# SIEM Detection alerts - Additional field adding in notification placeholders

**URL:** <https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247>\
**Category:** SIEM\
**Created:** [February 14, 2021, 11:16am UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247 "2021-02-14T11:16:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [February 14, 2021, 11:16am UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247/1 "2021-02-14T11:16:45Z")

</div>

Hi,

How can i add additional fields in alert email action body in detection rules. I am using ELK 7.10.

For eg: Need to include user.name and source.ip field in the rule alert in the body of alert email action.

Rule Logic is: More than 3 authentication failure in 5min from same user.  
I have created this rule using Threshold option in Detections.

Thanks

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [February 15, 2021, 6:23pm UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247/2 "2021-02-15T18:23:40Z")

</div>

@badger  
@Frank_Hassanabad  
Kindly help help with issue mentioned above.

---

<div class="post-metadata">

**Author:** ![jancodenew](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Post date:** [February 18, 2021, 9:19am UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247/3 "2021-02-18T09:19:03Z")

</div>

@Frank_Hassanabad Could you please help to resolve the below mentioned issue.

I am trying to add additional fields in alert email action body in detection rules in ELK 7.10.

For eg: Need to include user.name field in the rule alert in the body of alert email action.

Rule Logic is: More than 3 authentication failure in 5min from same user.  
I am able to create this rule using Threshold and EQL option in Detections and alerts are triggering, but i couldn't find an option to add one additional field in notification placeholder.

Thanks

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 18, 2021, 10:48pm UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247/4 "2021-02-18T22:48:15Z")

</div>

I'm not overall familiar with this part of the features and the code with actions. Was hoping someone else would jump in on this one.

You're on 7.10, but is this feature which was introduce in 7.11 what is currently missing for you to be able to do this?

> <https://github.com/elastic/kibana/pull/85488>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2021, 10:49pm UTC](https://discuss.elastic.co/t/siem-detection-alerts-additional-field-adding-in-notification-placeholders/264247/5 "2021-03-18T22:49:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
