog.computer\_name}} .

{{/context.alerts}}

Click the link for investigations;

[Failed Logons](https://10.58.128.40/s/security/app/dashboards#/view/a9bdb710-bb3b-11ec-be77-ff18766d8f98?_g=(filters:!(),refreshInterval:(pause:!f,value:30000),time:(from:now-1h,to:now)))

Result is the following email;

Rule sw\_Windows Service Failed Logons generated 25 alerts Windows Service Accounts ; where the winlog.event\_id : "4625" and ([user.name](http://user.name/) : svc\* or [user.name](http://user.name/) : _svc or [user.name](http://user.name/) : WIN-_ or [user.name](http://user.name/) : .\* or [user.name](http://user.name/) : \*Svc or [user.name](http://user.name/) : \*$ ) AND the Count on Failed logon Attempt is greater than or equal to 10.

Below is a list of the Failed Logons for the Windows Service Accounts :

User Name : UserName$  
Source Computer: _We are getting the computer name here, just removed this for security sake._

User Name : UserNamesvc  
Source Computer: _We are getting the computer name here, just removed this for security sake._

**ISSUE IS**

According to the documentation, the following should work and this did work on the previous release, but the “signal.threshold” loop is not working since the upgrade.

Plus we also need to have the count for each “{{value}}”.

{{#context.alerts}}

{{#signal.threshold\_result.terms}}

{{value}}

{{/signal.threshold\_result.terms}}

{{/context.alerts}}

Link to the documentation that shows the above [Create a detection rule | Elastic Security Solution [8.1] | Elastic](https://www.elastic.co/guide/en/security/8.1/rules-ui-create.html#create-threshold-rule)

If you need more information please let me know

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [May 16, 2022, 4:45pm UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/2 "2022-05-16T16:45:14Z")

</div>

Hi @sbemiller

Can you let me know which version of Kibana you used before the update, and which worked fine?

Additionally, when looking onto generated alert on alert details view: are there any threshold\_result.terms present?  
To look into it, please go to alerts table, and click on View Details icon, near alert name, and look for this property on table tab

 ![Screenshot 2022-05-16 at 17.42.59](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50fa15ebeed9328f1d853b1aea6edb896cf0e4dc.png)

Thanks, Vitalii

---

<div class="post-metadata">

**Author:** ![sbemiller](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sbemiller](https://discuss.elastic.co/u/sbemiller)\
**Post date:** [May 16, 2022, 5:11pm UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/3 "2022-05-16T17:11:48Z")

</div>

> [@vitaliidm](#):
>
> threshold\_result.terms present?

On the threshold\_result.terms, yes they are present. It is showing the field names and values.

The version before the upgrade was 7.17 I am pretty positive. We ran through the minor version updates leading up to 8.x and then made the big update to what was the current version.

---

<div class="post-metadata">

**Author:** ![madi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madi/32/75699_2.png) [@madi](https://discuss.elastic.co/u/madi)\
**Post date:** [May 17, 2022, 3:35am UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/4 "2022-05-17T03:35:04Z")

</div>

@sbemiller It does appear that this functionality no longer works in 8.1.3. The matching terms are now copied to the alert document, however, so you can just reference them directly. In your case, the fields in question are `user.name` and `winlog.computer_name`, which you correctly used in the first (working) template.

Is there a reason you'd like to access them using `signal.threshold_result.terms` instead of the through the source fields?

The count of matching events is available under `kibana.alert.threshold_result.count`.

---

<div class="post-metadata">

**Author:** ![sbemiller](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@sbemiller](https://discuss.elastic.co/u/sbemiller)\
**Post date:** [May 17, 2022, 12:25pm UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/5 "2022-05-17T12:25:38Z")

</div>

Thank you

We needed the count on the Email alert. Thank You for the assistance. I have them working now

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 12:25pm UTC](https://discuss.elastic.co/t/rules-email-variables-alerts/304811/6 "2022-06-14T12:25:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
