# Is Watcher webhook action support multi-document?

**URL:** <https://discuss.elastic.co/t/is-watcher-webhook-action-support-multi-document/207663>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [November 13, 2019, 9:19am UTC](https://discuss.elastic.co/t/is-watcher-webhook-action-support-multi-document/207663 "2019-11-13T09:19:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Izek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/izek/32/37113_2.png) [@Izek](https://discuss.elastic.co/u/Izek)\
**Post date:** [November 13, 2019, 9:19am UTC](https://discuss.elastic.co/t/is-watcher-webhook-action-support-multi-document/207663/1 "2019-11-13T09:19:42Z")

</div>

Hi there,

I am try to use watcher to post the data from one elastic cloud cluster to another one.  
But seems like the multi-document support is not working  
[multi-document support](https://www.elastic.co/guide/en/x-pack/5.1/actions-index.html#anatomy-actions-index-multi-doc-support)

And I saw a discussion before mentioned that index action do support.  
[https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/2?u=izek](https://discuss.elastic.co/t/watcher-webhook-action-with-bulk-request/72333/2)

But in my case, it failed  
here are the details

```json
          "webhook" : {
            "request" : {
              "host" : "host",
              "port" : 9243,
              "scheme" : "https",
              "method" : "post",
              "path" : "/decaf-watcher/watcher",
              "params" : {
                "id" : "monitor-by-system"
              },
              "headers" : {
                "Content-Type" : "application/json"
              },
              "auth" : {
                "basic" : {
                  "username" : "logstash_write_user",
                  "password" : "::es_redacted::"
                }
              },
              "body" : """{"_doc":[{"issue":"issue1","@timestamp":"2019-11-13T09:03:36.848704Z","element":"ABC123"},{"issue":"issue2","@timestamp":"2019-11-13T09:03:36.848704Z","element":"ABC456"}]}"""
            },
            "response" : {
              "status" : 200,
              "headers" : {
                "date" : [
                  "Wed, 13 Nov 2019 09:03:36 GMT"
                ],
                "x-cloud-request-id" : [
                  "f9bafffe-eb96-46dc-a035-26ff543fbcc0"
                ],
                "connection" : [
                  "keep-alive"
                ],
                "content-type" : [
                  "application/json; charset=UTF-8"
                ],
                "x-found-handling-server" : [
                  "172.30.103.190"
                ],
                "x-found-handling-cluster" : [
                  "2d96067f485b4a1098f709587e289cbe"
                ],
                "x-found-handling-instance" : [
                  "instance-0000000012"
                ]
              },
              "body" : """{"_index":"decaf-watcher","_type":"watcher","_id":"monitor-by-system","_version":124,"result":"updated","_shards":{"total":2,"successful":2,"failed":0},"_seq_no":18214,"_primary_term":1}"""
            }
          }

```

But the document view will be some thing like this

```json
{
   "_index":"decaf-watcher",
   "_type":"watcher",
   "_id":"monitor-by-system",
   "_version":127,
   "found":true,
   "_source":{
      "_doc":[
         {
            "issue":"issue1",
            "@timestamp":"2019-11-13T09:03:36.848704Z",
            "element":"ABC123"
         },
         {
            "issue":"issue2",
            "@timestamp":"2019-11-13T09:03:36.848704Z",
            "element":"ABC456"
         }
      ]
   }
}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 20, 2019, 3:07pm UTC](https://discuss.elastic.co/t/is-watcher-webhook-action-support-multi-document/207663/2 "2019-11-20T15:07:56Z")

</div>

you need to send a bulk request then with new line delimited JSON instead of a single JSON document.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2019, 3:08pm UTC](https://discuss.elastic.co/t/is-watcher-webhook-action-support-multi-document/207663/3 "2019-12-18T15:08:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
