# Surfacing Index Field Values in Kibana Alerts

**URL:** <https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [April 7, 2022, 10:12pm UTC](https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903 "2022-04-07T22:12:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Jones](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@Matt\_Jones](https://discuss.elastic.co/u/Matt_Jones)\
**Post date:** [April 7, 2022, 10:12pm UTC](https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903/1 "2022-04-07T22:12:52Z")

</div>

Hi,

I'm setting up Kibana alerts in using a number of connectors (e.g. Email and MS Teams) and alerting on matches against an Elasticsearch query.

Alerts are working fine....However, what I cannot figure out is how to surface field values from the index I'm querying and alerting on.

For example, the default message in the Email Connector is:

Elasticsearch query alert '{{alertName}}' is active:

- Value: {{context.value}}
- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}
- Timestamp: {{context.date}}

The index I'm performing the query against contains firewall event logs, which in the JSON view are like so:

```auto
"_source": {
    "log": {
      "syslog": {
        "priority": 0,
        "severity": {
          "name": "Emergency",
          "code": 0
        },
        "facility": {
        "name": "kernel",
        "code": 0
        }
      }
    },
    "action": "block",
    "app": "Proxy.HTTP"

```

So, what I'd like to pull from the log shown in the snippet above and display in the email message is one or more of those key values, for example the **app** value being **Proxy.HTTP**. The idea being my message would contain:

Elasticsearch query alert '{{alertName}}' is active:

- Value: {{context.value}}
- Conditions Met: {{context.conditions}} over {{params.timeWindowSize}}{{params.timeWindowUnit}}
- Timestamp: {{context.date}}
- **App: Proxy.HTTP**

Online docs at [Elasticsearch query | Kibana Guide [8.1] | Elastic](https://www.elastic.co/guide/en/kibana/current/rule-type-es-query.html) suggests that I can use {{\_source.`<field>`}} to pull values from the queried index, so in my case {{\_source.app}}.

However, this doesn't work and the message is returning a blank value, as shown in the screenshot below:

 ![Elastic_Alert_App_Event](https://us1.discourse-cdn.com/elastic/original/3X/c/e/ce6de860b563af913ceb29179ef63bd812f9efb0.jpeg)

Does someone know how to do this?

Thanks,

Matt

---

<div class="post-metadata">

**Author:** ![Matt\_Jones](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@Matt\_Jones](https://discuss.elastic.co/u/Matt_Jones)\
**Post date:** [April 10, 2022, 8:03pm UTC](https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903/2 "2022-04-10T20:03:15Z")

</div>

I figured it out based on the documentation linked above (needed to read it properly!)

Here's how I got it working to show the fields from the first 'hit':

{{ **#context.hits.0** }}{{\_source.\<your\_field\>}}{{ **/context.hits.0** }}

See the example beneath **context.hits** at [Elasticsearch query | Kibana Guide [7.15] | Elastic](https://www.elastic.co/guide/en/kibana/7.15/rule-type-es-query.html#_add_action_variables_2) where it says:

_"The most recent ES documents that matched the query. Using the [Mustache](https://mustache.github.io/) template array syntax, **you can iterate over these hits to get values from the ES documents into your actions**."_

Hope this helps anyone that comes across this post in the future!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2022, 8:04pm UTC](https://discuss.elastic.co/t/surfacing-index-field-values-in-kibana-alerts/301903/3 "2022-05-08T20:04:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
