# How to create a watch that email specific field from input index?

**URL:** <https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 2, 2016, 4:09am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947 "2016-08-02T04:09:59Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 2, 2016, 4:09am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/1 "2016-08-02T04:09:59Z")

</div>

Hi,  
I wanna include some filed from index to email body of action how I can do that?

curl -XPUT '[http://localhost:9200/\_watcher/watch/log\_error\_watch](http://localhost:9200/_watcher/watch/log_error_watch)' -d '{  
"trigger" : { "schedule" : { "interval" : "10s" } },  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["filebeat-\*"],  
"body" : {  
"query" : {  
"match" : { "message": "error" }  
}  
}  
}  
}  
},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "my\_name@my\_domain",  
"subject" : "error filebeat Status Warning",  
"body" : " want to include matching lines from index here"  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 2, 2016, 6:20am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/2 "2016-08-02T06:20:27Z")

</div>

Hey,

you can access parts of your search by accessing `ctx.payload` and using the mustache scripting language. The first example in the watcher docs about the [email action](https://www.elastic.co/guide/en/watcher/2.3/actions.html#configuring-email-actions) already includes an example.

--Alex

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 2, 2016, 6:30am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/3 "2016-08-02T06:30:38Z")

</div>

Thanks Alex for promt response.  
My index has fields like beat.hostname, syslog\_message and some more  
how I can include only these two fields?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 2, 2016, 3:22pm UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/4 "2016-08-02T15:22:14Z")

</div>

Hey,

by directly specify those fields in the `body` field of your email action. Please ask more concrete questions with an example to get more help - it is hard to find out what exactly you intend to do. If you need to know how to access search hits, check out the [search input docs](https://www.elastic.co/guide/en/watcher/2.3/input.html#input-search), which has an example.

Hope this helps!

--Alex

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 3, 2016, 1:54am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/5 "2016-08-03T01:54:00Z")

</div>

Hi Alex,  
Thanks Thats what actually Iam looking for  
my watch works with "body" : " Error {{ctx.payload.hits.hits.0}} "  
however this ddint wok  
"body" : " Host name {{ctx.payload.hits.hits.0.fields.received\_from}} "  
what could be the reason?

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 3, 2016, 1:57am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/6 "2016-08-03T01:57:37Z")

</div>

COmplete watch  
curl -XPUT '[http://localhost:9200/\_watcher/watch/log\_error\_watch](http://localhost:9200/_watcher/watch/log_error_watch)' -d '{  
"trigger" : { "schedule" : { "interval" : "10s" } },  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["filebeat-2016.08.02"],  
"body" : {  
"query" : {  
"match" : { "message": "error" }  
}  
}  
}  
}  
},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "my\_name@my\_domain",  
"subject" : "filebeat Status Warning",  
"body" : " Host name {{ctx.payload.hits.hits.0}} "  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 3, 2016, 6:21am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/7 "2016-08-03T06:21:50Z")

</div>

You will need to access the `_source` field to access the data you want. Please run the search manually, as it shows your the path to the JSON you want to extract.

--Alex

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 3, 2016, 7:03am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/8 "2016-08-03T07:03:39Z")

</div>

Hi Alex,  
Thank you for support.  
I am new to elastic packages  
could you please send me the relavant documents for that ?

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 18, 2016, 5:33am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/9 "2016-08-18T05:33:49Z")

</div>

HI,  
Can you provide a example of complete watcher that send mail from input inex fields ?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 22, 2016, 10:12pm UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/10 "2016-08-22T22:12:12Z")

</div>

hi

You can access all the elastic packages from the download pages here: [https://www.elastic.co/downloads](https://www.elastic.co/downloads)

Also the watcher documentation is here: [https://www.elastic.co/guide/en/watcher/current/index.html](https://www.elastic.co/guide/en/watcher/current/index.html)

Hope this helps.

