# Customize watch and/or watch\_history index template

**URL:** <https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 2, 2015, 3:39pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539 "2015-09-02T15:39:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aochsner](https://avatars.discourse-cdn.com/v4/letter/a/97f17d/32.png) [@aochsner](https://discuss.elastic.co/u/aochsner)\
**Post date:** [September 2, 2015, 3:39pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/1 "2015-09-02T15:39:31Z")

</div>

Is there a reason why these templates have an order set to Integer.MAX? I'd like to customize these a little bit. Specifically would like to index certain fields in the input.payload so that I can later search on them or set some fields to doc\_values.

Was hoping I could just add a higher order template for this but doesn't seem that this will be possible. Are there any other alternatives?

---

<div class="post-metadata">

**Author:** ![uboness](https://avatars.discourse-cdn.com/v4/letter/u/96bed5/32.png) [@uboness](https://discuss.elastic.co/u/uboness)\
**Post date:** [September 2, 2015, 6:33pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/2 "2015-09-02T18:33:40Z")

</div>

The reason for hardening some parts of the watch history schema is to prevent conflicts between different watches. Take the input payload as an example. A payload can be anything, and can change from one watch execution to another... even 2 executions of the same watch... think search inputs yielding 2 different search results, and it gets even worse with more generic inputs like `http` and `simple`. For this reason we disable the mappings for the input payload. There's currently no alternative. What we could consider for future feature is to throw the input as text into a single catch all field, say `payload_data` and make that searchable. Would that work for you?

---

<div class="post-metadata">

**Author:** ![aochsner](https://avatars.discourse-cdn.com/v4/letter/a/97f17d/32.png) [@aochsner](https://discuss.elastic.co/u/aochsner)\
**Post date:** [September 4, 2015, 3:30pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/3 "2015-09-04T15:30:00Z")

</div>

I see your point. Your proposal could work I think for the payload scenario.

What about metadata? That's really my data structures, so I'd like to be able to override the mappings (make them not\_analyzed and/or use doc\_values for example). Is there way to do that (via dynamic\_templates of a lower ordered template maybe?)?

Thanks

---

<div class="post-metadata">

**Author:** ![uboness](https://avatars.discourse-cdn.com/v4/letter/u/96bed5/32.png) [@uboness](https://discuss.elastic.co/u/uboness)\
**Post date:** [September 4, 2015, 7:49pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/4 "2015-09-04T19:49:32Z")

</div>

yea... customizing the metadata mapping totally makes sense. I'll add that to the roadmap. Thx for the suggestion!

---

<div class="post-metadata">

**Author:** ![prashant\_sharma](https://avatars.discourse-cdn.com/v4/letter/p/ea666f/32.png) [@prashant\_sharma](https://discuss.elastic.co/u/prashant_sharma)\
**Post date:** [December 2, 2015, 9:34pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/5 "2015-12-02T21:34:26Z")

</div>

I have having the watcher mapping issue for the same version of watcher- 1.0.1, ES version is 1.5.2

In one server the Watcher Mapping the Strings are not analysed whereas in the other one they are. So below Mapping exists in one instance and not another. These two ES instances are running independently. This behavior is causing our term based queries to not return the correct results.  
What could be causing this and what actions can be taken to ensure that we see consistent mapping in production when we go live?

"watch": {  
"dynamic\_date\_formats": [  
"date\_optional\_time"  
],  
"dynamic": "strict",  
"dynamic\_templates": [{  
"strings": {  
"mapping": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"match\_mapping\_type": "string",  
"match": "s\*"  
}  
},

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/customize-watch-and-or-watch-history-index-template/28539/6 "2017-07-06T13:47:59Z")

</div>


