# The original document/raw event can't be found

**URL:** <https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476>\
**Category:** Elastic Security\
**Created:** [July 25, 2025, 7:06pm UTC](https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476 "2025-07-25T19:06:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sergie](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Sergie](https://discuss.elastic.co/u/Sergie)\
**Post date:** [July 25, 2025, 7:06pm UTC](https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476/1 "2025-07-25T19:06:49Z")

</div>

I am seeing a similar situation as mentioned in this below post  
[Little help understanding a document query issue](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198):

I have this default elastic security rule enabled i.e. **High Number of Process and/or Service Termination**. Which is a threshold rule, definition for which is shown in below screenshot

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d76f33081777ccfd3530beccd6a33fcdf45d2028.png)

This rule is generating me an alert and the alert payload consists of this below field

```auto
"kibana.alert.ancestors": [
      {
        "depth": 0,
        "index": "endgame-*,logs-endpoint.events.process-*,logs-system.security*,logs-windows.forwarded*,logs-windows.sysmon_operational-*,winlogbeat-*",
        "id": "081c1490-1968-5ffe-a639-6e6ff2c10ad3",
        "type": "event"
      }
    ]

```

When I am trying to run a search against these indices and trying to find the document using the id, I can't find the actual doc.

However for the alerts generated by other Elastic **Custom Query** rules, I am able to track back the original document by querying it against the values of kibana.alert.ancestors.index and kibana.alert.ancestors.id fields.

So is this the expected behavior with threshold rules vs the custom query rules.  
Another observation for the threshold rule is that the alert payload does not have **agent.id** field in it. Is this default behavior for this or is this something that needs to be added as a functionality from Elastic side.

Kindly help/explain?

---

<div class="post-metadata">

**Author:** ![Sergie](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Sergie](https://discuss.elastic.co/u/Sergie)\
**Post date:** [July 28, 2025, 10:55am UTC](https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476/2 "2025-07-28T10:55:09Z")

</div>

Hi @stephenb, @Mark_Hopkin , can you please help ?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 28, 2025, 11:30am UTC](https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476/3 "2025-07-28T11:30:38Z")

</div>

Hello @Sergie

It seems you have below similar query , right?

> <https://github.com/elastic/kibana/issues/196262>
>
> \*\*Describe the bug:\*\*
> 
> \- Incorrect message displayed on the response fly-out wi…th added response actions and missing \`agent.id\` field
> 
> 
> \*\*Build Details:\*\*
> 
> 
> VERSION: 9.0.0 PR shared by @tomsonpl 
> BUILD: 79377
> COMMIT: 3a77c531cbb558bd84332a9ca161291ecd997efc
> 
> 
> \*\*Login Credentials\*\* 
> 
> \- https://p.elstc.co/paste/YcVH765T#bsK1zb5hP3aDjozGr1+jx6XRj+GzTd-/vsa4LmghlDH
> 
> \*\*Preconditions\*\*
> \- Kibana should be running.
> \- Create a threshold rule with below configuration
> !\[Image\](https://github.com/user-attachments/assets/b9ebc4cb-0a8f-4b2a-a477-d75f2bac838c)
> 
> \- Generate the alert from this rule by executing \`ls\` command on Linux endpoint
> 
> 
> \*\*Steps to Reproduce\*\*
> \- Click on the alerts details icon
> \- Scroll down and click on the Responses fly-out button
> \- Observe that Incorrect message displayed on the response fly-out with added response actions and missing \`agent.id\` field
> 
> 
> \*\*Actual result\*\*
> 
> \- Incorrect message displayed on the response fly-out with added response actions and missing \`agent.id\` field
> 
> \*\*Expected Result\*\*
> 
> \- Correct message should be displayed for the response fly-out with add response actions and missing \`agent.id\` field
> 
> 
> \*\*Screen-shot\*\*
> 
> !\[Image\](https://github.com/user-attachments/assets/588e66a0-64a9-4331-8a2b-e2d35e8e51a3)
> 
> 
> \*\*Exported Rule\*\*
> 
> \[rules\_export.ndjson.zip\](https://github.com/user-attachments/files/17375758/rules\_export.ndjson.zip)
> 
> \*\*Logs\*\*
> 
> \- N/A
> 
> \## AC
> 
> \- \[ \] Display proper messaging when there are no results from a rule execution containing automated response actions. cc: @caitlinbetz

Thanks!!

---

<div class="post-metadata">

**Author:** ![Sergie](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@Sergie](https://discuss.elastic.co/u/Sergie)\
**Post date:** [July 30, 2025, 5:58am UTC](https://discuss.elastic.co/t/the-original-document-raw-event-cant-be-found/380476/4 "2025-07-30T05:58:08Z")

</div>

Hi @Tortoise Yes (because agent.id field is missing from the alert payload) and No (Because I don't have response actions and hence no message) 🙂

For my use case I am not able to track back to the original docs which generated this alert using this

```auto
"kibana.alert.ancestors": [
      {
        "depth": 0,
        "index": "endgame-*,logs-endpoint.events.process-*,logs-system.security*,logs-windows.forwarded*,logs-windows.sysmon_operational-*,winlogbeat-*",
        "id": "081c1490-1968-5ffe-a639-6e6ff2c10ad3",
        "type": "event"
      }
    ]

```

Also, agent.id field as said in the previous comment is missing from these threshold kind of alerts, is it a valid behavior or this is a enhancement which can be done?
