# How to print a Field value in a Watch

**URL:** <https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [May 14, 2018, 7:12am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669 "2018-05-14T07:12:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![addanuj](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@addanuj](https://discuss.elastic.co/u/addanuj)\
**Post date:** [May 14, 2018, 7:12am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669/1 "2018-05-14T07:12:56Z")

</div>

```
==================Index output====================================
{
  "took": 590,
  "timed_out": false,
  "_shards": {
    "total": 10,
    "successful": 9,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 182288644,
    "max_score": 1,
    "hits": [
      {
        "_index": "logstash-ossec-2018.05.02",
        "_type": "doc",
        "_id": "iD9CHmMBSutjJDB7Oh9L",
        "_score": 1,
        "_source": {
          "rule": {
            "description": "Windows Logon Success.",
            "firedtimes": 40368,
            "pci_dss": [
              "10.2.5"
            ],
            "mail": false,
            "id": "18107",
            "level": 3,
            "groups": [
              "windows",
              "authentication_success"
            ]
          },
===============================================================

======================Watch===================================
{
  "trigger": {
"schedule": {
  "interval": "5s"
}
  },
  "input": {
"search": {
  "request": {
    "search_type": "query_then_fetch",
    "indices": [
      "logstash-ossec-*"
    ],
    "types": [],
    "body": {
      "size": 0,
      "query": {
        "bool": {
          "should": [
            {
              "match_phrase": {
                "rule.description": "sshd: Attempt to login using a nodn-existent user"
              }
            },
            {
              "match_phrase": {
                "rule.description": "Windows: Logon Failure - Unknown user or bad password"
              }
            }
          ],
          "minimum_should_match": 1,
          "filter": {
            "range": {
              "@timestamp": {
                "gte": "now-7d"
              }
            }
          }
        }
      }
    }
  }
}
  },
  "condition": {
"compare": {
  "ctx.payload.hits.total": {
    "gte": 1
  }
}
  },
  "actions": {
"my-logging-action": {
  "logging": {
    "level": "info",
    "text": "There are {{ctx.payload.hits.hits._source.description}} Attempts in last 10 Minutes."
  }
}
  }
}

====================actions output==============================
"actions": [
  {
    "id": "my-logging-action",
    "type": "logging",
    "status": "success",
    "logging": {
      "logged_text": "There are Attempts in last 10 Minutes."
    }
  }
]
  },
  "messages": []
}

```

I want to print Description field value which i am not able to ... please help.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 14, 2018, 7:30am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669/2 "2018-05-14T07:30:45Z")

</div>

please take the time to properly format your messages. You can use markdown in here to properly format code snippets so please do so - this is nearly impossible to read.

Using `{{ctx.payload.hits.hits._source.description}}` does not take into account that `ctx.payload.hits.hits` is an array. If you just want to know how many documents matched your query, use `ctx.payload.hits.total`, if you need to access an element inside of the hits array, use the index to access it: `{{ctx.payload.hits.hits.0._source.description}}`

hope this helps.

---

<div class="post-metadata">

**Author:** ![addanuj](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@addanuj](https://discuss.elastic.co/u/addanuj)\
**Post date:** [May 14, 2018, 8:01am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669/3 "2018-05-14T08:01:39Z")

</div>

now i am getting this error:

```
"caused_by": {
            "type": "mustache_exception",
            "reason": "Failed to get value for ctx.payload.hits.hits.0.rule.description @[query-template:1]",
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 14, 2018, 9:02am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669/4 "2018-05-14T09:02:11Z")

</div>

you are missing the `_source` field reference here. Please take your time to compare the JSON of your response with the fields you are trying to access, as it needs to be exact.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 9:02am UTC](https://discuss.elastic.co/t/how-to-print-a-field-value-in-a-watch/131669/5 "2018-06-11T09:02:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
