# Using document properties in alert index rule

**URL:** <https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [December 27, 2021, 1:07pm UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972 "2021-12-27T13:07:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tflorac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tflorac/32/42393_2.png) [@tflorac](https://discuss.elastic.co/u/tflorac)\
**Post date:** [December 27, 2021, 1:07pm UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972/1 "2021-12-27T13:07:34Z")

</div>

Hi,  
I'm using Elasticsearch and Kibana 7.16.2, and I'm trying to create custom alerts rules.  
I've created a rule which is using an index action and everything is nearly OK, but my question is: how can I include properties from document data matching my rule conditions?  
For example: if I create a rule on property "system.filesystem.used.pct", how can I include the matching host name in connector document?  
Best regards,  
Thierry

---

<div class="post-metadata">

**Author:** ![gmmorris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmorris/32/72624_2.png) [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Post date:** [January 18, 2022, 9:18am UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972/2 "2022-01-18T09:18:40Z")

</div>

Hi Thierry 👋

It depends on the specific rule type.  
Some rules support individual documents, while others don't, depending on their query strategy (aggregation-based rules, for example, don't have access to the individual documents).

If you need access to individual documents, I suggest using the [ES Query rule type](https://www.elastic.co/guide/en/kibana/master/rule-type-es-query.html), as it provides the [context.hits](https://www.elastic.co/guide/en/kibana/master/rule-type-es-query.html#_add_action_variables_2) variable that gives you access to the individual docs.

Cheers

---

<div class="post-metadata">

**Author:** ![tflorac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tflorac/32/42393_2.png) [@tflorac](https://discuss.elastic.co/u/tflorac)\
**Post date:** [January 21, 2022, 10:39am UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972/3 "2022-01-21T10:39:41Z")

</div>

Hi Gidi,  
Thank you for your reply!  
Actually my alert rule is a standard "Uptime monitor status". Is there a way to get the Elasticsearch query which is used by this rule to use it in a custom ES query rule type?  
Best regards,  
Thierry

---

<div class="post-metadata">

**Author:** ![Dominique\_Clarke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dominique_clarke/32/92223_2.png) [@Dominique\_Clarke](https://discuss.elastic.co/u/Dominique_Clarke)\
**Post date:** [January 30, 2022, 11:50pm UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972/4 "2022-01-30T23:50:40Z")

</div>

Hi @tflorac,

Dominique from Uptime here. For Uptime rules, you have access to a few data points when the alert is triggered, including monitor name, monitor id, monitor URL, monitor type, observer hostname, observer location, and latest error. In the index connector, you can access these variables the same way you can in other connector types, with data interpolation. Here I have pictures an example of all the data points we have available and how you can configure the data within your index connector.

 ![Screen Shot 2022-01-30 at 6.44.54 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5ee315915397dc984621c4b5a81a21b63393381f.png)

I know you mentioned wanting to include the host name for the affected monitor in your documents. Unfortunately, we don't include host and port separately in the alert state, but you can derive that information from the monitor URL. Is that sufficient for your use case? Please let us know if you'd like to see host and port tracked separately in the future.

Thanks!  
Dominique

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2022, 11:50pm UTC](https://discuss.elastic.co/t/using-document-properties-in-alert-index-rule/292972/5 "2022-02-27T23:50:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
