# How to ignore last element of array in elastic watcher \\ mustache template

**URL:** https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801
**Category:** Elasticsearch
**Tags:** elastic-stack-alerting, painless
**Created:** [September 12, 2023, 10:29am UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801 "2023-09-12T10:29:33Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)
#### Post date: [September 12, 2023, 10:29am UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801/1 "2023-09-12T10:29:33Z")

</div>

Hello!  
I have an issue when trying to set an elasticsearch watcher.  
Here is the part of its config:

```auto
  "input": {
    "chain": {
      "inputs": [
        {
          " **first**": {
            "search": {
              "request": {
                "search_type": "query_then_fetch",
                "indices": [
                  "winlogbeat-*"
                ],
                "rest_total_hits_as_int": true,
                "body": {
                  "query": {
                    "range": {
                      "@timestamp": {
                        "gte": "now-{{ctx.metadata.window_period}}"
                      }
                    }
                  },
.....
          " **second**": {
            "transform": {
              "script": {
                "source": "def last_period=ctx.payload.first.aggregations.periods.buckets.last_period.hosts.buckets.stream().map(e -> e.key).collect(Collectors.toList()); return ctx.payload.first.aggregations.periods.buckets.history.hosts.buckets.stream().map(e -> e.key).filter(p -> !last_period.contains(p)).collect(Collectors.toList());",
                "lang": "painless"
              }
            }
          }
        },
....
        {
          " **third**": {
            "search": {
              "request": {
                "search_type": "query_then_fetch",
                "indices": [
                  "checkpointt*"
                ],
                "rest_total_hits_as_int": true,
                "body": {
                  "query": {
                    "bool": {
                      "must": [
                        {
                          "range": {
                            "@timestamp": {
                              "gte": "now-{{ctx.metadata.last_period}}"
                            }
                          }
                        },
                        {
                          "terms": {
                            "src_address": [
                              "{{#ctx.payload.second._value}}{{.}}",
                              "{{/ctx.payload.second._value}}"
                            ]
                          }
                        }
                      ],

```

Most interesting part of it - ` **third** `  
When I try to execute this query search error happens:  
`failed to create query: '' is not an IP string literal.`  
After step **second** I have a normal array of items like  
["1.1.1.1", "2.2.2.2", "8.8.8.8"], and after **third** it converts to something like:  
"1.1.1.1",  
"2.2.2.2",  
"8.8.8.8",  
""  
Why the last empty element of array - "" appeared? How to remove it?

---

<div class="post-metadata">

### Author: ![vladislav](https://avatars.discourse-cdn.com/v4/letter/v/bbce88/32.png) [@vladislav](https://discuss.elastic.co/u/vladislav)
#### Post date: [September 26, 2023, 12:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801/2 "2023-09-26T12:12:49Z")

</div>

Any thoughts?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 24, 2023, 12:13pm UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801/3 "2023-10-24T12:13:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