--Rashmi

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [August 31, 2016, 3:10am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/11 "2016-08-31T03:10:08Z")

</div>

Hi,  
Thanks Rashmi. But I am looking for more specific

I used this watcher to send alert, but It doesnt have all the records. when I checked through kibana It contain more records.  
what could be the reason ?  
curl -XPUT '[http://localhost:9200/\_watcher/watch/log\_error\_watch](http://localhost:9200/_watcher/watch/log_error_watch)' -d '{  
"trigger" : { "schedule" : { "interval" : "10s" } },  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["filebeat-2016.08.31"],  
"body" : {  
"query" : {  
"match" : { "message": "uat" }  
}  
}  
}  
}  
},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "muname@mydoamin",  
"subject" : "filebeat Status Warning",  
"body" : "{{ctx.payload}}"  
}  
}  
}  
}'

and I used this to get first hit  
" "body" : "{{ctx.payload.hits.hits.0}}" "

How can i get only the latest hit? most recent one ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 5, 2016, 3:48pm UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/12 "2016-09-05T15:48:29Z")

</div>

Hey,

you need to sort your search request by timestamp, then the first hit will always be the latest.

--Alex

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [September 6, 2016, 1:55am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/13 "2016-09-06T01:55:33Z")

</div>

Hi Alex,  
Thank you very much.  
with this I could get latest hit  
curl -XPUT '[http://localhost:9200/\_watcher/watch/log\_error\_watch](http://localhost:9200/_watcher/watch/log_error_watch)' -d '{  
"trigger" : { "schedule" : { "interval" : "30s" } },  
"input" : {  
"search" : {  
"request" : {  
"indices" : ["filebeat-2016.09.06"],  
"body" : {  
"query" : {  
"match" : { "message": "failure" }  
},

"sort":  
{ "syslog\_timestamp": { "order": "desc" }}

```
    }
  }
}

```

},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "R@mydomain",  
"subject" : "filebeat Statussys log\_message failure ",  
"body" : "{{ctx.payload.hits.hits.0}}"  
}  
}  
}  
}'

Is there anyway I can format the output (email body) ? As of now alert is not user friendly.

Thanks  
Ruchira

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 6, 2016, 7:33am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/14 "2016-09-06T07:33:36Z")

</div>

Hey,

you can use newlines or just use HTML for more custom formatting, see [how to configure email attachments](https://www.elastic.co/guide/en/watcher/2.4/actions.html#configuring-email-attachments).

--Alex

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [September 6, 2016, 8:29am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/15 "2016-09-06T08:29:30Z")

</div>

Thanks Alex.  
Will check on that.

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [September 9, 2016, 8:51am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/16 "2016-09-09T08:51:08Z")

</div>

HI Alex,  
How I can attach only the first hit ?  
Thanks

---

<div class="post-metadata">

**Author:** ![ruchira](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@ruchira](https://discuss.elastic.co/u/ruchira)\
**Post date:** [September 9, 2016, 8:57am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/17 "2016-09-09T08:57:14Z")

</div>

HI,  
I can get the last hit using specific index name, but when I use wildcast for index name it shows me old result not the latest.  
In my system I have seperate index for everyday (filebeat-2016.09.08).

curl -XPUT '[http://localhost:9200/\_watcher/watch/log\_error\_watch](http://localhost:9200/_watcher/watch/log_error_watch)' -d '{  
"trigger" : { "schedule" : { "interval" : "20s" } },  
"input" : {  
"search" : {  
"request" : {  
**"indices" : ["filebeat-\*"],**  
"body" : {  
"query" : {  
"match" : { "message": "Fail event detected" }  
},

"sort":  
{ "syslog\_timestamp": { "order": "desc" }}

```
    }
  }
}

```

},  
"condition" : {  
"compare" : { "ctx.payload.hits.total" : { "gt" : 0 }}  
},  
"actions" : {  
"send\_email" : {  
"email" : {  
"to" : "myname@mydoain",  
"subject" : "syslog critical event detected attched 09 ",  
"body" : "{{ctx.payload.hits.hits.0}}",

"attachments" : {  
"attached\_data" : {  
"data" : {  
"format" : "json"  
}  
}  
},  
"priority" : "high"

```
  }
}

```

}  
}'

How I can resolve this ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 9, 2016, 9:22am UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/18 "2016-09-09T09:22:17Z")

</div>

Hey,

how does the syslog timestamp look like? is it possible that it does not contain a year and thus is hard to sort correctly as it is not a unique timestamp but reoccurs every 24 hours?

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/how-to-create-a-watch-that-email-specific-field-from-input-index/56947/19 "2017-07-06T13:42:59Z")

</div>


