# How to return NA in watcher alert email if field is not available

**URL:** <https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 6, 2018, 9:50pm UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719 "2018-02-06T21:50:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![saranyav](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@saranyav](https://discuss.elastic.co/u/saranyav)\
**Post date:** [February 6, 2018, 9:50pm UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/1 "2018-02-06T21:50:00Z")

</div>

Hello,

I am trying to return a field as NA in watcher alert email if that field is not available in \_source.  
I am using a transform script to see if the field is available in the \_source, if not I am returning NA.  
Please let me know if this is the correct way of doing this.  
But I am getting watcher execution error below.  
Here is my watcher job and the error trace.

```
"actions": {
    "email_administrator": {
      "transform": {
        "script": {
          "source": "if(ctx.payload.hits.hits._source.containsKey(\"CASE_NO\")) {return ctx.payload.hits.hits._source.CASE_NO;} else {return \"NA\"}",
          "lang": "painless"
        }
      },
      "email": {
        "profile": "standard",
        "from": "' <test1@test.com>'",
        "priority": "high",
        "to": [
          "' <test2@test.com>'"
        ],
        "subject": "Test - Email template",
        "body": {
           "html": "<head><h4>Test - Email template</h4></head>{{#ctx.payload.hits.hits}}<table border=1 align=center><tbody><tr><th>Participant SSN</th><td>{{_source.SOC_SEC_NO}}</td></tr><tr><th>CASE_NO</th><td>{{key}}</td></tr><tr><th>IP Address</th><td>{{_source.REMOTE_IP_I}}</td></tr><tr><th>Geo IP location</th><td>{{_source.geoiplocation}}</td></tr></tbody></table><p></p>{{/ctx.payload.hits.hits}}"
        }
      }
    }
  }

```

## Error excecution

"actions": [  
{  
"id": "email\_administrator",  
"type": "email",  
"status": "failure",  
"transform": {  
"type": "script",  
"status": "failure",  
"reason": "ScriptException[runtime error]; nested: IllegalArgumentException[Illegal list shortcut value [\_source].]; "  
},  
"reason": "Failed to transform payload"  
}  
]  
},  
"messages": []  
}

---

<div class="post-metadata">

**Author:** ![saranyav](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@saranyav](https://discuss.elastic.co/u/saranyav)\
**Post date:** [February 6, 2018, 10:07pm UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/2 "2018-02-06T22:07:16Z")

</div>

Update:  
The get below returns NA if the field is not available.  
But when I use this script in the transform script , getting NULL Pointer exception.

failed to execute action []. failed to transform payload. ScriptException[runtime error]; nested: NullPointerException;

Can someone pls tell me how to loop for multiple records in transform?

```
GET inetvru-util-logs-model-2018-02-05/_search
{
  "query": {
    "match": {"NON_REPUD_CD": "SA"}
  },
  "script_fields": {
    "test": {
      "script": {
        "lang":"painless",
        "source":"if(params._source.containsKey(\"CASE_NO\")) {return params._source.CASE_NO;} else {return \"NA\"}"
      
      }
    
      }
  }
}
```

---

<div class="post-metadata">

**Author:** ![saranyav](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@saranyav](https://discuss.elastic.co/u/saranyav)\
**Post date:** [February 7, 2018, 3:50am UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/3 "2018-02-07T03:50:20Z")

</div>

Hello,

Tried to loop through the transform script like below. I am getting below error.

Watcher: An internal server error occurred

Is transform script is the right choice to show NA (in email alert) for the fields that are not available with \_source? If so, Once I transform this how can I access the returned value in the email alert?

"transform": {  
"script": {  
"source": "for(int j=0;j\<ctx.payload.hits.hits;j++){if(ctx.payload.hits.hits[j].\_source.containsKey("CASE\_NO")) {return ctx.payload.hits.hits[j].\_source.CASE\_NO} else {return "NA"}}",  
"lang": "painless"  
}  
}

Thanks!  
Saranya

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 7, 2018, 9:12am UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/4 "2018-02-07T09:12:17Z")

</div>

From the examples I read in your posts I think there is one fundamental issue, and once that is fixed, things should be more clear.

To quote [Transforms | X-Pack for the Elastic Stack [6.1] | Elastic](https://www.elastic.co/guide/en/x-pack/6.1/transform.html)

> Blockquote  
> A Transform processes and **changes** the payload in the watch execution context to prepare it for the watch actions.

The important part here is, that the word _changes_ means, the existing payload gets overwritten. You cannot access the hits if you dont specify them in your transform. Also in your last example, you basically returned early, as soon as the first document has the key - I do think you want to create a list here?

It might make sense to check out our examples repo athttps://github.com/elastic/examples/tree/master/Alerting

---

<div class="post-metadata">

**Author:** ![saranyav](https://avatars.discourse-cdn.com/v4/letter/s/977dab/32.png) [@saranyav](https://discuss.elastic.co/u/saranyav)\
**Post date:** [February 7, 2018, 8:36pm UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/5 "2018-02-07T20:36:31Z")

</div>

Hello Alexander,

I implemented this by creating a scripted field rather than transforming the payload.  
Then I accessed the scripted field as ctx.payload.hits.hits.fields.scriptedfield.  
Thanks for pointing me the right direction.

```
 "script_fields": {
            "name": {
              "script": {
                "lang": "painless",
                "inline": "if(params._source.containsKey(\"name\")) {return params._source.name;} else {return \"N/A\"}"
              }
            }

```

Thanks!  
SV

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2018, 8:36pm UTC](https://discuss.elastic.co/t/how-to-return-na-in-watcher-alert-email-if-field-is-not-available/118719/6 "2018-03-07T20:36:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
