# Mustache template to access timestamp field

**URL:** <https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 6, 2018, 4:38pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195 "2018-08-06T16:38:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Micah\_Hunsberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_hunsberger/32/147436_2.png) [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Post date:** [August 6, 2018, 4:38pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/1 "2018-08-06T16:38:01Z")

</div>

I want to create a watch that generates an action for a certain event, but I want to format the output using a mustache template.

In the output I want to be able to say when each event happened, e.g.

```auto
{{#ctx.payload.hits.hits}}
  At {{_source.@timestamp}} this happened.
{{/ctx.payload.hits.hits}}

```

I am using an online mustache template tester to help write the template, but this tester doesn't seem to be able to access fields that start with an `@`.

Will this work in elasticsearch? If not, how would I get the field value since its key starts with `@`

Thanks

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [August 6, 2018, 6:05pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/2 "2018-08-06T18:05:25Z")

</div>

From what I can tell Mustache won't work with fields that start with an @ sign. (Probably because Javascript identifiers can't start with an @). You could set up a scripted field timestamp that just returns the timestamp. Or you could change your documents so that the timestamp field doesn't start with an @ sign.

---

<div class="post-metadata">

**Author:** ![Micah\_Hunsberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_hunsberger/32/147436_2.png) [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Post date:** [August 6, 2018, 7:00pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/3 "2018-08-06T19:00:03Z")

</div>

Thank you. When you add scripted fields it seems to add them as an array so I had to access the value as if it were an array in mustache.

So in my watcher JSON in `input.search.request`

```auto
"script_fields" : {
  "tstamp": {
    "script" : "doc['@timestamp']"
  }
}

```

Then in `actions` the mustache template would look like this:

```auto
{{#ctx.payload.hits.hits}}
  At {{fields.tstamp.0}} this happened
{{/ctx.payload.hits.hits}}

```

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [August 6, 2018, 7:10pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/4 "2018-08-06T19:10:33Z")

</div>

That is odd that the tstamp comes as an array. Sounds like maybe a watcher bug? Pretty sure that scripted fields don't work like that in other contexts. Glad that you got it working.

---

<div class="post-metadata">

**Author:** ![Micah\_Hunsberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_hunsberger/32/147436_2.png) [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Post date:** [August 6, 2018, 8:02pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/5 "2018-08-06T20:02:07Z")

</div>

I am getting arrays from scripted fields using `DevTools > Console`

```auto
PUT test-script-fields
{
  "mappings": {
    "_doc" : {
      "properties": {
        "orig_field": { "type" : "keyword" }
      }
    }
  }
}

```

```auto
POST test-script-fields/_doc
{
  "orig_field": "value"
}

```

```auto
GET test-script-fields/_search
{
  "query": {
    "match_all": {}
  },
  "script_fields": {
    "new_field": {
      "script": "doc['orig_field']"
    }
  }
}

```

**Response**

```auto
{
  "took": 1,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 1,
    "max_score": 1,
    "hits": [
      {
        "_index": "test-script-fields",
        "_type": "_doc",
        "_id": "lJ_QEGUBKMz4hZe4_pnw",
        "_score": 1,
        "fields": {
          "new_field": [
            "value"
          ]
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Bill\_McConaghy](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@Bill\_McConaghy](https://discuss.elastic.co/u/Bill_McConaghy)\
**Post date:** [August 6, 2018, 8:07pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/6 "2018-08-06T20:07:49Z")

</div>

Thanks for the knowledge.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 7, 2018, 6:34am UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/7 "2018-08-07T06:34:55Z")

</div>

Using a script field means that Elasticsearch has to load the doc values of all the hits of a query (which might be millions) into memory.

Also, your snippet seems to work for me, this sample watch

```auto
POST _xpack/watcher/watch/_execute
{
  "watch": {
    "trigger": {
      "schedule": {
        "interval": "10h"
      }
    },
    "input": {
      "simple": {
        "hits": {
          "hits": [
            {
              "_source": {
                "@timestamp": "123"
              }
            }
          ]
        }
      }
    },
    "actions": {
      "logme": {
        "logging": {
          "text": "{{#ctx.payload.hits.hits}} At {{_source.@timestamp}} this happened. {{/ctx.payload.hits.hits}}"
        }
      }
    }
  }
}

```

logs

```auto
[2018-08-07T08:34:02,287][INFO][o.e.x.w.a.l.ExecutableLoggingAction] [DWc9wWT] At 123 this happened.

```

so maybe the issue is somewhere else? If you share your whole watch and the output of the execute watch API in a gist, that would make it easier to help.

---

<div class="post-metadata">

**Author:** ![Micah\_Hunsberger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_hunsberger/32/147436_2.png) [@Micah\_Hunsberger](https://discuss.elastic.co/u/Micah_Hunsberger)\
**Post date:** [August 7, 2018, 1:42pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/8 "2018-08-07T13:42:39Z")

</div>

Thank you @spinscale, this worked for me as well. I had not tried accessing `@timestamp` from within the watch, I had only tried it with the javascript version of mustache, which is what seems to have the problem accessing fields with `@` in them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 1:42pm UTC](https://discuss.elastic.co/t/mustache-template-to-access-timestamp-field/143195/9 "2018-09-04T13:42:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
