# Issue embedding document fields in my alert

**URL:** https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766
**Category:** Alerting
**Created:** [September 16, 2020, 2:10pm UTC](https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766 "2020-09-16T14:10:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![dev01](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/dev01/32/817_2.png) [@dev01](https://forum.opensearch.org/u/dev01)
#### Post date: [September 16, 2020, 2:10pm UTC](https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766/1 "2020-09-16T14:10:08Z")

</div>

These are my mappings for this index:

```
 "mappings" : {
  "properties" : {
    "@timestamp" : {
      "type" : "date"
    },
    "@version" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "console_ip" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "date" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "destination_ip" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "device_host" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "device_ip" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "dport" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "external_id" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "host" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "incident_name" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "mac_address" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "message" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "severity" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "tags" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "type" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },
    "url" : {
      "type" : "text",
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    }
  }
},

```

Now I try to include some fields on my alert to make it more informative, but I can’t get it to work. Can someone take a look at my syntax and verify or tell me what is wrong with what I am doing…

```
- Description: There are {{ctx.results.hits.0.total.value}} high profile incidents over the last 20 minutes.

```

`[{{#ctx.results.0.hits.hits}}{{_source.title}} {{_source.url}}{{/ctx.results.0.hits.hits}}]`

right now I still get blank in my alert:

```
- Description: There are high profile incidents over the last 20 minutes.

```

[]

---

<div class="post-metadata">

### Author: ![stmx38](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/stmx38/32/4354_2.png) [@stmx38](https://forum.opensearch.org/u/stmx38)
#### Post date: [September 16, 2020, 6:07pm UTC](https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766/2 "2020-09-16T18:07:32Z")

</div>

Hello @dev01, can you please try to follow the following guide: [Kibana email alert - extracting field results - #18 by stmx38](https://forum.opensearch.org/t/kibana-email-alert-extracting-field-results/3606/18)

---

<div class="post-metadata">

### Author: ![dev01](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/dev01/32/817_2.png) [@dev01](https://forum.opensearch.org/u/dev01)
#### Post date: [September 16, 2020, 7:56pm UTC](https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766/3 "2020-09-16T19:56:20Z")

</div>

I saw this guide actually prior to posting here, but will try to follow again.

---

<div class="post-metadata">

### Author: ![dev01](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/dev01/32/817_2.png) [@dev01](https://forum.opensearch.org/u/dev01)
#### Post date: [September 17, 2020, 5:01pm UTC](https://forum.opensearch.org/t/issue-embedding-document-fields-in-my-alert/3766/4 "2020-09-17T17:01:53Z")

</div>

Thank you so much!!! this is a lifesaver guide… wish it was part of official opendistro documentation… would save me hours of waste…

Great guide!
