# Finding correct painless request for Kibana Webhook

**URL:** <https://discuss.elastic.co/t/finding-correct-painless-request-for-kibana-webhook/193122>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [July 31, 2019, 1:28pm UTC](https://discuss.elastic.co/t/finding-correct-painless-request-for-kibana-webhook/193122 "2019-07-31T13:28:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![isabel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/isabel/32/51594_2.png) [@isabel](https://discuss.elastic.co/u/isabel)\
**Post date:** [July 31, 2019, 1:28pm UTC](https://discuss.elastic.co/t/finding-correct-painless-request-for-kibana-webhook/193122/1 "2019-07-31T13:28:25Z")

</div>

Hello,

I'm trying to hand over an ID from my Watcher context to my Watcher Action (Webhook).

There are the following Fields:

> workerId.keyword = string  
> f1score = number  
> assignment\_completed = boolean

I want to find out if there is a workerId having at least 5 'assignment\_complete = true' in the last 5 minutes.

Then I want to find out if a workerId having these 5 assignments\_completed = true does have an average f1Score \< 0.7.  
If the workerId have an average f1Score \< 0.7 I want to hand over the workerId to the body of my Action.

> "WorkerId": _here the workerId.keyword of the one with average f1Score \< 0.7 should appear_

Here you can see my actual request:  
I am asking actualy for a workerId.keyword in the last 5 min with an f1score \< 0.7 without asking for the 5 times 'assignment\_complete = true' (didn't get it and would be happy for help but for me its more importent to hand over the id.).

```
{
  "trigger": {
    "schedule": {
      "interval": "30s"
    }
  },
  "input": {
    "search": {
      "request": {
        "search_type": "query_then_fetch",
        "indices": [
          "mobots_assignments*"
        ],
        "rest_total_hits_as_int": true,
        "body": {
          "size": 0,
          "query": {
            "bool": {
              "filter": {
                "range": {
                  "start_time": {
                    "gte": "{{ctx.trigger.scheduled_time}}||-5m",  
                    "lte": "{{ctx.trigger.scheduled_time}}",
                    "format": "strict_date_optional_time||epoch_millis"
                  }
                }
              }
            }
          },
          "aggs": {
            "bucketAgg": {
              "terms": {
                "field": "workerId.keyword",
                "size": 1,
                "order": {
                  "metricAgg": "asc"
                }
              },
              "aggs": {
                "metricAgg": {
                  "min": {
                    "field": "f1score"
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "condition": {
    "script": {
      "source": "ArrayList arr = ctx.payload.aggregations.bucketAgg.buckets; for (int i = 0; i < arr.length; i++) { if (arr[i]['metricAgg'].value < params.threshold) { return true; } } return false;",
      "lang": "painless",
      "params": {
        "threshold": 0.7
      }
    }
  },
  "actions": {
    "mobots_webhook": {
      "webhook": {
        "scheme": "https",
        "host": "www.xyz.com",
        "port": 443,
        "method": "post",
        "path": "/worker_block",
        "params": {},
        "headers": {
          "Host": "www.xyz.com",
          "Content-Type": "application/json"
        },
        "body": {
          "source": {
            "WorkerId": "HERE THE workerId OF THE ONE WITH AVERAGE F1SCORE<0.7 SHOULD APPEAR",
            "Reason": "for test"
          },
          "lang": "mustache",
          "options": {
            "content_type": "application/json; charset=UTF-8"
          }
        }
      }
    }
  }
}

```

If you need more Information, let me know.  
Thank you for reading.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 26, 2019, 8:48am UTC](https://discuss.elastic.co/t/finding-correct-painless-request-for-kibana-webhook/193122/2 "2019-08-26T08:48:34Z")

</div>

the trick is to modify your payload data before handing it over to the webhook. You can use a [[https://www.elastic.co/guide/en/elastic-stack-overview/7.3/transform-script.html](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/transform-script.html)](script transform) to do that. Take a look at the [alerting examples](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches) for some more inspiration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2019, 8:48am UTC](https://discuss.elastic.co/t/finding-correct-painless-request-for-kibana-webhook/193122/3 "2019-09-23T08:48:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
