# Not Sending Unique Errors

**URL:** <https://discuss.elastic.co/t/not-sending-unique-errors/59340>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 30, 2016, 4:38pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340 "2016-08-30T16:38:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![denton64](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@denton64](https://discuss.elastic.co/u/denton64)\
**Post date:** [August 30, 2016, 4:38pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/1 "2016-08-30T16:38:25Z")

</div>

Hey there,

Right now, I have a watch set up to send errors within a set window to a hipchat webhook. Unfortunately, it is only sending the most recent error. I would like to send all unique errors in that window but unsure how. The following is my current curl comman:

```auto
curl -XPUT 'localhost:9200/_watcher/watch/api-error' -d '{
      "trigger" : {
          "schedule" : { "interval" : "10s" } 
        },
        "input" : {
          "search" : {
            "request" : {
              "indices" : ["filebeat"],
              "body" : {
                "query" : {
                  "filtered" : {
                    "query" : {
                  "match_phrase" : { "source": "/var/www/html/logs/error_log" }
                  },
                  "filter" : {
                    "bool": {
                    "must": [
                    {
                      "range": {
                        "@timestamp" : {
                        "from" : "now-5m",
                        "to" : "now"
                        }
                      }
                    }
                    ]
                  }
                }
              }
            }
          }
          }
          }
        },
        "actions" : {
        "notify-hipchat" : {
          "throttle_period" : "5m",
          "hipchat" : {
            "account" : "notify-dev-monitoring",
            "message" : {
              "body": "New error seen in api apache error_log!\n\nHost: {{ctx.payload.hits.hits.0._source.beat.hostname}}\nMessage: {{ctx.payload.hits.hits.0._source.message}}",
              "format" : "text",
              "color" : "red",
              "notify" : true
            }
          }
        }
      }
      }'

```

Any insight would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 30, 2016, 6:23pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/2 "2016-08-30T18:23:17Z")

</div>

Hey Matthew,

To confirm your goal - do you you want one hipchat message that contains all the hosts that had errors, or do you want to send one message per host?

The first one (one message listing multiple hosts) should be possible today, using mustache templates over the results array. So in your message body, you could do something like:

```
{{#ctx.payload.hits.hits}} 
  {{_source.beat.hostname}} Message: {{ _source.message}} \n
{{/ctx.payload.hits.hits}} 

```

I'm not able to check the syntax right this second, but that should give you the idea.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![denton64](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@denton64](https://discuss.elastic.co/u/denton64)\
**Post date:** [August 30, 2016, 7:02pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/3 "2016-08-30T19:02:08Z")

</div>

Thanks for the response Steve.

To verify, I need to show every unique message the comes through in my time frame. For example, the watch runs at 2:05 and shows 3 error messages that were logged to apache error\_log between 2:00-2:05. Right now, it only shows the most recent log entry.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 30, 2016, 7:20pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/4 "2016-08-30T19:20:47Z")

</div>

Great, then the array support in mustache seems like it should work for you!

---

<div class="post-metadata">

**Author:** ![denton64](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@denton64](https://discuss.elastic.co/u/denton64)\
**Post date:** [August 30, 2016, 7:30pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/5 "2016-08-30T19:30:00Z")

</div>

So to verify, the new curl should look like this?

```auto
curl -XPUT 'localhost:9200/_watcher/watch/api-error' -d '{
      "trigger" : {
          "schedule" : { "interval" : "10s" } 
        },
        "input" : {
          "search" : {
            "request" : {
              "indices" : ["filebeat"],
              "body" : {
                "query" : {
                  "filtered" : {
                    "query" : {
                  "match_phrase" : { "source": "/var/www/html/logs/error_log" }
                  },
                  "filter" : {
                    "bool": {
                    "must": [
                    {
                      "range": {
                        "@timestamp" : {
                        "from" : "now-5m",
                        "to" : "now"
                        }
                      }
                    }
                    ]
                  }
                }
              }
            }
          }
          }
          }
        },
        "actions" : {
        "notify-hipchat" : {
          "throttle_period" : "5m",
          "hipchat" : {
            "account" : "notify-dev-monitoring",
            "message" : {
              "body": "New error seen in api apache error_log!\n\nHost: {{ctx.payload.hits.hits._source.beat.hostname}}\nMessage: {{ctx.payload.hits.hits._source.message}}",
              "format" : "text",
              "color" : "red",
              "notify" : true
            }
          }
        }
      }
      }'

```

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 30, 2016, 7:46pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/6 "2016-08-30T19:46:08Z")

</div>

> [@denton64](#):
>
> "body": "New error seen in api apache error\_log!\n\nHost: {{ctx.payload.hits.hits.\_source.beat.hostname}}\nMessage: {{ctx.payload.hits.hits.\_source.message}}"

IMO, you're going to want to iterate over the hits, so each one gets added to the message:

```
"body": "New error seen in api apache error_log! {{#ctx.payload.hits.hits}} \n\nHost: {{_source.beat.hostname}}\nMessage: {{_source.message}} {{/ctx.payload.hits.hits}}"

```

---

<div class="post-metadata">

**Author:** ![denton64](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@denton64](https://discuss.elastic.co/u/denton64)\
**Post date:** [August 30, 2016, 9:20pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/7 "2016-08-30T21:20:38Z")

</div>

Hmm, it did not like that. Got rid of the message entirely!

![](https://us1.discourse-cdn.com/elastic/original/2X/5/5b1fab3371989e4c82c9d61ac33c8af20647e360.png)

---

<div class="post-metadata">

**Author:** ![denton64](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@denton64](https://discuss.elastic.co/u/denton64)\
**Post date:** [August 31, 2016, 3:07pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/8 "2016-08-31T15:07:53Z")

</div>

It is actually outputting hits on a schedule without any new error. Looks blank because there wasn't an error in the timeframe. Still no cooperating as expected.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [September 1, 2016, 2:54am UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/9 "2016-09-01T02:54:01Z")

</div>

Ah yes, it looks like your watch doesn't have a condition, so the action will always be run, no matter what comes back from the query.

I would imagine that you could use a compare condition that looks at ctx.payload.hits.total \> 0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/not-sending-unique-errors/59340/10 "2017-07-06T13:43:18Z")

</div>


