# Index action, index search output as multiple documents

**URL:** <https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [April 16, 2019, 10:23am UTC](https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058 "2019-04-16T10:23:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![agone](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@agone](https://discuss.elastic.co/u/agone)\
**Post date:** [April 16, 2019, 10:23am UTC](https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058/1 "2019-04-16T10:23:28Z")

</div>

Hi!  
I need to create a watch, that will search through several indicies for certain events and then save each doc as a separate event to a new index.  
I have already read this [topic](https://discuss.elastic.co/t/transform-single-hit-into-multiple-documents-with-index-action/145010), got the idea but still hunting for working approach.  
If anyone can provide an example of working script transform - that would be prefect.  
I am on 6.6.1.  
Here is my watch:

```
	{
	"trigger": {
		"schedule": {
			"interval": "1m"
		}
	},
	"input": {
		"search": {
			"request": {
				"search_type": "query_then_fetch",
				"indices": [
					"networklogs-cisco-step_dit*",
					"networklogs-fortinet-step_dit*"
				],
				"types": [
					"doc"
				],
				"body": {
					"size": 50,
					"query": {
						"bool": {
							"filter": [
								{
									"range": {
										"@timestamp": {
											"lt": "now",
											"gte": "now-5m"
										}
									}
								},
								{
									"term": {
										"destination.port": 445
									}
								},
								{
									"terms": {
										"event.action": [
											"pass",
											"passthrough",
											"log-only",
											"allowed",
											"accept",
											"dns",
											"ip-conn",
											"allow",
											"allowed"
										]
									}
								}
							]
						}
					}
				}
			}
		}
	},
	"condition": {
		"compare": {
			"ctx.payload.hits.total": {
				"gte": 1
			}
		}
	},
	"actions": {
		"create_incident": {
			"transform": {
				"script": {
					"source": "<I stucked here>"
				}
			},
			"index": {
				"index": "alerts",
				"doc_type": "doc"
			}
		}
	}
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [April 16, 2019, 4:27pm UTC](https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058/2 "2019-04-16T16:27:10Z")

</div>

Check out the [examples repo](https://github.com/elastic/examples/tree/master/Alerting), IIRC the port scanning watch contains a transform doing that.

---

<div class="post-metadata">

**Author:** ![agone](https://avatars.discourse-cdn.com/v4/letter/a/c6cbf5/32.png) [@agone](https://discuss.elastic.co/u/agone)\
**Post date:** [April 17, 2019, 7:58am UTC](https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058/3 "2019-04-17T07:58:43Z")

</div>

Hi, @spinscale  
Thank you for your reply. I checked the script you mentioned. It is slightly overweight for my task.  
I was able to write less elegant but yet shorter script.

```
"actions": {
    "create_incident": {
        "transform": {
            "script": {
                "source": "def buff_arr = ctx.payload.hits.hits; def result_arr = []; for (item in buff_arr) { result_arr.add(item._source); } return ['_doc': result_arr]",
                "lang": "painless"
            }
        },
        "index": {
            "index": "alerts",
            "doc_type": "doc"
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 7:58am UTC](https://discuss.elastic.co/t/index-action-index-search-output-as-multiple-documents/177058/4 "2019-05-15T07:58:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
