# Elastic wacher painlless script and mustache template

**URL:** <https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 25, 2020, 3:04am UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755 "2020-02-25T03:04:09Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [February 25, 2020, 3:04am UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/1 "2020-02-25T03:04:09Z")

</div>

hi

I have created following watcher by following [https://cinhtau.net/2017/06/19/es-nodes-mem\_watch/](https://cinhtau.net/2017/06/19/es-nodes-mem_watch/) I had to edit few stuff to make it work for ELK 7

```
{
  "trigger": {
    "schedule": {
      "interval": "6h"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          ".monitoring-es-7*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": [
                {
                  "range": {
                    "timestamp": {
                      "gte": "now-2m",
                      "lte": "now"
                    }
                  }
                }
              ]
            }
          },
          "aggs": {
            "minutes": {
              "date_histogram": {
                "field": "timestamp",
                "calendar_interval": "1h"
              },
              "aggs": {
                "nodes": {
                  "terms": {
                    "field": "source_node.name"
                  },
                  "aggs": {
                    "memory": {
                      "max": {
                        "field": "node_stats.jvm.mem.heap_used_percent"
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "return ctx.payload.aggregations.minutes.buckets.stream().anyMatch(b -> b.nodes.buckets.stream().anyMatch(x -> x.memory.value > 50))",
      "lang": "painless"
    }
  },
  "actions": {
    "send_mem_warning": {
      "transform": {
        "script": {
          "source": "def latest = ctx.payload.aggregations.minutes.buckets[-1]; return latest.nodes.buckets.stream().filter(item -> item.memory.value >= ctx.metadata.threshold).collect(Collectors.toList());",
          "lang": "painless"
        }
      },
      "email": {
        "profile": "standard",
        "from": "XXXXXXXXX",
        "reply_to": [
          "XXXXXXXX"
        ],
        "to": [
          "XXXXXXXXXX"
        ],
        "subject": "Watcher Notification - HIGH MEMORY USAGE",
        "body": {
          "html": {
            "id": "mem-watch-warning"
          }
        }
      }
    }
  },
  "metadata": {
    "threshold": 50
  }
}

```

I added mustache template as per that doc. When i execute the watcher i get following output (from log)

```
 "email" : {
            "account" : "exchange_account",
            "message" : {
              "id" : "send_mem_warning_mem-watch-mustache_1c138b80-c812-46ec-b6c0-449aa6536765-2020-02-25T03:00:53.683535Z",
              "from" : "XXXXXXXXXXXXXX",
              "reply_to" : [
                "XXXXXXXXX"
              ],
              "sent_date" : "2020-02-25T03:00:54.338305Z",
              "to" : [
                "XXXXXXXXX"
              ],
              "subject" : "Watcher Notification - HIGH MEMORY USAGE",
              "body" : {
                "html" : "mem-watch-warning"
              }
            }
          }
        }

```

my email has only following.

mem-watch-warning

So some where in forum i read painelss and mustache dont work together. But i lost that thread. So is that true ? if yes how do i fix my issue ?

---

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [February 25, 2020, 5:04pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/2 "2020-02-25T17:04:41Z")

</div>

any input ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 12, 2020, 10:18am UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/3 "2020-03-12T10:18:07Z")

</div>

Can you explain what you mean with 'do not work together' - it's basically an either-or relationship. Either you use a painless script, for example for the script condition, or you use mustache, if you want to format text, but not both.

Hope that makes sense, otherwise please add somemore detail to your question, what you are referring to.

Thanks!

---

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [March 12, 2020, 2:52pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/4 "2020-03-12T14:52:18Z")

</div>

Alexander,

I ended up opening a case and i was told this is a known bug.

> <https://github.com/elastic/elasticsearch/issues/40212>
>
> Elasticsearch version (bin/elasticsearch --version): 6.5.0
> Plugins installed: none
> JVM version (java -version):
> java version "11" 2018-09-25
> Java(TM) SE Runtime Environment 18.9 (build 11+28)
> Java HotSpot(TM) 64-Bit...

Raj

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 12, 2020, 4:57pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/5 "2020-03-12T16:57:42Z")

</div>

I just opened a PR to fix this, let's see if it gets in, you can follow it at [https://github.com/elastic/elasticsearch/pull/53497](https://github.com/elastic/elasticsearch/pull/53497)

---

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [March 19, 2020, 5:32pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/6 "2020-03-19T17:32:53Z")

</div>

just curious how will i know this is fixed and released in what version ?

---

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [March 19, 2020, 6:15pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/7 "2020-03-19T18:15:33Z")

</div>

i found it.

[spinscale](https://github.com/spinscale) added the [v7.6.2](https://github.com/elastic/elasticsearch/labels/v7.6.2) label [2 days ago](https://github.com/elastic/elasticsearch/pull/53497#event-3136571526)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2020, 6:15pm UTC](https://discuss.elastic.co/t/elastic-wacher-painlless-script-and-mustache-template/220755/8 "2020-04-16T18:15:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
