# Getting parse exception on a Watch that works in a previous version of elastic

**URL:** <https://discuss.elastic.co/t/getting-parse-exception-on-a-watch-that-works-in-a-previous-version-of-elastic/236206>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [June 8, 2020, 4:52pm UTC](https://discuss.elastic.co/t/getting-parse-exception-on-a-watch-that-works-in-a-previous-version-of-elastic/236206 "2020-06-08T16:52:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [June 8, 2020, 4:52pm UTC](https://discuss.elastic.co/t/getting-parse-exception-on-a-watch-that-works-in-a-previous-version-of-elastic/236206/1 "2020-06-08T16:52:24Z")

</div>

Hi, im getting this error when I test my watch

parse\_exception :  
"reason" : "please wrap watch including field [trigger] inside a "watch" field"

the alerts are sended to microsoft teams  
this is my watch:

```auto
PUT _watcher/watch/my_watch/_execute
{
    "trigger": {
        "schedule": {
            "interval": "5m"
        }
    },
    "input": {
        "search": {
            "request": {
                "body": {
                    "size": 0,
                    "query": {
                        "bool": {
                            "filter": {
                                "range": {
                                    "@timestamp": {
                                        "gte": "{{ctx.trigger.scheduled_time}}||-5m",
                                        "lte": "{{ctx.trigger.scheduled_time}}",
                                        "format": "strict_date_optional_time||epoch_millis"
                                    }
                                }
                            }
                        }
                    }
                },
                "indices": [
                    "metrics-*"
                ]
            }
        }
    },
    "condition": {
        "script": {
            "source": "if (ctx.payload.hits.total <= params.threshold) { return true; } return false;",
            "params": {
                "threshold": 0
            }
        }
    },
    "transform": {
        "script": {
            "source": "HashMap result = new HashMap(); result.result = ctx.payload.hits.total; return result;",
            "lang": "painless",
            "params": {
                "threshold": 0
            }
        }
    },
    "actions": {
        "webhook_teams": {
            "webhook": {
                "scheme": "https",
                "host": "outlook.office.com",
                "port": 443,
                "method": "post",
                "path": "/webhook/...",
                "params": {},
                "headers": {
                    "Content-Type": "application/json"
                },
                "body": "{{#toJson}}ctx.payload{{/toJson}}"
            }
        }
    }
}

```

I have it working in another older version of elastic, 7.5.1.....in version 7.6 doesnt work

Any suggestions?

---

<div class="post-metadata">

**Author:** ![alisongoryachev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alisongoryachev/32/111352_2.png) [@alisongoryachev](https://discuss.elastic.co/u/alisongoryachev)\
**Post date:** [June 11, 2020, 3:48pm UTC](https://discuss.elastic.co/t/getting-parse-exception-on-a-watch-that-works-in-a-previous-version-of-elastic/236206/2 "2020-06-11T15:48:37Z")

</div>

Hi @ElasticLiver!

If you are executing an existing watch you only need to include the watch id in the request.

```auto
POST _watcher/watch/my_watch/_execute

```

Alternatively, you can define a watch in the request body.

```auto
POST _watcher/watch/_execute
{
  "watch" : {
   {
    "trigger": {
        "schedule": {
            "interval": "5m"
        }
    },
    "input": {
        "search": {
            "request": {
                "body": {
                    "size": 0,
                    "query": {
                        "bool": {
                            "filter": {
                                "range": {
                                    "@timestamp": {
                                        "gte": "{{ctx.trigger.scheduled_time}}||-5m",
                                        "lte": "{{ctx.trigger.scheduled_time}}",
                                        "format": "strict_date_optional_time||epoch_millis"
                                    }
                                }
                            }
                        }
                    }
                },
                "indices": [
                    "metrics-*"
                ]
            }
        }
    },
    "condition": {
        "script": {
            "source": "if (ctx.payload.hits.total <= params.threshold) { return true; } return false;",
            "params": {
                "threshold": 0
            }
        }
    },
    "transform": {
        "script": {
            "source": "HashMap result = new HashMap(); result.result = ctx.payload.hits.total; return result;",
            "lang": "painless",
            "params": {
                "threshold": 0
            }
        }
    },
    "actions": {
        "webhook_teams": {
            "webhook": {
                "scheme": "https",
                "host": "outlook.office.com",
                "port": 443,
                "method": "post",
                "path": "/webhook/...",
                "params": {},
                "headers": {
                    "Content-Type": "application/json"
                },
                "body": "{{#toJson}}ctx.payload{{/toJson}}"
            }
        }
    }
}
  }
}

```

For more information, please check out the docs: [https://www.elastic.co/guide/en/elasticsearch/reference/7.5/watcher-api-execute-watch.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/watcher-api-execute-watch.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2020, 3:48pm UTC](https://discuss.elastic.co/t/getting-parse-exception-on-a-watch-that-works-in-a-previous-version-of-elastic/236206/3 "2020-07-09T15:48:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
