# Webhook action is sending multiple alerts

**URL:** <https://discuss.elastic.co/t/webhook-action-is-sending-multiple-alerts/336059>\
**Category:** Endpoint Security\
**Tags:** elastic-stack-alerting\
**Created:** [June 15, 2023, 8:35am UTC](https://discuss.elastic.co/t/webhook-action-is-sending-multiple-alerts/336059 "2023-06-15T08:35:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_B](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@Daniel\_B](https://discuss.elastic.co/u/Daniel_B)\
**Post date:** [June 15, 2023, 8:35am UTC](https://discuss.elastic.co/t/webhook-action-is-sending-multiple-alerts/336059/1 "2023-06-15T08:35:12Z")

</div>

Hello there,

I have few webhook actions set for some security rules and I'm including some fields from {{context.alerts}} in the POST request. However I've noticed that when 2 (probably more ) alerts of the same type occurs at the very same time with only few milliseconds apart, the webhook action POST request will include the details of both alerts in a single action. The effect of this issue is that the resolved field will contain merged data from both alerts. Example the result of this field {{#context.alerts}}{{host.name}}{{/contect.alert}} will be 'host1host2' where it should be either host1 or2

More detailed example.  
An alert is raised when windows event id 4624 is generated.  
log - eventId - host - user - alert\_created(hh:mm:ss.ms)  
WindowsForwarding - 4624 - host1 - user1 - 10:00:00.000  
WindowsForwarding - 4624 - host2 - user2 - 10:00:00.002

Result of {{#context.alerts}}{{host.name}}{{/contect.alert}} will be 'host1host2'

Is this expected behavior and is there a way to fix or go around this ?

tks

Daniel

---

<div class="post-metadata">

**Author:** ![vitaliidm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitaliidm/32/101610_2.png) [@vitaliidm](https://discuss.elastic.co/u/vitaliidm)\
**Post date:** [June 15, 2023, 4:57pm UTC](https://discuss.elastic.co/t/webhook-action-is-sending-multiple-alerts/336059/2 "2023-06-15T16:57:09Z")

</div>

Hey @Daniel_B  
Yes, it's an expected behaviour: when action is triggered it contains in its context all alerts that were generated during single rule execution or during specified in action throttle interval.

However, starting from 8.8.0+, it is possible to configure action per alert, so each action will have only one alert in it's context: [Create a detection rule | Elastic Security Solution [8.8] | Elastic](https://www.elastic.co/guide/en/security/current/rules-ui-create.html#rule-notifications)  
In step 2, it's described how to do this.

Hope that helps.  
Thanks, Vitalii

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2023, 4:57pm UTC](https://discuss.elastic.co/t/webhook-action-is-sending-multiple-alerts/336059/3 "2023-07-13T16:57:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
