# Sending the alert JSON details using Webhook Connector

**URL:** <https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223>\
**Category:** SIEM\
**Created:** [April 11, 2024, 2:22pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223 "2024-04-11T14:22:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviran-cato](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@aviran-cato](https://discuss.elastic.co/u/aviran-cato)\
**Post date:** [April 11, 2024, 2:22pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/1 "2024-04-11T14:22:40Z")

</div>

Hi,

I want to use a Webhook connector to send the alert data to an automation platform.  
The issue is that in the Connector action, I can't find a way to send only the JSON alert information. As marked in the image.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/2564ed765583ace0875a590f943cdcf87261989b.jpeg)

when using

```auto
{{#context.alerts}}
{{{.}}}
{{/context.alerts}}

```

It sends out tunes of info containing unuseful things. In this case, I can't know in advance what fields I will have in the alert, so I can't add to the connector variables like `{{user.name}}` because maybe in a different alert, the user name is in a different field.

I want everything related to the alert. The JSON tab in the alert contains just that, but I can't send it via the webhook connector.

Is it possible?

Thanks!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 2:41pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/2 "2024-04-11T14:41:10Z")

</div>

You need to send `{{context}}`, it will have the fields related to the alert and you will need to parse it in your automation platform.

---

<div class="post-metadata">

**Author:** ![aviran-cato](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@aviran-cato](https://discuss.elastic.co/u/aviran-cato)\
**Post date:** [April 11, 2024, 2:47pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/3 "2024-04-11T14:47:48Z")

</div>

Thanks for the quick reply @leandrojmp !

But it seems that it's not working.  
I'm searching for the `fields` in the raw log I received in the automation platform (highlieted in the image) from the Webhook action, and there isn't such field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb30db39c73509a3ae69c5b5fcabd3b7f8ab63fc.jpeg)

It dons't seem to be sent via the webhook when the action is

```auto
{{#context.alerts}}
{{{.}}}
{{/context.alerts}}

```

OR

```auto
{{#context}}
{{{.}}}
{{/context}}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 2:56pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/4 "2024-04-11T14:56:08Z")

</div>

> [@aviran-cato](#):
>
> I'm searching for the `fields` in the raw log I received in the automation platform (highlieted in the image) from the Webhook action, and there isn't such field.

It does not exist in the json, the `fields` is how Kibana shows the fields that are indexed in the alert index.

When an alert is triggered it will be written into an internal index, and this process probably will do some parsing on the fields before indexing.

When using a webhook you have access to a couple of fields like `context`, `rule` and `alert` and you can send those fields to your destination.

---

<div class="post-metadata">

**Author:** ![aviran-cato](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@aviran-cato](https://discuss.elastic.co/u/aviran-cato)\
**Post date:** [April 11, 2024, 3:01pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/5 "2024-04-11T15:01:39Z")

</div>

> [@leandrojmp](#):
>
> alert

I think I understand @leandrojmp, so my only option here is to send everything using `{{#context}}`, and then I will get everything (also things that are no in the JSON tab), or specify the specific fields I want in the action.

and in a case, the rule triggered 2 alerts. Is there a way that I can send them one by one and not as a long JSON containing 2 different alerts?  
and if not, is there a way to send only the first alert?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 3:07pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/6 "2024-04-11T15:07:21Z")

</div>

You need to use `{{context}}` not `{{#context}}`.

If I'm not wrong if the rule triggered 2 alerts at the same time you will get an array with the alerts, not sure if you can change this behavior.

You would need to text it.

---

<div class="post-metadata">

**Author:** ![aviran-cato](https://avatars.discourse-cdn.com/v4/letter/a/cc9497/32.png) [@aviran-cato](https://discuss.elastic.co/u/aviran-cato)\
**Post date:** [April 11, 2024, 3:33pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/7 "2024-04-11T15:33:59Z")

</div>

@leandrojmp, number 1 it's not sending anything, and number 2 it won't let me save the action.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/690c7eca8088a1b2cdd1dec1ce6d79b709aaa86e.png)

Not sending anything:

```auto
{{context}}

```

Not sending anything.

```auto
{{context}}
{{{.}}}
{{context}}

```

Not letting me save.

```auto
{{#context}}
{{{.}}}
{{/context}}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 11, 2024, 3:42pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/8 "2024-04-11T15:42:06Z")

</div>

You need a valid payload that will depend on what your webhook is expecting to receive:

You will need something like this:

```auto
{
    "field_expected_by_your_webhook": "{{context}}"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2024, 3:43pm UTC](https://discuss.elastic.co/t/sending-the-alert-json-details-using-webhook-connector/357223/9 "2024-05-09T15:43:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
