# Extract a tag field into watcher / Watcher to Alert if a Heartbeat Host is Down

**URL:** <https://discuss.elastic.co/t/extract-a-tag-field-into-watcher-watcher-to-alert-if-a-heartbeat-host-is-down/132829>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 22, 2018, 1:15pm UTC](https://discuss.elastic.co/t/extract-a-tag-field-into-watcher-watcher-to-alert-if-a-heartbeat-host-is-down/132829 "2018-05-22T13:15:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheNmaptomyHeartBeat](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Post date:** [May 22, 2018, 1:15pm UTC](https://discuss.elastic.co/t/extract-a-tag-field-into-watcher-watcher-to-alert-if-a-heartbeat-host-is-down/132829/1 "2018-05-22T13:15:41Z")

</div>

I am trying to create a watcher, and I am using Heartbeat to check if any hosts are down.

I have add a tag field to the IPs that I will be monitoring, this helps identify them easier. However, the tag field is not in the payload.  
I would like the message to read "Warning, Server1 is down." instead of "Warning, 123.123.12.103 is down."

I have tried `extract` which didn't work.

If anyone can offer a hand that would be swell. I am not even sure this watcher is right. I think I might need to add a timestamp to it. It might still not work right.

This is my heartbeat.yml file:

```auto
heartbeat.monitors:
- type: http

  # List or urls to query
  urls:
    - https://foobar.com
    - https://foobar.com
    - https://foobar.com
  schedule: '@every 10s'

- type: icmp
  tags: ["Server1"]
  hosts:
  - 123.123.12.103#These are servers so have to use IP address
  schedule: '@every 10s'

- type: icmp
  tags: ["Server2"]
  hosts:
  - 123.123.12.105
  schedule: '@every 10s'

```

And my watcher

```auto
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
          "indices" : "heartbeat-*",
        "body": {
          "query": {
            "match": { "monitor.status" : "down"}
          }
        }
      }
    }
  },
  "actions": {
    "my-logging-action": {
      "logging": {
        "text": "Warning, {{ctx.payload.hits.hits.0._source.resolve.ip}} is down."
      }
    }
  }
}

```

The output

```auto
   "actions": [
      {
        "id": "my-logging-action",
        "type": "logging",
        "status": "simulated",
        "logging": {
          "logged_text": "Warning, 123.123.12.105 is down."
        }
      }
    ]
  }

```

---

<div class="post-metadata">

**Author:** ![TheNmaptomyHeartBeat](https://avatars.discourse-cdn.com/v4/letter/t/47e85d/32.png) [@TheNmaptomyHeartBeat](https://discuss.elastic.co/u/TheNmaptomyHeartBeat)\
**Post date:** [May 23, 2018, 8:30am UTC](https://discuss.elastic.co/t/extract-a-tag-field-into-watcher-watcher-to-alert-if-a-heartbeat-host-is-down/132829/2 "2018-05-23T08:30:37Z")

</div>

I have managed to figure out this watcher.  
I will post the JSON code below in case anyone needs it. Since I weren't able to find an example online when I was making it, it might be helpful for someone.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "10s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "heartbeat-*"
        ],
        "types": [],
        "body": {
          "query": {
            "bool": {
              "must": [
                {
                  "range": {
                    "@timestamp": {
                      "gte": "now-10s"
                    }
                  }
                },
                {
                  "match": {
                    "monitor.status": "down"
                  }
                }
              ]
            }
          }
        }
      }
    }
  },
  "condition": {
    "compare": {
      "ctx.payload.hits.total": {
        "gte": 1
      }
    }
  },
  "actions": {
    "notify-slack": {
      "throttle_period_in_millis": 2000,
      "slack": {
        "message": {
          "to": [
            "#watcher"
          ],
          "text": "Warning. Host: {{ctx.payload.hits.hits.0._source.tags.0}} is down"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2018, 8:30am UTC](https://discuss.elastic.co/t/extract-a-tag-field-into-watcher-watcher-to-alert-if-a-heartbeat-host-is-down/132829/3 "2018-06-20T08:30:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
