# Inline success script move to stored failed in transform watcher

**URL:** <https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940>\
**Category:** Elasticsearch\
**Created:** [October 13, 2017, 6:24pm UTC](https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940 "2017-10-13T18:24:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RomainXie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romainxie/32/22427_2.png) [@RomainXie](https://discuss.elastic.co/u/RomainXie)\
**Post date:** [October 13, 2017, 6:24pm UTC](https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940/1 "2017-10-13T18:24:19Z")

</div>

Hi, all

The follow is run correct.

```
  "transform": {
    "script": {
      "source": "return ['error_count' : ctx.payload.aggregations.whichHost.buckets.length, 'hosts' : ctx.payload.aggregations.whichHost.buckets.stream().map(item -> item.key).collect(Collectors.toList()).join(', '), 'process' : 'ntpd']",
      "lang": "painless"
    }
  }

```

But I got a "internal server error", just moving the source in a file.

The script file:

```
{
  "script": {
    "lang": "mustache",
    "source": "return ['error_count' : ctx.payload.aggregations.whichHost.buckets.length, 'hosts' : ctx.payload.aggregations.whichHost.buckets.stream().map(item -> item.key).collect(Collectors.toList()).join(', '), 'process' : 'ntpd']"
  }
}

```

The snippet in the watcher

```
  "transform": {
    "script": {
        "id": "script_process_trans",
      "lang": "painless"
    }
  }

```

I'm sure the filename is right.

How can I ......

PS. could not use the error information like that? 😭 The user saw it will be crazy.

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [October 13, 2017, 6:42pm UTC](https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940/2 "2017-10-13T18:42:00Z")

</div>

The file script should only contain the source, not any json. Eg, `scripts/script_process_trans.mustache`:

```auto
return ['error_count' : ctx.payload.aggregations.whichHost.buckets.length, 'hosts' : ctx.payload.aggregations.whichHost.buckets.stream().map(item -> item.key).collect(Collectors.toList()).join(', '), 'process' : 'ntpd']

```

(although note that does not look like mustache, you likely meant it to be painless, as indicated in the usage in your last snippet)

---

<div class="post-metadata">

**Author:** ![RomainXie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romainxie/32/22427_2.png) [@RomainXie](https://discuss.elastic.co/u/RomainXie)\
**Post date:** [October 14, 2017, 3:04am UTC](https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940/3 "2017-10-14T03:04:21Z")

</div>

> [@rjernst](#):
>
> (although note that does not look like mustache, you likely meant it to be painless, as indicated in the usage in your last snippet)

Finally, I want to send some params in the mushache, and then use it in the transform section.

the mushache named "script\_process\_trans"

```
{
  "script": {
    "lang": "mustache",
    "source": "return ['error_count' : ctx.payload.aggregations.{{buckets_name}}.buckets.length, 'hosts' : ctx.payload.aggregations.{{buckets_name}}.buckets.stream().map(item -> item.key).collect(Collectors.toList()).join(', '), 'process' : '{{process_name}}']"
  }
}

```

And the snippet of the watcher:

```
  "transform": {
    "script": {
        "id": "script_process_trans",
      "lang": "painless",
      "params": {
        "buckets_name": "whichHost",
        "process_name": "ntpd"
      }
    }
  }

```

After I got a "internal system error", I track the error. And then discovery the error will be caused only when include the file without params.

But it's success like it in the condition section.

The script named script\_bucket\_no\_empty

```
{
  "script": {
    "lang": "mustache",
    "source": "return ctx.payload.aggregations.{{bucket_name}}.buckets.length > 0"
  }
}

```

And use it successful followed:

```
  "condition": {
    "script": {
      "id": "script_bucket_no_empty",
      "lang": "painless",
      "params": {
        "bucket_name": "whichHost"
      }
    }
  },

```

I don't know what is different?  
I am a newbie for this, maybe the question is stupid. 😊

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2017, 3:04am UTC](https://discuss.elastic.co/t/inline-success-script-move-to-stored-failed-in-transform-watcher/103940/4 "2017-11-11T03:04:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
