# Iterate over payload in Index action

**URL:** <https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 13, 2019, 9:52am UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775 "2019-12-13T09:52:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul12](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@Rahul12](https://discuss.elastic.co/u/Rahul12)\
**Post date:** [December 13, 2019, 9:52am UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775/1 "2019-12-13T09:52:37Z")

</div>

Hi,  
I am trying to iterate over payload result and index multiple rows using watcher index action.  
Using my watcher I trying to get the list of host for which CPU crossing the threshold limit. I want to index multiple row in my index for different host.  
Can anyone please suggest any solution?  
Thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 13, 2019, 12:51pm UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775/2 "2019-12-13T12:51:50Z")

</div>

the index action allow you to index several documents in one action, see [https://www.elastic.co/guide/en/elasticsearch/reference/7.5/actions-index.html#anatomy-actions-index-multi-doc-support](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/actions-index.html#anatomy-actions-index-multi-doc-support)

What you need to do is to get the data in a proper format. This can be done by using a [script transform](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/transform-script.html) within your index action.

If you need some examples, check out the [examples repo](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches), that contains a few example watches that can help you get up and running.

--Alex

---

<div class="post-metadata">

**Author:** ![Rahul12](https://avatars.discourse-cdn.com/v4/letter/r/e9c0ed/32.png) [@Rahul12](https://discuss.elastic.co/u/Rahul12)\
**Post date:** [December 17, 2019, 12:04pm UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775/3 "2019-12-17T12:04:13Z")

</div>

Hi,  
Thanks for your help..  
I have tried to implement the same but getting error "could not execute action [index\_payload] of watch [_inlined_]. [ctx.payload.\_index] or [ctx.payload.\_doc.\_index] were set together with action [index] field. Only set one of them"  
According to other post I have found needs to remove \_index field from the payload. I have tried a transform  
def hits = ctx.payload.hits.hits.map(hit -\> hit.remove('\_index')).collect(Collectors.toList());  
return ['\_doc' : hits]

But getting below error

"script": "ctx.payload.hits.hits.map(hit -\> hit.remove('\_index')).collect(Collectors.toList());",  
"lang": "painless",  
"caused\_by": {  
"type": "illegal\_argument\_exception",  
"reason": "dynamic method [java.util.ArrayList, map/1] not found"  
}

Can you please help to fix the issue?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 17, 2019, 12:14pm UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775/4 "2019-12-17T12:14:37Z")

</div>

`ctx.payload.hits.hits` is an arraylist, if you want to use a stream on that, you need to call `ctx.payload.hits.hits.stream()` first.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2020, 12:14pm UTC](https://discuss.elastic.co/t/iterate-over-payload-in-index-action/211775/5 "2020-01-14T12:14:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
