# Combining Painless and Mustache

**URL:** <https://discuss.elastic.co/t/combining-painless-and-mustache/296209>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [February 3, 2022, 3:12pm UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209 "2022-02-03T15:12:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Navanit\_dubey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navanit_dubey/32/100321_2.png) [@Navanit\_dubey](https://discuss.elastic.co/u/Navanit_dubey)\
**Post date:** [February 3, 2022, 3:12pm UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209/1 "2022-02-03T15:12:55Z")

</div>

Can I make a template using both the painless script and mustache.  
So as to make a search query where the search is done by mustache template and its done insde the painless language query.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 8, 2022, 2:04pm UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209/2 "2022-02-08T14:04:27Z")

</div>

Can you share an example of what you are trying to achieve with a sample document and query? I have a hard time to imagine the use-case 🙂

---

<div class="post-metadata">

**Author:** ![michaelv](https://avatars.discourse-cdn.com/v4/letter/m/90db22/32.png) [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Post date:** [February 10, 2022, 4:46am UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209/3 "2022-02-10T04:46:50Z")

</div>

I thought mustache is used for display purposes only. It has no effect on a search.  
The aggregation used gives a multi-level aggregation results so it outputs some result

```auto
    "send_email": {
      "email": {
        "profile": "standard",
        "from": "example@example.com",
        "to": [
          "example@example.com"
        ],
        "subject": "Failed Login Exceeding",
        "body": {
          "text": """Failed Login Exceeding
{{#ctx.payload.aggregations.server_name.buckets}}
{{key.host_name}}
{{#events.buckets}}
    Time: {{key_as_string}}
    {{#user_name.buckets}}
          {{key}} Count={{doc_count}}
    {{/user_name.buckets}}
{{/events.buckets}}

{{/ctx.payload.aggregations.server_name.buckets}}"""
        }
      }
    }

```

Output of email body is like this

```auto
           "body": {
              "text": "Failed Login Exceeding\nelk1\n Time: 2022-02-10T04:42:00.000Z\n guest Count=3\n Time: 2022-02-10T04:43:00.000Z\n guest Count=2\n\n"
            }

```

Looks like

```auto
Failed Login Exceeding
    elk1    
        Time: 2022-02-10T04:42:00.000Z
             guest Count=3
        Time: 2022-02-10T04:43:00.000Z
             guest Count=2

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 17, 2022, 8:44am UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209/4 "2022-02-17T08:44:08Z")

</div>

Yes, this is true, if you need to modify the data structure you want to use in the mustache template, you can use a script to do so, that should work in this case, unless I am missing a requirement.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2022, 8:45am UTC](https://discuss.elastic.co/t/combining-painless-and-mustache/296209/5 "2022-03-17T08:45:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
