# Multiple chain inputs and foreach

**URL:** <https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting, painless\
**Created:** [March 2, 2023, 6:39pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882 "2023-03-02T18:39:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [March 2, 2023, 6:39pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882/1 "2023-03-02T18:39:42Z")

</div>

I have following basic watcher.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "chain": {
      "inputs": [
        {
          "first_input": {
            "http": {
              "request": {
                "url": "http://example.com/first_input",
                "params": {},
                "headers": {}
              }
            }
          }
        },
        {
          "second_input": {
            "http": {
              "request": {
                "url": "http://example.com/second_input",
                "params": {},
                "headers": {}
              }
            }
          }
        }
      ]
    }
  },
  "condition": {
    "script": {
      "source": "for (def item : ctx.payload.first_input) { if (item.some_field > 10) { return true; } } return false;",
      "lang": "painless"
    }
  },
  "actions": {
    "send_email": {
      "email": {
        "to": "email@example.com",
        "subject": "Watcher Triggered",
        "body": {
          "text": "The watcher was triggered."
        }
      }
    }
  }
}

```

I want to run second\_input in foreach for the total count of first\_input.

So i changed the code like this for second\_input

```auto
second_input": {
           "foreach": "ctx.payload.first_input.hits.hits",
           "max_iterations": 50,
            "http": {
              "request": {
                "url": "http://example.com/second_input",
                "params": {},
                "headers": {}
              }
            }
          }

```

As soon i try to save it i get this error.

could not parse input for watch [chain\_example]. expected an object representing input [foreach], but found [VALUE\_STRING] instead

But if i remove that for each code and print in log following it , it shows total count.

Total {{ctx.payload.first\_input.hits.total}} shows # i.e 12

How can i fix this ?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 3, 2023, 12:03am UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882/2 "2023-03-03T00:03:07Z")

</div>

The `foreach` is only for `actions`, not `inputs`

Maybe describe the use case of what you're trying to do - perhaps there's a different way of doing it.

---

<div class="post-metadata">

**Author:** ![rajsolanki](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajsolanki/32/86859_2.png) [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Post date:** [March 3, 2023, 1:16pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882/3 "2023-03-03T13:16:34Z")

</div>

ok let me explain . Please let me know if its unclear.

```auto
{
  "trigger": {
    "schedule": {
      "interval": "1m"
    }
  },
  "input": {
    "chain": {
      "inputs": [
        {
          "first_input": {
            // search query gets resutls from heartbeat index and
// aggregates on monitor.name whose status is down for last 15 mins
        },
        {
          "second_input": {
           
           //for each document found in above query second input fires
// a get request to by passing monitor.name as query param to restapi
// and fetchs data for given monitor.name ,so if 2 documents were found 
//in first query second input will fire 2 times rest query with respective
 //monitor.name as query param.
          }
        }.
        {
           " third input" : {
            // transform the payload from first and second and create an array
// object from first payload get monitor.name and second payload get value of 
// flag 
           }
         }
        
      ]
    }
  },
  "condition": {
    "script": {
      // for loop to iterate through third payload array
      // if payload has flag = True value then take action. 
      // may be this condition can be in actions i think instead of here. 
    }
  },
  "actions": {
    "send_email": {
    "condition": {
            "script": {
            // if payload has flag = True value then take action.
            }
          },
      "foreach": "ctx.payload._value",
      "email": {
        "to": "email@example.com",
        "subject": "Watcher Triggered",
        "body": {
          "text": "The watcher was triggered."
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2023, 1:17pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882/4 "2023-03-31T13:17:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
