# Truncate a Mustache variable in an Alerting rule action (e.g. limit a long text field to N words)?

**URL:** <https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [August 7, 2026, 8:14am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290 "2026-08-07T08:14:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 7, 2026, 8:14am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290/1 "2026-08-07T08:14:37Z")

</div>

Hello Team,

**Kibana version:** 9.x

We have a rule (Elasticsearch query rule type) that runs every few minutes against an index of banking transaction logs. When it matches, the action is an Index connector that writes a summary record into a separate `payment` index. The action's document body uses a Mustache template that loops over `context.hits` and builds one delimited "row" per matched document, e.g.:

```auto
{
  "message": "{{#context.hits}}{{#_source}}{{#FormatDate}}{{{@timestamp}}};Europe/London{{/FormatDate}},{{TransactionContext.SourceSystem}},{{TransactionContext.TargetSystem}},{{ErrorContext.ErrorDescription}}|{{/_source}}{{/context.hits}}"
}

```

Sample log:

```auto
{
  "@timestamp": "2026-08-07T07:00:00.000Z",
  "TransactionContext": {
    "SourceSystem": "PaymentGateway",
    "TargetSystem": "CoreBanking"
  },
  "ErrorContext": {
    "ErrorDescription": "java.lang.RuntimeException: Connection timed out, retrying failed at com.bank.service.PaymentService.process(PaymentService.java:142), caused by java.net.SocketTimeoutException: Read timed out at java.base/sun.nio.ch.NioSocketImpl.timedRead(NioSocketImpl.java:283), at java.base/sun.nio.ch.NioSocketImpl.implRead(NioSocketImpl.java:309) ... [continues for several hundred words]"
  }
}

```

## The problem

`ErrorContext.ErrorDescription` (exception message) can run into hundreds of words. We only want the first ~50 words of it to land in the `payment` index record - everything else in the row should render as-is, untouched.

Is an ingest pipeline the only way to fix this issue? I was looking for any Mustache function that can handle this at runtime.

Will the below GitHub issue fix this in future? [elastic/kibana#230634 — provide mustache lambda to substitute strings](https://github.com/elastic/kibana/issues/230634)

Thanks!!

---

<div class="post-metadata">

**Author:** ![viktoriyanavrotskaya](https://avatars.discourse-cdn.com/v4/letter/v/59ef9b/32.png) [@viktoriyanavrotskaya](https://discuss.elastic.co/u/viktoriyanavrotskaya)\
**Post date:** [August 10, 2026, 9:41am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290/2 "2026-08-10T09:41:56Z")

</div>

Mustache in Kibana is pretty limited here, so I don’t think there’s a built-in way to truncate a field by word count at render time. An ingest [website](https://tropical-casino.com/) pipeline is probably the cleanest option for now. The lambda issue could help if implemented, but I wouldn’t rely on it until it’s actually available in your Kibana version.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 13, 2026, 5:23am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290/3 "2026-08-13T05:23:43Z")

</div>

Hello,

Did not found any way to truncate the message & only current way was to use ingest pipeline.

Thanks!!
