# Elasticsearch Watcher Painless error when trying to send email

**URL:** <https://discuss.elastic.co/t/elasticsearch-watcher-painless-error-when-trying-to-send-email/304614>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [May 12, 2022, 5:11pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-painless-error-when-trying-to-send-email/304614 "2022-05-12T17:11:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elasti\_Newbie](https://avatars.discourse-cdn.com/v4/letter/e/2bfe46/32.png) [@Elasti\_Newbie](https://discuss.elastic.co/u/Elasti_Newbie)\
**Post date:** [May 12, 2022, 5:11pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-painless-error-when-trying-to-send-email/304614/1 "2022-05-12T17:11:12Z")

</div>

Hi,

I really need help at this point, I'm trying to set up a watcher that triggers an email alert whenever a file is changed (file integrity).

The issue I'm having is trying to use a for loop on the script intended to retrieve the name of the files to add them to the email body.

This works perfectly fine, and I'm able to access each element in the array by manually changing `ctx.payload.hits.hits[0]`:

```auto
  "actions": {
    "send_email": {
      "email": {
        "profile": "standard",
        "to": [
          "someone@domain.com"
        ],
        "subject": "DR ELK:: File Integrity Monitoring",
        "body": {
          "text": """Important files below have been modified: \r\r {{ctx.payload.agents_hostname}} => {{ctx.payload.files}} => {{ctx.payload.event}}"""
        }
      }
    }
  },
"transform": {
	"script": {
		"source": """
			ctx.payload.transform = ['agents_hostname' : ctx.payload.hits.hits[0]._source.agent.hostname, 'files' : ctx.payload.hits.hits[0]._source.file.path, 'event' : ctx.payload.hits.hits[0]._source.event.action]; return ctx.payload.transform""",
		"lang": "painless"
	}
},

```

But if I try with a FOR / WHILE loop to automatically iterate through the array values like this:

```auto
"transform" :{
	"script": {
      "source": """
			for(int j = 0; j < ctx.payload.hits.total; j++) { 
				ctx.payload.transform = ['agents_hostname' : ctx.payload.hits.hits[j]._source.agent.hostname,
				'files' : ctx.payload.hits.hits[j]._source.file.path,
				'event' : ctx.payload.hits.hits[j]._source.event.action];
			}, 
			return ctx.payload.transform""",
		"lang": "painless"
	}
},

```

Then I get a **"Compile Error"** when trying to save/simulate.

I've been stuck at this for a few days now, read a lot and cannot get it to work.

Thanks in advance!

Regards!

---

<div class="post-metadata">

**Author:** ![Elasti\_Newbie](https://avatars.discourse-cdn.com/v4/letter/e/2bfe46/32.png) [@Elasti\_Newbie](https://discuss.elastic.co/u/Elasti_Newbie)\
**Post date:** [May 12, 2022, 8:56pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-painless-error-when-trying-to-send-email/304614/2 "2022-05-12T20:56:27Z")

</div>

I was able to find the error, the comma after closing the FOR loop shouldn't be in there, this way:

```auto
				'event' : ctx.payload.hits.hits[j]._source.event.action];
			}, 
			return ctx.payload.transform""",
		"lang": "painless"
	}
},

```

Becomes:

```auto
				'event' : ctx.payload.hits.hits[j]._source.event.action];
			}
			return ctx.payload.transform""",
		"lang": "painless"
	}
},

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2022, 8:57pm UTC](https://discuss.elastic.co/t/elasticsearch-watcher-painless-error-when-trying-to-send-email/304614/3 "2022-06-09T20:57:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
