# Geting JSON from ctx.payload.hits in a webhook action that Ruby consumes

**URL:** <https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 10, 2016, 8:29pm UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478 "2016-06-10T20:29:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Randall\_Valenciano\_F](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/randall_valenciano_f/32/10256_2.png) [@Randall\_Valenciano\_F](https://discuss.elastic.co/u/Randall_Valenciano_F)\
**Post date:** [June 10, 2016, 8:29pm UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/1 "2016-06-10T20:29:29Z")

</div>

Hi,

Using elasticsearch and watcher, I'm having the same issue as [here](https://discuss.elastic.co/t/webhook-action-hits-collection-not-json/24568):

However, using the proposed solution is not working, groovy.json.JSONOutput is not supported anymore. I opened an issue in the elastic repo.

> <https://github.com/elastic/elasticsearch/issues/18807>

There you can read deeply about the situation. Summarizing, watcher ctx.payload.hits is giving me a java.util.HashMap object and I need a json object.

Any other possible way to retrieve a json instead of a java.util.HashMap response from watcher ctx? Or do I have to program using groovy core a parser from HashMap to json?

I'm using

Elasticsearch version: 2.3

JVM version: openjdk version "1.8.0\_91"  
OpenJDK Runtime Environment (build 1.8.0\_91-b14)  
OpenJDK 64-Bit Server VM (build 25.91-b14, mixed mode)

OS version: centOS 7

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 13, 2016, 8:09am UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/2 "2016-06-13T08:09:10Z")

</div>

Hey,

indeed I dont see a clean way that this is possible at the moment, without tedious manual construction inside of a string. Maybe a mustache function like `{{#toJson}}` (that accepts map as an argument) could help a lot here - but I am not sure if this is how mustache works, as I would expect it to only be able to handle strings - need to check it out.

--Alex

---

<div class="post-metadata">

**Author:** ![Randall\_Valenciano\_F](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/randall_valenciano_f/32/10256_2.png) [@Randall\_Valenciano\_F](https://discuss.elastic.co/u/Randall_Valenciano_F)\
**Post date:** [June 13, 2016, 2:22pm UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/3 "2016-06-13T14:22:21Z")

</div>

Hi!

Thanks for the response. I manage using some regex in ruby to parse it down. It would be nice to contribute to the community, but not sure how to proceed.

Best

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 14, 2016, 7:59am UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/4 "2016-06-14T07:59:43Z")

</div>

Hey,

Taking a look at the elasticsearch mustache integration and the possibility to add a JSON function might make sense here. This could be reused in watcher then.

Happy to help with first steps!

--Alex

---

<div class="post-metadata">

**Author:** ![Pranav\_Raj.S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav_raj.s/32/10702_2.png) [@Pranav\_Raj.S](https://discuss.elastic.co/u/Pranav_Raj.S)\
**Post date:** [July 4, 2016, 10:43am UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/5 "2016-07-04T10:43:55Z")

</div>

@Randall_Valenciano_F Would you mind sharing the regex which you used to parse in ruby ? I'm stuck right here.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 5, 2016, 6:25am UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/6 "2016-07-05T06:25:15Z")

</div>

Hey,

Just FYI: In Elasticsearch 2.4 and above we added a `toJson` mustache directive. See the PR [https://github.com/elastic/elasticsearch/pull/19153](https://github.com/elastic/elasticsearch/pull/19153) and the documentation of that one in particular [https://github.com/elastic/elasticsearch/pull/19153/files#diff-b99a30a3f37550a69a2508b3a3e120a6R226](https://github.com/elastic/elasticsearch/pull/19153/files#diff-b99a30a3f37550a69a2508b3a3e120a6R226)

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/geting-json-from-ctx-payload-hits-in-a-webhook-action-that-ruby-consumes/52478/7 "2017-07-06T13:44:33Z")

</div>


