# Notify slack action -- help with list\_path

**URL:** <https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 8, 2017, 9:35am UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790 "2017-03-08T09:35:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![paolo1](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@paolo1](https://discuss.elastic.co/u/paolo1)\
**Post date:** [March 8, 2017, 9:35am UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/1 "2017-03-08T09:35:12Z")

</div>

Hello,  
Could someone help with what needs to be entered into "list\_path" ? I'm trying to create a dynamic attachment for Slack based on the cluster health status. "list\_path" is required but isn't fully explained in the documentation.

> PUT \_xpack/watcher/watch/cluster\_health\_watch  
> {  
> "trigger" : {  
> "schedule" : { "interval" : "30s" }  
> },  
> "input" : {  
> "http" : {  
> "request" : {  
> "host" : "localhost",  
> "port" : 9200,  
> "path" : "/\_cluster/health",  
> "auth": {  
> "basic": {  
> "username": "",  
> "password": ""  
> }  
> }  
> }  
> }  
> },  
> "actions" : {  
> "notify-slack" : {  
> "transform" : {  
> "script" : {  
> "inline" : "return ['name': ctx.payload.cluster\_name, 'color': ctx.payload.status == 'green' ? 'good' : 'danger'];",  
> "lang" : "painless"  
> }  
> },  
> "slack" : {  
> "message" : {  
> "from" : "",  
> "to" : [""],  
> "dynamic\_attachments" : {  
> "list\_path" : "?????",  
> "attachment\_template" : {  
> "title" : "Status:",  
> "text" : "{{name}}",  
> "color" : "{{color}}"  
> }  
> },  
> "text" : "_Cluster health_"  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 8, 2017, 2:12pm UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/2 "2017-03-08T14:12:30Z")

</div>

Hey,

the `list_path`points to an element in the payload, that is a list - for each element in that list a dynamic attachment is created. For example for the buckets of an aggregation.

Hope that helps!

--Alex

---

<div class="post-metadata">

**Author:** ![paolo1](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@paolo1](https://discuss.elastic.co/u/paolo1)\
**Post date:** [March 8, 2017, 2:40pm UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/3 "2017-03-08T14:40:10Z")

</div>

Thanks Alex. I'm new to ES, so still not entirely sure. WRT my example, is this possible. Am i on the right line?

define items list:

> "inline" : "def items = ['name': ctx.payload.cluster\_name, 'color': ctx.payload.status == 'green' ? 'good' : 'danger']; return items;",

reference list in list\_path:

> ```
> "dynamic_attachments" : {
> "list_path" : "items",
> "attachment_template" : {
> "title" : "Status:",
> "text" : "{{name}}",
> "color" : "{{color}}"
> }
> },
> 
> ```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 13, 2017, 7:54pm UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/4 "2017-03-13T19:54:53Z")

</div>

Hey,

the context is not yet, what you want to have. You need a field called `ctx.items` that contains a list of similar events, like this

```auto
ctx.items = [[name: 'foo', color: 'red'], [name: 'bar', color: 'green'], [name: 'baz', color: 'yellow'] ]

```

hope this helps..

--Alex

---

<div class="post-metadata">

**Author:** ![paolo1](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@paolo1](https://discuss.elastic.co/u/paolo1)\
**Post date:** [March 14, 2017, 4:19pm UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/5 "2017-03-14T16:19:34Z")

</div>

Hey Alex,  
Where should ctx.items be placed? In a condition, action or something else?

---

<div class="post-metadata">

**Author:** ![paolo1](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@paolo1](https://discuss.elastic.co/u/paolo1)\
**Post date:** [March 14, 2017, 4:43pm UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/6 "2017-03-14T16:43:08Z")

</div>

This is what I have:

```
 > "condition" : {
> "script" : {
> "inline" : "if (ctx.payload.status != 'green') return true;"
> }
> },
> "actions" : {
> "notify-slack" : {
> "transform" : {
> "script" : {
> "inline" : "['items' : ['name': 'test', 'color': ctx.payload.status == 'yellow' ? 'yellow' : 'danger']]",
> "lang" : "painless"
> }
> },
> "slack" : {
> "message" : {
> "from" : "watcher",
> "to" : ["#test"], 
> "dynamic_attachments" : {
> "list_path" : "ctx.payload.items",
> "attachment_template" : {
> "title" : "Status:",
> "text" : "{{name}}",
> "color" : "{{color}}"
> }
> },
> "text" : "*Cluster health*" 
> }
> }
> }
> }
> }

```

getting the following error:

"reason": "IllegalArgumentException[dynamic attachment could not be resolved. expected context [ctx.payload.items] to be a list, but found [{color=123, name=test}] instead]",

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 16, 2017, 8:02am UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/7 "2017-03-16T08:02:09Z")

</div>

Hey,

it should be placed in a transform, likely inside of that slack action. You need to prepare your data to be in a certain format.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 8:02am UTC](https://discuss.elastic.co/t/notify-slack-action-help-with-list-path/77790/8 "2017-04-13T08:02:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
