# Signal Webhooks send document fields

**URL:** <https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189>\
**Category:** Elastic Security\
**Created:** [July 22, 2020, 12:32pm UTC](https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189 "2020-07-22T12:32:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![The1WhoPrtNocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/the1whoprtnocks/32/72685_2.png) [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Post date:** [July 22, 2020, 12:32pm UTC](https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189/1 "2020-07-22T12:32:12Z")

</div>

Hi,

I have set up a custom signal that is triggering within ELK as i want.  
I would like to use the Webhook function to trigger some ex ternal actions.  
In order to do this though i need to send some of the document fields in the body of the webhook.

I have tried to search on how to do this but can not find any documents/guidance.  
Is this even possible ?

If it is can somone provide me with what should go in the moustash parameter to send @timestamp for example?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [August 13, 2020, 10:16pm UTC](https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189/2 "2020-08-13T22:16:41Z")

</div>

Hey there @The1WhoPrtNocks, welcome to the community and thanks for posting! Looks like this one slipped through the cracks, but let's see what we can do to answer your questions 🙂

So for referencing field/values in your Webhook Action, there is currently access to the following [notification placeholder fields](https://www.elastic.co/guide/en/siem/guide/7.8/rules-ui-create.html#rule-action-variables). So you don't have to reference the docs each time, there is a shortcut within the UI to view the available fields and for inserting them into your action message. As seen below, if you click the icon to the top right of the action text area, you'll see a list of all available fields:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/4/0482b23c443261ce662e0e821ddabaf8824a7ebf.png)

Currently only the `rule` fields, `signals_count` and `results_link` are exposed, so you won't have access to `@timestamp`, but we're looking to include access to the underlying signal fields in a future release. You can follow the below two issues for tracking this functionality.

> <https://github.com/elastic/kibana/issues/66587>
>
> Describe the feature:
> As a security analyst often use my mobile device to keep an eye on high priority and critical alerts...

  

> <https://github.com/elastic/kibana/issues/68438>
>
> Problem
> When creating a rule action, users are provided with a list of variables that they can use to reference alert-specific data:
> For...

Hope this helps! And thanks again for posting 🙂

-Garrett

---

<div class="post-metadata">

**Author:** ![The1WhoPrtNocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/the1whoprtnocks/32/72685_2.png) [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Post date:** [August 14, 2020, 5:11am UTC](https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189/3 "2020-08-14T05:11:00Z")

</div>

HI @spong,

Thank you for the detailed response and for posting to the issues.  
I have a workaround functioning atm where i post to an API with a certain body and based of the body it triggers an Elasticsearch API call to get me the details i need.

So not a major issue, but would be "cleaner" once the above is implemented,

Luke

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:07am UTC](https://discuss.elastic.co/t/signal-webhooks-send-document-fields/242189/4 "2022-11-04T08:07:15Z")

</div>


