# Two questions about Kibana alarms

**URL:** <https://discuss.elastic.co/t/two-questions-about-kibana-alarms/306289>\
**Category:** Kibana\
**Created:** [June 3, 2022, 6:22am UTC](https://discuss.elastic.co/t/two-questions-about-kibana-alarms/306289 "2022-06-03T06:22:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fgjensen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fgjensen/32/62320_2.png) [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Post date:** [June 3, 2022, 6:22am UTC](https://discuss.elastic.co/t/two-questions-about-kibana-alarms/306289/1 "2022-06-03T06:22:34Z")

</div>

Hi

Could you, please, help with two issues about Kibana alarms?

1. The tags I can add to a rule when creating a rule from the Rules and Connectors page seem to be integrated with the tags I can create from the Kibana Tags menu? The tags from Kibana tags can be attached to Kibana objects, so I expect tags created while editing a rule also was create in Kibana tags and visa versa.

2. How do I get access to terms in the documents returned to the rule by an Elasticsearch query, so I can write the values out in the message? I would like to write like this in the message Log level: {{context.log.level}} as an example assuming the query returns one document. It would also be useful to be able to iterate over the returned documents.

Best regards  
Flemming

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [June 29, 2022, 1:15pm UTC](https://discuss.elastic.co/t/two-questions-about-kibana-alarms/306289/2 "2022-06-29T13:15:11Z")

</div>

1. The [rule tags](https://www.elastic.co/guide/en/kibana/8.2/create-and-manage-rules.html#defining-rules-general-details) are not related with the [Kibana tags](https://www.elastic.co/guide/en/kibana/8.3/managing-tags.html), as far as I know

2. Check the `context.hits` variable and all the rest of the [variables available](https://www.elastic.co/guide/en/kibana/8.2/rule-type-es-query.html#_add_action_variables_2) for that rule type. You have there an example on how to iterate over hits using the Mustache templating system

hope it helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2022, 1:15pm UTC](https://discuss.elastic.co/t/two-questions-about-kibana-alarms/306289/3 "2022-07-27T13:15:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
