# Variables in webhook

**URL:** <https://discuss.elastic.co/t/variables-in-webhook/294092>\
**Category:** Elastic Security\
**Tags:** detection-rules\
**Created:** [January 12, 2022, 12:39am UTC](https://discuss.elastic.co/t/variables-in-webhook/294092 "2022-01-12T00:39:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![angelolol](https://avatars.discourse-cdn.com/v4/letter/a/34f0e0/32.png) [@angelolol](https://discuss.elastic.co/u/angelolol)\
**Post date:** [January 12, 2022, 12:39am UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/1 "2022-01-12T00:39:15Z")

</div>

Hi,

I created a rule with a post-action using webhook so how I can get source ip or hostname in the body .

Thanks

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [January 13, 2022, 7:06pm UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/2 "2022-01-13T19:06:14Z")

</div>

Hey there @angelolol, welcome to the community! 👋

We've got some documentation outlining [example action templates](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#placeholder-examples), and just above that section is a [list of available action variables](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-action-variables) you can use as well.

To loop over all the alerts generated within the action context and output each `Source IP` / `Host Name` you could use something like the following:

```auto
Rule {{context.rule.name}} generated {{state.signals_count}} alerts

{{#context.alerts}}
Detection alert for source.ip: {{source.ip}} and host.name: {{host.name}}
{{/context.alerts}}

```

Hope this helps, and welcome again to the Elastic Security community! 🙂

P.S. We've got an [enhancement logged here](https://github.com/elastic/kibana/issues/108940) for adding templating and inline examples/documentation links here to improve UX.

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![angelolol](https://avatars.discourse-cdn.com/v4/letter/a/34f0e0/32.png) [@angelolol](https://discuss.elastic.co/u/angelolol)\
**Post date:** [January 13, 2022, 10:48pm UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/3 "2022-01-13T22:48:09Z")

</div>

Hi @spong, thanks a lot. Thats works for my case but how could I limit the number of responses because when de signal count is greater than one repeat the field.

---

<div class="post-metadata">

**Author:** ![angelolol](https://avatars.discourse-cdn.com/v4/letter/a/34f0e0/32.png) [@angelolol](https://discuss.elastic.co/u/angelolol)\
**Post date:** [January 13, 2022, 10:53pm UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/4 "2022-01-13T22:53:51Z")

</div>

I´ve that json body

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29ea763da3e2c82ce69b263240fe0c647a35c634.png)

and as you said I could get the fields in this case "process.name" but if I have a lot alerts then generate more than one in my destination app, Can I limit a only one?

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e137cfc336ddf3ea2dc21ac3d3b8a964b5acdcd3.png)

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [January 14, 2022, 1:27am UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/5 "2022-01-14T01:27:20Z")

</div>

Hey there @angelolol -- glad it's working for you now 🙂

As for:

> how could I limit the number of responses because when de signal count is greater than one repeat the field

So the action templates support [mustache templating](https://mustache.github.io/mustache.5.html), so you should be able to leverage any of the features outlined there to traverse/limit your results.

That said, each execution or interval that your action fires for can have any number of alerts, and each alert will have it's own unique fields (`source.ip`/`host.name`/etc, hence why you're seeing multiple), so you'll need to take that into account when looping over the alerts.

Let me know if that makes sense or if you have any other questions.

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2022, 1:28am UTC](https://discuss.elastic.co/t/variables-in-webhook/294092/6 "2022-02-11T01:28:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
