# SIEM Detection Rules Alerts Actions

**URL:** https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039
**Category:** Elastic Security
**Created:** [April 23, 2024, 3:09pm UTC](https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039 "2024-04-23T15:09:04Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Sunil\_Iyengar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunil_iyengar/32/123759_2.png) [@Sunil\_Iyengar](https://discuss.elastic.co/u/Sunil_Iyengar)
#### Post date: [April 23, 2024, 3:09pm UTC](https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039/1 "2024-04-23T15:09:04Z")

</div>

Hi All, Is there a way to create an default detection rule alert action endpoint and then have this for all detection rules alerts? i.e. bulk action all enabled rules to send the alerts to our notification endpoint?

Cheers

Sunil

---

<div class="post-metadata">

### Author: ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)
#### Post date: [April 29, 2024, 11:08am UTC](https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039/2 "2024-04-29T11:08:16Z")

</div>

Hello @Sunil_Iyengar

Welcome to the community

Alert action can be setup [Create a detection rule | Elastic Security Solution [8.13] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-notifications)

By notification endpoint, do you mean external web service? If so, this action connector would help: [Webhook connector and action | Kibana Guide [8.13] | Elastic](https://www.elastic.co/guide/en/kibana/8.13/webhook-action-type.html)

This webhook action can be added in bulk to rules: [Manage detection rules | Elastic Security Solution [8.13] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-management.html#edit-rules-settings)

Thanks, Vitalii

---

<div class="post-metadata">

### Author: ![Sunil\_Iyengar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunil_iyengar/32/123759_2.png) [@Sunil\_Iyengar](https://discuss.elastic.co/u/Sunil_Iyengar)
#### Post date: [May 1, 2024, 4:15pm UTC](https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039/3 "2024-05-01T16:15:33Z")

</div>

Hi @vitaliidm, Thanks.

I am trying to send some custom source fields using \<context.alerts\> to the pagerduty actions message.

Elastic adds defaults notification properties as default. How can I change this default properties so I can have a default values filled for the pagerduty context notification object.

Is this done by moustache templating? Where can we change this so it is applied to all elastic rule alerts (elastic and custom rules).

Can provide some examples if that helps.

Kind Regards

Sunil

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 29, 2024, 4:16pm UTC](https://discuss.elastic.co/t/siem-detection-rules-alerts-actions/358039/4 "2024-05-29T16:16:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
