# Accessing payload in nested object with groovy

**URL:** <https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 19, 2016, 2:54pm UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452 "2016-05-19T14:54:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![peppetrick](https://avatars.discourse-cdn.com/v4/letter/p/3d9bf3/32.png) [@peppetrick](https://discuss.elastic.co/u/peppetrick)\
**Post date:** [May 19, 2016, 2:54pm UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452/1 "2016-05-19T14:54:25Z")

</div>

Hi all

I have a problem with inline script for condition in a watch.

The payload response is like the one below, and I have to calculate the condition on the ratio

KO.dco\_count/hits.total

I wrote

"condition" : {  
"script" : {  
"inline" : "return ctx.payload.aggregations.2.buckets.KO.doc\_count/ctx.payload.hits.total \> threshold",  
"params" : {  
"threshold" : 0.1  
}  
}  
}

but it gives me error on "ctx.payload.aggregations.2.buckets.KO.doc\_count"

* * *

payload

{  
"responses": [{  
"took": 34,  
"timed\_out": false,  
"\_shards": {  
"total": 20,  
"successful": 20,  
"failed": 0  
},  
"hits": {  
"total": 5434,  
"max\_score": 0.0,  
"hits": []  
},  
"aggregations": {  
"2": {  
"buckets": {  
"OK": {  
"doc\_count": 5343  
},  
"KO": {  
"doc\_count": 91  
}  
}  
}  
}  
}]  
}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 20, 2016, 7:25am UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452/2 "2016-05-20T07:25:46Z")

</div>

Hey,

can you try and change the name of the aggregation to be not a number? Looks as if the `2`in `ctx.payload.aggregations.2.buckets.KO.doc_count` is recognized as an array element and not a string.

--Alex

---

<div class="post-metadata">

**Author:** ![peppetrick](https://avatars.discourse-cdn.com/v4/letter/p/3d9bf3/32.png) [@peppetrick](https://discuss.elastic.co/u/peppetrick)\
**Post date:** [May 20, 2016, 9:21am UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452/3 "2016-05-20T09:21:13Z")

</div>

Hi Alexander

The json does not depend on me, it depends on elasticsearch response.

Giuseppe

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 20, 2016, 2:00pm UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452/4 "2016-05-20T14:00:26Z")

</div>

Hey,

Can you please paste your full watch. The name of the aggregation bucket is defined by you as part of the request, so you have full control over it. You can rename it from `2` to sth like `status` and try again.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:45pm UTC](https://discuss.elastic.co/t/accessing-payload-in-nested-object-with-groovy/50452/5 "2017-07-06T13:45:32Z")

</div>


